This image poses a critical security risk and must not be used in production, especially as an internet-facing service. Exploitation of vulnerabilities such as CVE-2024-2961 in glibc or CVE-2016-9840 in zlib could lead to remote code execution, memory corruption, or denial of service, potentially compromising the MySQL database server. The image contains 55 exposed vulnerabilities, with 12 rated 7.0 or higher. While some critical issues like CVE-2024-37371 in krb5-libs are conditional on specific configurations like Kerberos authentication, the overall high-impact vulnerabilities present an immediate and severe threat.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2024-2961 | HIGH8 | glibc 2.17-326.0.9.el7_9 fixed in 2.17-326.0.9.el7_9.3 | 91.9% Actively Exploited | Directly ExposedContext importance: MEDIUM |
| CVE-2024-2961 | HIGH8 | glibc-common 2.17-326.0.9.el7_9 fixed in 2.17-326.0.9.el7_9.3 | 91.9% Actively Exploited | Directly ExposedContext importance: MEDIUM |
| CVE-2016-9840 | HIGH8 | zlib 1.2.7-21.el7_9 fixed in 1.2.7-21.0.1.el7_9 | 10.0% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2025-6965 | HIGH7.84 | sqlite 3.7.17-8.el7_7.1 fixed in 3.7.17-8.0.1.el7_9.1 | 1.0% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2023-48795 | HIGH7.67 | paramiko 2.11.0 fixed in 3.4.0 | 53.6% Actively Exploited | Directly Exposed |
| CVE-2025-6021 | HIGH7.5 | libxml2 2.9.1-6.0.3.el7_9.6 fixed in 2.9.1-6.0.7.el7_9.6 | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2025-6021 | HIGH7.5 | libxml2-python 2.9.1-6.0.3.el7_9.6 fixed in 2.9.1-6.0.7.el7_9.6 | 2.1% Low-Moderate Risk | Directly Exposed |
| CVE-2024-37371 | HIGH7.28 | krb5-libs 1.15.1-55.0.1.el7_9 fixed in 1.15.1-55.0.3.el7_9 | 2.6% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2025-49796 | HIGH7.28 | libxml2 2.9.1-6.0.3.el7_9.6 fixed in 2.9.1-6.0.7.el7_9.6 | 1.8% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2025-49796 | HIGH7.28 | libxml2-python 2.9.1-6.0.3.el7_9.6 fixed in 2.9.1-6.0.7.el7_9.6 | 1.8% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2020-11023 | HIGH7.01 | libgcc 4.8.5-44.0.3.el7 fixed in 4.8.5-45.0.1.el7_9 | 44.5% High Exploitation Risk | Directly Exposed |
| CVE-2020-11023 | HIGH7.01 | libstdc++ 4.8.5-44.0.3.el7 fixed in 4.8.5-45.0.1.el7_9 | 44.5% High Exploitation Risk | Directly Exposed |
| CVE-2024-39689 | MEDIUM6.9 | certifi 2023.7.22 fixed in 2024.7.4 | 21.2% High Exploitation Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2024-56171 | MEDIUM6.66 | libxml2 2.9.1-6.0.3.el7_9.6 fixed in 2.9.1-6.0.5.el7_9.6 | 0.2% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2024-56171 | MEDIUM6.66 | libxml2-python 2.9.1-6.0.3.el7_9.6 fixed in 2.9.1-6.0.5.el7_9.6 | 0.2% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2022-1304 | MEDIUM6.63 | libcom_err 1.42.9-19.0.1.el7 fixed in 1.45.4-3.0.7.el7 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-7425 | MEDIUM6.63 | libxml2 2.9.1-6.0.3.el7_9.6 fixed in 2.9.1-6.0.9.el7_9.6 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-7425 | MEDIUM6.63 | libxml2-python 2.9.1-6.0.3.el7_9.6 fixed in 2.9.1-6.0.9.el7_9.6 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-13601 | MEDIUM6.54 | glib2 2.56.1-9.el7_9 fixed in 2.56.1-9.0.3.el7_9 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-24928 | MEDIUM6.54 | libxml2 2.9.1-6.0.3.el7_9.6 fixed in 2.9.1-6.0.5.el7_9.6 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-24928 | MEDIUM6.54 | libxml2-python 2.9.1-6.0.3.el7_9.6 fixed in 2.9.1-6.0.5.el7_9.6 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-33599 | MEDIUM6.46 | glibc 2.17-326.0.9.el7_9 fixed in 2.17-326.0.9.el7_9.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-33599 | MEDIUM6.46 | glibc-common 2.17-326.0.9.el7_9 fixed in 2.17-326.0.9.el7_9.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2024-37370 | MEDIUM6.38 | krb5-libs 1.15.1-55.0.1.el7_9 fixed in 1.15.1-55.0.3.el7_9 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-32414 | MEDIUM6.38 | libxml2 2.9.1-6.0.3.el7_9.6 fixed in 2.9.1-6.0.7.el7_9.6 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-32415 | MEDIUM6.38 | libxml2 2.9.1-6.0.3.el7_9.6 fixed in 2.9.1-6.0.11.el7_9.6 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-32414 | MEDIUM6.38 | libxml2-python 2.9.1-6.0.3.el7_9.6 fixed in 2.9.1-6.0.7.el7_9.6 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-32415 | MEDIUM6.38 | libxml2-python 2.9.1-6.0.3.el7_9.6 fixed in 2.9.1-6.0.11.el7_9.6 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2023-50782 | MEDIUM6.38 | cryptography 3.2.1 fixed in 42.0.0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2023-49083 | MEDIUM6.38 | cryptography 3.2.1 fixed in 41.0.6 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2025-49794 | MEDIUM6.18 | libxml2 2.9.1-6.0.3.el7_9.6 fixed in 2.9.1-6.0.7.el7_9.6 | 0.4% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2025-49794 | MEDIUM6.18 | libxml2-python 2.9.1-6.0.3.el7_9.6 fixed in 2.9.1-6.0.7.el7_9.6 | 0.4% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2024-3596 | MEDIUM6 | krb5-libs 1.15.1-55.0.1.el7_9 fixed in 1.15.1-55.0.7.el7_9 | 19.0% High Exploitation Risk | Directly Exposed |
| CVE-2025-4802 | MEDIUM5.95 | glibc 2.17-326.0.9.el7_9 fixed in 2.17-326.0.11.el7_9.3 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-4802 | MEDIUM5.95 | glibc-common 2.17-326.0.9.el7_9 fixed in 2.17-326.0.11.el7_9.3 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2023-0286 | MEDIUM5.77 | cryptography 3.2.1 fixed in 39.0.1 | 88.3% Actively Exploited | Directly Exposed |
| CVE-2025-24528 | MEDIUM5.52 | krb5-libs 1.15.1-55.0.1.el7_9 fixed in 1.15.1-55.0.9.el7_9 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-26007 | MEDIUM5.52 | cryptography 3.2.1 fixed in 46.0.5 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2023-23931 | MEDIUM5.52 | cryptography 3.2.1 fixed in 39.0.1 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2020-36242 | MEDIUM5.46 | cryptography 3.2.1 fixed in 3.3.2 | 1.6% Low-Moderate Risk | Directly Exposed |
| CVE-2024-21626 | MEDIUM5.16 | github.com/opencontainers/runc v1.1.0 fixed in 1.1.12 | 3.9% Low-Moderate Risk | Post-Exploit |
| CVE-2025-9230 | MEDIUM4.76 | openssl-libs 1:1.0.2k-26.el7_9 fixed in 1:1.0.2k-26.0.1.el7_9 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2024-0727 | MEDIUM4.67 | cryptography 3.2.1 fixed in 42.0.2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-33600 | MEDIUM4.5 | glibc 2.17-326.0.9.el7_9 fixed in 2.17-326.0.9.el7_9.3 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-33600 | MEDIUM4.5 | glibc-common 2.17-326.0.9.el7_9 fixed in 2.17-326.0.9.el7_9.3 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-34073 | MEDIUM4.5 | cryptography 3.2.1 fixed in 46.0.6 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27448 | MEDIUM4.5 | pyOpenSSL 20.0.1 fixed in 26.0.0 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-31133 | LOW3.98 | github.com/opencontainers/runc v1.1.0 fixed in 1.2.8, 1.3.3, 1.4.0-rc.3 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2022-29162 | LOW3.98 | github.com/opencontainers/runc v1.1.0 fixed in 1.1.2 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2023-28642 | LOW3.98 | github.com/opencontainers/runc v1.1.0 fixed in 1.1.5 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-52565 | LOW3.82 | github.com/opencontainers/runc v1.1.0 fixed in 1.2.8, 1.3.3, 1.4.0-rc.3 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-52881 | LOW3.82 | github.com/opencontainers/runc v1.1.0 fixed in 1.2.8, 1.3.3, 1.4.0-rc.3 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-69277 | LOW3.82 | PyNaCl 1.4.0 fixed in 1.6.2 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-15367 | LOW3.62 | python-libs 2.7.5-94.0.1.el7_9 fixed in 2.7.5-94.0.5.el7_9 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-68973 | LOW3.57 | gnupg2 2.0.22-5.el7_5 fixed in 2.0.22-5.0.1.el7_5 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2023-27561 | LOW3.57 | github.com/opencontainers/runc v1.1.0 fixed in 1.1.5 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2024-33601 | LOW3.4 | glibc 2.17-326.0.9.el7_9 fixed in 2.17-326.0.9.el7_9.3 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-33602 | LOW3.4 | glibc 2.17-326.0.9.el7_9 fixed in 2.17-326.0.9.el7_9.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2024-33601 | LOW3.4 | glibc-common 2.17-326.0.9.el7_9 fixed in 2.17-326.0.9.el7_9.3 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-33602 | LOW3.4 | glibc-common 2.17-326.0.9.el7_9 fixed in 2.17-326.0.9.el7_9.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2023-25809 | LOW3.21 | github.com/opencontainers/runc v1.1.0 fixed in 1.1.5 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2024-6345 | LOW3.17 | setuptools 58.1.0 fixed in 70.0.0 | 5.6% Low-Moderate Risk | Post-Exploit |
| CVE-2022-40897 | LOW3.01 | setuptools 58.1.0 fixed in 65.5.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-6357 | LOW2.96 | pip 23.0.1 fixed in 26.1 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-44405 | LOW2.89 | paramiko 2.11.0 No fix yet | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-9230 | LOW2.86 | openssl 1:1.0.2k-26.el7_9 fixed in 1:1.0.2k-26.0.1.el7_9 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-12084 | LOW2.7 | python 2.7.5-94.0.1.el7_9 fixed in 2.7.5-94.0.3.el7_9 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-12084 | LOW2.7 | python-libs 2.7.5-94.0.1.el7_9 fixed in 2.7.5-94.0.3.el7_9 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-8869 | LOW2.7 | pip 23.0.1 fixed in 25.3 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-47273 | LOW2.69 | setuptools 58.1.0 fixed in 78.1.1 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-3219 | LOW2.55 | pip 23.0.1 fixed in 26.1 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-15366 | LOW2.17 | python 2.7.5-94.0.1.el7_9 fixed in 2.7.5-94.0.5.el7_9 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-15367 | LOW2.17 | python 2.7.5-94.0.1.el7_9 fixed in 2.7.5-94.0.5.el7_9 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-15366 | LOW2.17 | python-libs 2.7.5-94.0.1.el7_9 fixed in 2.7.5-94.0.5.el7_9 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-1703 | LOW1.99 | pip 23.0.1 fixed in 26.0 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2024-45310 | LOW1.84 | github.com/opencontainers/runc v1.1.0 fixed in 1.1.14, 1.2.0-rc.3 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-4519 | LOW1.68 | python 2.7.5-94.0.1.el7_9 fixed in 2.7.5-94.0.7.el7_9 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-4519 | LOW1.68 | python-libs 2.7.5-94.0.1.el7_9 fixed in 2.7.5-94.0.7.el7_9 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2023-5752 | LOW1.68 | pip 23.0.1 fixed in 23.3 | <0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-68121 | NONE0 | stdlib v1.18.2 fixed in 1.24.13, 1.25.7, 1.26.0-rc.3 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2023-24538 | NONE0 | stdlib v1.18.2 fixed in 1.19.8, 1.20.3 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2023-24540 | NONE0 | stdlib v1.18.2 fixed in 1.19.9, 1.20.4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2024-24790 | NONE0 | stdlib v1.18.2 fixed in 1.21.11, 1.22.4 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2022-30580 | NONE0 | stdlib v1.18.2 fixed in 1.17.11, 1.18.3 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2023-29403 | NONE0 | stdlib v1.18.2 fixed in 1.19.10, 1.20.5 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2022-27664 | NONE0 | stdlib v1.18.2 fixed in 1.18.6, 1.19.1 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2022-28131 | NONE0 | stdlib v1.18.2 fixed in 1.17.12, 1.18.4 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2022-2879 | NONE0 | stdlib v1.18.2 fixed in 1.18.7, 1.19.2 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2022-2880 | NONE0 | stdlib v1.18.2 fixed in 1.18.7, 1.19.2 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2022-29804 | NONE0 | stdlib v1.18.2 fixed in 1.17.11, 1.18.3 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2022-30630 | NONE0 | stdlib v1.18.2 fixed in 1.17.12, 1.18.4 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2022-30631 | NONE0 | stdlib v1.18.2 fixed in 1.17.12, 1.18.4 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2022-30632 | NONE0 | stdlib v1.18.2 fixed in 1.17.12, 1.18.4 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2022-30633 | NONE0 | stdlib v1.18.2 fixed in 1.17.12, 1.18.4 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2022-30634 | NONE0 | stdlib v1.18.2 fixed in 1.17.11, 1.18.3 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2022-30635 | NONE0 | stdlib v1.18.2 fixed in 1.17.12, 1.18.4 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2022-32189 | NONE0 | stdlib v1.18.2 fixed in 1.17.13, 1.18.5 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2022-41715 | NONE0 | stdlib v1.18.2 fixed in 1.18.7, 1.19.2 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2022-41716 | NONE0 | stdlib v1.18.2 fixed in 1.18.8, 1.19.3 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2022-41720 | NONE0 | stdlib v1.18.2 fixed in 1.18.9, 1.19.4 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2022-41722 | NONE0 | stdlib v1.18.2 fixed in 1.19.6, 1.20.1 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2022-41723 | NONE0 | stdlib v1.18.2 fixed in 1.19.6, 1.20.1 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2022-41724 | NONE0 | stdlib v1.18.2 fixed in 1.19.6, 1.20.1 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2022-41725 | NONE0 | stdlib v1.18.2 fixed in 1.19.6, 1.20.1 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2023-24534 | NONE0 | stdlib v1.18.2 fixed in 1.19.8, 1.20.3 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2023-24536 | NONE0 | stdlib v1.18.2 fixed in 1.19.8, 1.20.3 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2023-24537 | NONE0 | stdlib v1.18.2 fixed in 1.19.8, 1.20.3 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2023-39325 | NONE0 | stdlib v1.18.2 fixed in 1.20.10, 1.21.3 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2023-45283 | NONE0 | stdlib v1.18.2 fixed in 1.20.11, 1.21.4, 1.20.12, 1.21.5 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2023-45287 | NONE0 | stdlib v1.18.2 fixed in 1.20.0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2023-45288 | NONE0 | stdlib v1.18.2 fixed in 1.21.9, 1.22.2 | 69.9% Actively Exploited | Not Applicable |
| CVE-2024-34156 | NONE0 | stdlib v1.18.2 fixed in 1.22.7, 1.23.1 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-61726 | NONE0 | stdlib v1.18.2 fixed in 1.24.12, 1.25.6 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2025-61729 | NONE0 | stdlib v1.18.2 fixed in 1.24.11, 1.25.5 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2026-25679 | NONE0 | stdlib v1.18.2 fixed in 1.25.8, 1.26.1 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2026-32280 | NONE0 | stdlib v1.18.2 fixed in 1.25.9, 1.26.2 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2026-32281 | NONE0 | stdlib v1.18.2 fixed in 1.25.9, 1.26.2 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2026-32283 | NONE0 | stdlib v1.18.2 fixed in 1.25.9, 1.26.2 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2026-33811 | NONE0 | stdlib v1.18.2 fixed in 1.25.10, 1.26.3 | — | Not Applicable |
| CVE-2026-33814 | NONE0 | stdlib v1.18.2 fixed in 1.25.10, 1.26.3 | — | Not Applicable |
| CVE-2026-39820 | NONE0 | stdlib v1.18.2 fixed in 1.25.10, 1.26.3 | — | Not Applicable |
| CVE-2026-39836 | NONE0 | stdlib v1.18.2 fixed in 1.25.10, 1.26.3 | — | Not Applicable |
| CVE-2025-58183 | NONE0 | stdlib v1.18.2 fixed in 1.24.8, 1.25.2 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2025-61728 | NONE0 | stdlib v1.18.2 fixed in 1.24.12, 1.25.6 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2023-24539 | NONE0 | stdlib v1.18.2 fixed in 1.19.9, 1.20.4 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2023-29400 | NONE0 | stdlib v1.18.2 fixed in 1.19.9, 1.20.4 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2025-47907 | NONE0 | stdlib v1.18.2 fixed in 1.23.12, 1.24.6 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2025-4673 | NONE0 | stdlib v1.18.2 fixed in 1.23.10, 1.24.4 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2022-1705 | NONE0 | stdlib v1.18.2 fixed in 1.17.12, 1.18.4 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2022-32148 | NONE0 | stdlib v1.18.2 fixed in 1.17.12, 1.18.4 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2023-29406 | NONE0 | stdlib v1.18.2 fixed in 1.19.11, 1.20.6 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2024-24785 | NONE0 | stdlib v1.18.2 fixed in 1.21.8, 1.22.1 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2025-47906 | NONE0 | stdlib v1.18.2 fixed in 1.23.12, 1.24.6 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2025-61727 | NONE0 | stdlib v1.18.2 fixed in 1.24.11, 1.25.5 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2026-32282 | NONE0 | stdlib v1.18.2 fixed in 1.25.9, 1.26.2 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2023-39318 | NONE0 | stdlib v1.18.2 fixed in 1.20.8, 1.21.1 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2023-39319 | NONE0 | stdlib v1.18.2 fixed in 1.20.8, 1.21.1 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2026-32289 | NONE0 | stdlib v1.18.2 fixed in 1.25.9, 1.26.2 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2024-24783 | NONE0 | stdlib v1.18.2 fixed in 1.21.8, 1.22.1 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2024-24791 | NONE0 | stdlib v1.18.2 fixed in 1.21.12, 1.22.5 | 1.0% Low-Moderate Risk | Not Applicable |
| CVE-2024-34155 | NONE0 | stdlib v1.18.2 fixed in 1.22.7, 1.23.1 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2024-34158 | NONE0 | stdlib v1.18.2 fixed in 1.22.7, 1.23.1 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2024-45336 | NONE0 | stdlib v1.18.2 fixed in 1.22.11, 1.23.5, 1.24.0-rc.2 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2022-1962 | NONE0 | stdlib v1.18.2 fixed in 1.17.12, 1.18.4 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2024-24789 | NONE0 | stdlib v1.18.2 fixed in 1.21.11, 1.22.4 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2026-32288 | NONE0 | stdlib v1.18.2 fixed in 1.25.9, 1.26.2 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2024-24784 | NONE0 | stdlib v1.18.2 fixed in 1.21.8, 1.22.1 | 2.0% Low-Moderate Risk | Not Applicable |
| CVE-2025-22871 | NONE0 | stdlib v1.18.2 fixed in 1.23.8, 1.24.2 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-27142 | NONE0 | stdlib v1.18.2 fixed in 1.25.8, 1.26.1 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2026-39826 | NONE0 | stdlib v1.18.2 fixed in 1.25.10, 1.26.3 | — | Not Applicable |
| CVE-2022-41717 | NONE0 | stdlib v1.18.2 fixed in 1.18.9, 1.19.4 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2023-24532 | NONE0 | stdlib v1.18.2 fixed in 1.19.7, 1.20.2 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2023-29409 | NONE0 | stdlib v1.18.2 fixed in 1.19.12, 1.20.7, 1.21.0-rc.4 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2023-39326 | NONE0 | stdlib v1.18.2 fixed in 1.20.12, 1.21.5 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2023-45284 | NONE0 | stdlib v1.18.2 fixed in 1.20.11, 1.21.4 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2023-45289 | NONE0 | stdlib v1.18.2 fixed in 1.21.8, 1.22.1 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2023-45290 | NONE0 | stdlib v1.18.2 fixed in 1.21.8, 1.22.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-22866 | NONE0 | stdlib v1.18.2 fixed in 1.22.12, 1.23.6, 1.24.0-rc.3 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2025-22873 | NONE0 | stdlib v1.18.2 fixed in 1.23.9, 1.24.3 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2025-47912 | NONE0 | stdlib v1.18.2 fixed in 1.24.8, 1.25.2 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2025-58185 | NONE0 | stdlib v1.18.2 fixed in 1.24.8, 1.25.2 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2025-58187 | NONE0 | stdlib v1.18.2 fixed in 1.24.9, 1.25.3 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2025-58188 | NONE0 | stdlib v1.18.2 fixed in 1.24.8, 1.25.2 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2025-58189 | NONE0 | stdlib v1.18.2 fixed in 1.24.8, 1.25.2 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2025-61723 | NONE0 | stdlib v1.18.2 fixed in 1.24.8, 1.25.2 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2025-61724 | NONE0 | stdlib v1.18.2 fixed in 1.24.8, 1.25.2 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2025-61725 | NONE0 | stdlib v1.18.2 fixed in 1.24.8, 1.25.2 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2025-61730 | NONE0 | stdlib v1.18.2 fixed in 1.24.12, 1.25.6 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2025-58186 | NONE0 | stdlib v1.18.2 fixed in 1.24.8, 1.25.2 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2025-22870 | NONE0 | stdlib v1.18.2 fixed in 1.23.7, 1.24.1 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2024-45341 | NONE0 | stdlib v1.18.2 fixed in 1.22.11, 1.23.5, 1.24.0-rc.2 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2022-30629 | NONE0 | stdlib v1.18.2 fixed in 1.17.11, 1.18.3 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2026-27139 | NONE0 | stdlib v1.18.2 fixed in 1.25.8, 1.26.1 | <0.1% Theoretical Threat | Not Applicable |
| GHSA-5cpq-8wj7-hf2v | NONE0 | cryptography 3.2.1 fixed in 41.0.0 | — | Not Applicable |
| GHSA-jm77-qphf-c4w8 | NONE0 | cryptography 3.2.1 fixed in 41.0.3 | — | Not Applicable |
| GHSA-v8gr-m533-ghj9 | NONE0 | cryptography 3.2.1 fixed in 41.0.4 | — | Not Applicable |
| CVE-2026-39823 | NONE0 | stdlib v1.18.2 fixed in 1.25.10, 1.26.3 | — | Not Applicable |
| CVE-2026-39825 | NONE0 | stdlib v1.18.2 fixed in 1.25.10, 1.26.3 | — | Not Applicable |
| CVE-2026-42499 | NONE0 | stdlib v1.18.2 fixed in 1.25.10, 1.26.3 | — | Not Applicable |
| CVE-2026-42504 | NONE0 | stdlib v1.18.2 fixed in 1.25.11, 1.26.4 | — | Not Applicable |
| CVE-2025-0913 | NONE0 | stdlib v1.18.2 fixed in 1.23.10, 1.24.4 | <0.1% Theoretical Threat | Not Applicable |
| CVE-2026-27145 | NONE0 | stdlib v1.18.2 fixed in 1.25.11, 1.26.4 | — | Not Applicable |
| CVE-2026-42507 | NONE0 | stdlib v1.18.2 fixed in 1.25.11, 1.26.4 | — | Not Applicable |