Vulnerability Reportopensearchproject/opensearch:2.19.0

opensearchproject/opensearch:2.19.0
digestsha256:1f8b88245a6af61e7aa500afe0e87d43401e4b33140bb47230a919428ce3f7cb

Executive Summary

Last scanned:

Threat Score
74/100CAUTION
Reputation
TRUSTED

This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker could exploit request smuggling via CVE-2026-42581 to bypass proxies or poison caches, and trigger denial of service through multiple OS-level vulnerabilities such as CVE-2021-43396. Restricting inbound traffic to trusted networks and upgrading Netty to a patched version would eliminate the most critical exposure. Note that some OpenSSL findings require non-default configuration (e.g., enabling delta CRL processing), reducing their practical relevance.

Vulnerabilities

Vulnerability Log

426 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-42581HIGH8.33
io.netty:netty-codec-http
4.1.108.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.6%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-42581HIGH8.33
io.netty:netty-codec-http
4.1.115.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.6%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-42581HIGH8.33
io.netty:netty-codec-http
4.1.117.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.6%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2021-43396HIGH7.5
glibc-common
2.34-117.amzn2023.0.1
fixed in 2.34-181.amzn2023.0.1
3.1%
Low-Moderate Risk
Directly Exposed
CVE-2021-43396HIGH7.5
glibc-minimal-langpack
2.34-117.amzn2023.0.1
fixed in 2.34-181.amzn2023.0.1
3.1%
Low-Moderate Risk
Directly Exposed
CVE-2025-61726HIGH7.5
libcap
2.48-2.amzn2023.0.3
fixed in 2.73-1.amzn2023.0.6
1.9%
Low-Moderate Risk
Directly Exposed
CVE-2025-27113HIGH7.5
libxml2
2.10.4-1.amzn2023.0.7
fixed in 2.10.4-1.amzn2023.0.9
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2025-6021HIGH7.5
libxml2
2.10.4-1.amzn2023.0.7
fixed in 2.10.4-1.amzn2023.0.11
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-28388HIGH7.5
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.5.5-1.amzn2023.0.4
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-28389HIGH7.5
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.5.5-1.amzn2023.0.4
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-28390HIGH7.5
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.5.5-1.amzn2023.0.4
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-34183HIGH7.5
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.5.5-1.amzn2023.0.5
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2025-4138HIGH7.5
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.23-1.amzn2023.0.1
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2025-55163HIGH7.5
io.netty:netty-codec-http2
4.1.108.Final
fixed in 4.2.4.Final, 4.1.124.Final
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-33871HIGH7.5
io.netty:netty-codec-http2
4.1.108.Final
fixed in 4.1.132.Final, 4.2.11.Final
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2025-55163HIGH7.5
io.netty:netty-codec-http2
4.1.115.Final
fixed in 4.2.4.Final, 4.1.124.Final
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-33871HIGH7.5
io.netty:netty-codec-http2
4.1.115.Final
fixed in 4.1.132.Final, 4.2.11.Final
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2025-55163HIGH7.5
io.netty:netty-codec-http2
4.1.117.Final
fixed in 4.2.4.Final, 4.1.124.Final
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-33871HIGH7.5
io.netty:netty-codec-http2
4.1.117.Final
fixed in 4.1.132.Final, 4.2.11.Final
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2025-24970HIGH7.5
io.netty:netty-handler
4.1.108.Final
fixed in 4.1.118.Final
2.1%
Low-Moderate Risk
Directly Exposed
CVE-2025-24970HIGH7.5
io.netty:netty-handler
4.1.115.Final
fixed in 4.1.118.Final
2.1%
Low-Moderate Risk
Directly Exposed
CVE-2025-24970HIGH7.5
io.netty:netty-handler
4.1.117.Final
fixed in 4.1.118.Final
2.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-58014HIGH7.31
glib2
2.82.2-764.amzn2023
fixed in 2.82.2-770.amzn2023
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-58010MEDIUM6.97
glib2
2.82.2-764.amzn2023
fixed in 2.82.2-770.amzn2023
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-58012MEDIUM6.97
glib2
2.82.2-764.amzn2023
fixed in 2.82.2-770.amzn2023
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-58013MEDIUM6.97
glib2
2.82.2-764.amzn2023
fixed in 2.82.2-770.amzn2023
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-28387MEDIUM6.88
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.5.5-1.amzn2023.0.4
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-6100MEDIUM6.88
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.5
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-54512MEDIUM6.88
com.fasterxml.jackson.core:jackson-databind
2.14.1
fixed in 2.18.8, 3.1.4, 2.21.4
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-54513MEDIUM6.88
com.fasterxml.jackson.core:jackson-databind
2.14.1
fixed in 2.18.8, 2.21.4, 3.1.4
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-54512MEDIUM6.88
com.fasterxml.jackson.core:jackson-databind
2.17.1
fixed in 2.18.8, 3.1.4, 2.21.4
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-54513MEDIUM6.88
com.fasterxml.jackson.core:jackson-databind
2.17.1
fixed in 2.18.8, 2.21.4, 3.1.4
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-54512MEDIUM6.88
com.fasterxml.jackson.core:jackson-databind
2.18.2
fixed in 2.18.8, 3.1.4, 2.21.4
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-54513MEDIUM6.88
com.fasterxml.jackson.core:jackson-databind
2.18.2
fixed in 2.18.8, 2.21.4, 3.1.4
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-44249MEDIUM6.88
io.netty:netty-handler
4.1.108.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-44249MEDIUM6.88
io.netty:netty-handler
4.1.115.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-44249MEDIUM6.88
io.netty:netty-handler
4.1.117.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-0938MEDIUM6.8
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.21-1.amzn2023.0.2
1.5%
Low-Moderate Risk
Directly Exposed
CVE-2025-54920MEDIUM6.7
org.apache.spark:spark-core_2.13
3.5.4
fixed in 4.0.1, 3.5.7
5.3%
Low-Moderate Risk
Directly Exposed
CVE-2025-1372MEDIUM6.63
elfutils-libelf
0.188-3.amzn2023.0.2
fixed in 0.188-3.amzn2023.0.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-1372MEDIUM6.63
elfutils-libs
0.188-3.amzn2023.0.2
fixed in 0.188-3.amzn2023.0.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-25210MEDIUM6.63
expat
2.6.3-1.amzn2023.0.2
fixed in 2.6.3-1.amzn2023.0.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-5914MEDIUM6.63
libarchive
3.7.4-2.amzn2023.0.2
fixed in 3.7.4-2.amzn2023.0.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-48864MEDIUM6.63
libsolv
0.7.22-1.amzn2023.0.2
fixed in 0.7.22-1.amzn2023.0.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2022-49043MEDIUM6.63
libxml2
2.10.4-1.amzn2023.0.7
fixed in 2.10.4-1.amzn2023.0.8
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-7425MEDIUM6.63
libxml2
2.10.4-1.amzn2023.0.7
fixed in 2.10.4-1.amzn2023.0.13
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-9287MEDIUM6.63
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.21-1.amzn2023.0.1
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-13601MEDIUM6.54
glib2
2.82.2-764.amzn2023
fixed in 2.82.2-767.amzn2023
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-24928MEDIUM6.54
libxml2
2.10.4-1.amzn2023.0.7
fixed in 2.10.4-1.amzn2023.0.9
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-12718MEDIUM6.46
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.23-1.amzn2023.0.1
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-1352MEDIUM6.38
elfutils-libelf
0.188-3.amzn2023.0.2
fixed in 0.188-3.amzn2023.0.3
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-1352MEDIUM6.38
elfutils-libs
0.188-3.amzn2023.0.2
fixed in 0.188-3.amzn2023.0.3
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-6052MEDIUM6.38
glib2
2.82.2-764.amzn2023
fixed in 2.82.2-766.amzn2023
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-58011MEDIUM6.38
glib2
2.82.2-764.amzn2023
fixed in 2.82.2-770.amzn2023
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-58015MEDIUM6.38
glib2
2.82.2-764.amzn2023
fixed in 2.82.2-770.amzn2023
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-40355MEDIUM6.38
krb5-libs
1.21.3-1.amzn2023.0.1
fixed in 1.21.3-7.amzn2023.0.1
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-40356MEDIUM6.38
krb5-libs
1.21.3-1.amzn2023.0.1
fixed in 1.21.3-7.amzn2023.0.1
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-22874MEDIUM6.38
libcap
2.48-2.amzn2023.0.3
fixed in 2.73-1.amzn2023.0.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-58183MEDIUM6.38
libcap
2.48-2.amzn2023.0.3
fixed in 2.73-1.amzn2023.0.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-61728MEDIUM6.38
libcap
2.48-2.amzn2023.0.3
fixed in 2.73-1.amzn2023.0.6
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61729MEDIUM6.38
libcap
2.48-2.amzn2023.0.3
fixed in 2.73-1.amzn2023.0.5
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-33811MEDIUM6.38
libcap
2.48-2.amzn2023.0.3
fixed in 2.73-1.amzn2023.0.7
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-33814MEDIUM6.38
libcap
2.48-2.amzn2023.0.3
fixed in 2.73-1.amzn2023.0.7
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-39820MEDIUM6.38
libcap
2.48-2.amzn2023.0.3
fixed in 2.73-1.amzn2023.0.7
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-42499MEDIUM6.38
libcap
2.48-2.amzn2023.0.3
fixed in 2.73-1.amzn2023.0.7
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-41989MEDIUM6.38
libgcrypt
1.10.2-1.amzn2023.0.2
fixed in 1.10.2-1.amzn2023.0.3
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27135MEDIUM6.38
libnghttp2
1.59.0-3.amzn2023.0.1
fixed in 1.59.0-3.amzn2023.0.2
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-48863MEDIUM6.38
libsolv
0.7.22-1.amzn2023.0.2
fixed in 0.7.22-1.amzn2023.0.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-49795MEDIUM6.38
libxml2
2.10.4-1.amzn2023.0.7
fixed in 2.10.4-1.amzn2023.0.12
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-32414MEDIUM6.38
libxml2
2.10.4-1.amzn2023.0.7
fixed in 2.10.4-1.amzn2023.0.10
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-32415MEDIUM6.38
libxml2
2.10.4-1.amzn2023.0.7
fixed in 2.10.4-1.amzn2023.0.10
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-69421MEDIUM6.38
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.2.2-1.amzn2023.0.5
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-4435MEDIUM6.38
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.23-1.amzn2023.0.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-8194MEDIUM6.38
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.23-1.amzn2023.0.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-3644MEDIUM6.38
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4224MEDIUM6.38
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-7210MEDIUM6.38
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.7
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-42583MEDIUM6.38
io.netty:netty-codec
4.1.108.Final
fixed in 4.1.133.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59901MEDIUM6.38
io.netty:netty-codec
4.1.108.Final
fixed in 4.1.136.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-58057MEDIUM6.38
io.netty:netty-codec
4.1.108.Final
fixed in 4.1.125.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42583MEDIUM6.38
io.netty:netty-codec
4.1.115.Final
fixed in 4.1.133.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59901MEDIUM6.38
io.netty:netty-codec
4.1.115.Final
fixed in 4.1.136.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-58057MEDIUM6.38
io.netty:netty-codec
4.1.115.Final
fixed in 4.1.125.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42583MEDIUM6.38
io.netty:netty-codec
4.1.117.Final
fixed in 4.1.133.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59901MEDIUM6.38
io.netty:netty-codec
4.1.117.Final
fixed in 4.1.136.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-58057MEDIUM6.38
io.netty:netty-codec
4.1.117.Final
fixed in 4.1.125.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-33870MEDIUM6.38
io.netty:netty-codec-http
4.1.108.Final
fixed in 4.1.132.Final, 4.2.10.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42587MEDIUM6.38
io.netty:netty-codec-http
4.1.108.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-55831MEDIUM6.38
io.netty:netty-codec-http
4.1.108.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-55833MEDIUM6.38
io.netty:netty-codec-http
4.1.108.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-56745MEDIUM6.38
io.netty:netty-codec-http
4.1.108.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42585MEDIUM6.38
io.netty:netty-codec-http
4.1.108.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-56746MEDIUM6.38
io.netty:netty-codec-http
4.1.108.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59899MEDIUM6.38
io.netty:netty-codec-http
4.1.108.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-58056MEDIUM6.38
io.netty:netty-codec-http
4.1.108.Final
fixed in 4.1.125.Final, 4.2.5.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-33870MEDIUM6.38
io.netty:netty-codec-http
4.1.115.Final
fixed in 4.1.132.Final, 4.2.10.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42587MEDIUM6.38
io.netty:netty-codec-http
4.1.115.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-55831MEDIUM6.38
io.netty:netty-codec-http
4.1.115.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-55833MEDIUM6.38
io.netty:netty-codec-http
4.1.115.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-56745MEDIUM6.38
io.netty:netty-codec-http
4.1.115.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42585MEDIUM6.38
io.netty:netty-codec-http
4.1.115.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-56746MEDIUM6.38
io.netty:netty-codec-http
4.1.115.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59899MEDIUM6.38
io.netty:netty-codec-http
4.1.115.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-58056MEDIUM6.38
io.netty:netty-codec-http
4.1.115.Final
fixed in 4.1.125.Final, 4.2.5.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-33870MEDIUM6.38
io.netty:netty-codec-http
4.1.117.Final
fixed in 4.1.132.Final, 4.2.10.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42587MEDIUM6.38
io.netty:netty-codec-http
4.1.117.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-55831MEDIUM6.38
io.netty:netty-codec-http
4.1.117.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-55833MEDIUM6.38
io.netty:netty-codec-http
4.1.117.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-56745MEDIUM6.38
io.netty:netty-codec-http
4.1.117.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42585MEDIUM6.38
io.netty:netty-codec-http
4.1.117.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-56746MEDIUM6.38
io.netty:netty-codec-http
4.1.117.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59899MEDIUM6.38
io.netty:netty-codec-http
4.1.117.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-58056MEDIUM6.38
io.netty:netty-codec-http
4.1.117.Final
fixed in 4.1.125.Final, 4.2.5.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42587MEDIUM6.38
io.netty:netty-codec-http2
4.1.108.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-48043MEDIUM6.38
io.netty:netty-codec-http2
4.1.108.Final
fixed in 4.1.135.Final, 4.2.15.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42587MEDIUM6.38
io.netty:netty-codec-http2
4.1.115.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-48043MEDIUM6.38
io.netty:netty-codec-http2
4.1.115.Final
fixed in 4.1.135.Final, 4.2.15.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42587MEDIUM6.38
io.netty:netty-codec-http2
4.1.117.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-48043MEDIUM6.38
io.netty:netty-codec-http2
4.1.117.Final
fixed in 4.1.135.Final, 4.2.15.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-45416MEDIUM6.38
io.netty:netty-handler
4.1.108.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-50010MEDIUM6.38
io.netty:netty-handler
4.1.108.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-45416MEDIUM6.38
io.netty:netty-handler
4.1.115.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-50010MEDIUM6.38
io.netty:netty-handler
4.1.115.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-45416MEDIUM6.38
io.netty:netty-handler
4.1.117.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-50010MEDIUM6.38
io.netty:netty-handler
4.1.117.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42578MEDIUM6.38
io.netty:netty-handler-proxy
4.1.117.Final
fixed in 4.1.133.Final, 4.2.13.Final
1.0%
Theoretical Threat
Directly Exposed
CVE-2024-57699MEDIUM6.38
net.minidev:json-smart
2.5.0
fixed in 2.5.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-34478MEDIUM6.38
org.apache.logging.log4j:log4j-core
2.21.0
fixed in 2.25.4
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-34480MEDIUM6.38
org.apache.logging.log4j:log4j-core
2.21.0
fixed in 2.25.4
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-5588MEDIUM6.38
org.bouncycastle:bcpkix-jdk15to18
1.78.1
fixed in 1.84
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5588MEDIUM6.38
org.bouncycastle:bcpkix-jdk18on
1.78
fixed in 1.84
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5588MEDIUM6.38
org.bouncycastle:bcpkix-jdk18on
1.78.1
fixed in 1.84
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-14813MEDIUM6.38
org.bouncycastle:bcprov-jdk15to18
1.78.1
fixed in 1.84
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-5598MEDIUM6.38
org.bouncycastle:bcprov-jdk15to18
1.78.1
fixed in 1.80.2
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-14813MEDIUM6.38
org.bouncycastle:bcprov-jdk18on
1.78
fixed in 1.80.2, 1.81.1, 1.84
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-14813MEDIUM6.38
org.bouncycastle:bcprov-jdk18on
1.78.1
fixed in 1.80.2, 1.81.1, 1.84
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-14813MEDIUM6.38
org.bouncycastle:bcprov-jdk18on
1.80
fixed in 1.80.2, 1.81.1, 1.84
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-66566MEDIUM6.38
org.lz4:lz4-java
1.8.0
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-9624MEDIUM6.38
org.opensearch:opensearch-common
2.19.0
fixed in 3.3.0, 2.19.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-69419MEDIUM6.29
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.2.2-1.amzn2023.0.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34182MEDIUM6.29
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.5.5-1.amzn2023.0.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-4330MEDIUM6.21
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.23-1.amzn2023.0.1
0.8%
Theoretical Threat
Directly Exposed
CVE-2022-46908MEDIUM6.21
sqlite-libs
3.40.0-1.amzn2023.0.4
fixed in 3.40.0-1.amzn2023.0.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-13009MEDIUM6.12
org.eclipse.jetty:jetty-server
9.4.56.v20240826
fixed in 9.4.57.v20241219
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-54369MEDIUM6.03
libacl
2.3.1-2.amzn2023.0.2
fixed in 2.4.0-1.amzn2023.0.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-1299MEDIUM6.03
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-4786MEDIUM6.03
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-4802MEDIUM5.95
glibc
2.34-117.amzn2023.0.1
fixed in 2.34-196.amzn2023.0.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-4802MEDIUM5.95
glibc-common
2.34-117.amzn2023.0.1
fixed in 2.34-196.amzn2023.0.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-4802MEDIUM5.95
glibc-minimal-langpack
2.34-117.amzn2023.0.1
fixed in 2.34-196.amzn2023.0.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-13151MEDIUM5.9
libtasn1
4.19.0-1.amzn2023.0.4
fixed in 4.19.0-1.amzn2023.0.6
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-31790MEDIUM5.9
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.5.5-1.amzn2023.0.4
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-42764MEDIUM5.9
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.5.5-1.amzn2023.0.5
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-9231MEDIUM5.9
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.2.2-1.amzn2023.0.2
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-56132MEDIUM5.87
expat
2.6.3-1.amzn2023.0.2
fixed in 2.6.3-1.amzn2023.0.5
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56403MEDIUM5.87
expat
2.6.3-1.amzn2023.0.2
fixed in 2.6.3-1.amzn2023.0.6
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56406MEDIUM5.87
expat
2.6.3-1.amzn2023.0.2
fixed in 2.6.3-1.amzn2023.0.6
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56407MEDIUM5.87
expat
2.6.3-1.amzn2023.0.2
fixed in 2.6.3-1.amzn2023.0.6
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-4673MEDIUM5.78
libcap
2.48-2.amzn2023.0.3
fixed in 2.73-1.amzn2023.0.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-35554MEDIUM5.78
org.apache.kafka:kafka-clients
3.7.1
fixed in 3.9.2, 4.0.2, 4.1.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-5915MEDIUM5.61
libarchive
3.7.4-2.amzn2023.0.2
fixed in 3.7.4-2.amzn2023.0.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-9230MEDIUM5.6
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.2.2-1.amzn2023.0.2
1.7%
Low-Moderate Risk
Directly Exposed
CVE-2025-24528MEDIUM5.52
krb5-libs
1.21.3-1.amzn2023.0.1
fixed in 1.21.3-6.amzn2023.0.1
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61727MEDIUM5.52
libcap
2.48-2.amzn2023.0.3
fixed in 2.73-1.amzn2023.0.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9149MEDIUM5.52
libsolv
0.7.22-1.amzn2023.0.2
fixed in 0.7.22-1.amzn2023.0.4
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9150MEDIUM5.52
libsolv
0.7.22-1.amzn2023.0.2
fixed in 0.7.22-1.amzn2023.0.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-2673MEDIUM5.52
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.5.5-1.amzn2023.0.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-11972MEDIUM5.52
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59888MEDIUM5.52
com.fasterxml.jackson.core:jackson-databind
2.17.1
fixed in 2.18.8, 2.21.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-59888MEDIUM5.52
com.fasterxml.jackson.core:jackson-databind
2.18.2
fixed in 2.18.8, 2.21.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-67735MEDIUM5.52
io.netty:netty-codec-http
4.1.108.Final
fixed in 4.2.8.Final, 4.1.129.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-41417MEDIUM5.52
io.netty:netty-codec-http
4.1.108.Final
fixed in 4.1.133.Final, 4.2.13.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42580MEDIUM5.52
io.netty:netty-codec-http
4.1.108.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-67735MEDIUM5.52
io.netty:netty-codec-http
4.1.115.Final
fixed in 4.2.8.Final, 4.1.129.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-41417MEDIUM5.52
io.netty:netty-codec-http
4.1.115.Final
fixed in 4.1.133.Final, 4.2.13.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42580MEDIUM5.52
io.netty:netty-codec-http
4.1.115.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-67735MEDIUM5.52
io.netty:netty-codec-http
4.1.117.Final
fixed in 4.2.8.Final, 4.1.129.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-41417MEDIUM5.52
io.netty:netty-codec-http
4.1.117.Final
fixed in 4.1.133.Final, 4.2.13.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42580MEDIUM5.52
io.netty:netty-codec-http
4.1.117.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59900MEDIUM5.52
io.netty:netty-codec-http2
4.1.108.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-59900MEDIUM5.52
io.netty:netty-codec-http2
4.1.115.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-59900MEDIUM5.52
io.netty:netty-codec-http2
4.1.117.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-27820MEDIUM5.52
org.apache.httpcomponents.client5:httpclient5
5.4.1
fixed in 5.4.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-0636MEDIUM5.52
org.bouncycastle:bcprov-jdk15to18
1.78.1
fixed in 1.84
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-0636MEDIUM5.52
org.bouncycastle:bcprov-jdk18on
1.78
fixed in 1.84
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-0636MEDIUM5.52
org.bouncycastle:bcprov-jdk18on
1.78.1
fixed in 1.84
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-0636MEDIUM5.52
org.bouncycastle:bcprov-jdk18on
1.80
fixed in 1.84
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-12183MEDIUM5.52
org.lz4:lz4-java
1.8.0
fixed in 1.8.1
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-54370MEDIUM5.35
libacl
2.3.1-2.amzn2023.0.2
fixed in 2.4.0-1.amzn2023.0.1
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-34181MEDIUM5.35
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.5.5-1.amzn2023.0.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.5.5-1.amzn2023.0.5
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-59375MEDIUM5.3
expat
2.6.3-1.amzn2023.0.2
fixed in 2.6.3-1.amzn2023.0.3
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2024-33600MEDIUM5.3
glibc
2.34-117.amzn2023.0.1
fixed in 2.34-181.amzn2023.0.1
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2024-33600MEDIUM5.3
glibc-common
2.34-117.amzn2023.0.1
fixed in 2.34-181.amzn2023.0.1
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2024-33600MEDIUM5.3
glibc-minimal-langpack
2.34-117.amzn2023.0.1
fixed in 2.34-181.amzn2023.0.1
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2024-12133MEDIUM5.3
libtasn1
4.19.0-1.amzn2023.0.4
fixed in 4.19.0-1.amzn2023.0.5
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-1757MEDIUM5.27
libxml2
2.10.4-1.amzn2023.0.7
fixed in 2.10.4-1.amzn2023.0.18
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-1390MEDIUM5.18
libcap
2.48-2.amzn2023.0.3
fixed in 2.48-2.amzn2023.0.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-6019MEDIUM5.18
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.6
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-3576MEDIUM5.02
krb5-libs
1.21.3-1.amzn2023.0.1
fixed in 1.21.3-6.amzn2023.0.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-0990MEDIUM5.02
libxml2
2.10.4-1.amzn2023.0.7
fixed in 2.10.4-1.amzn2023.0.16
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-15468MEDIUM5.02
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.2.2-1.amzn2023.0.5
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-66199MEDIUM5.02
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.2.2-1.amzn2023.0.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69420MEDIUM5.02
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.2.2-1.amzn2023.0.5
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-22796MEDIUM5.02
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.2.2-1.amzn2023.0.5
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.5.5-1.amzn2023.0.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.5.5-1.amzn2023.0.5
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.5.5-1.amzn2023.0.5
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-9669MEDIUM5.02
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34477MEDIUM5.02
org.apache.logging.log4j:log4j-core
2.21.0
fixed in 2.25.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM5
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.5.5-1.amzn2023.0.5
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2025-53864MEDIUM4.93
com.nimbusds:nimbus-jose-jwt
9.48
fixed in 10.0.2, 9.37.4
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-59921MEDIUM4.84
io.netty:netty-codec-http
4.1.108.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-59921MEDIUM4.84
io.netty:netty-codec-http
4.1.115.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-59921MEDIUM4.84
io.netty:netty-codec-http
4.1.117.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-0395MEDIUM4.67
glibc
2.34-117.amzn2023.0.1
fixed in 2.34-181.amzn2023.0.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-0395MEDIUM4.67
glibc-common
2.34-117.amzn2023.0.1
fixed in 2.34-181.amzn2023.0.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-0395MEDIUM4.67
glibc-minimal-langpack
2.34-117.amzn2023.0.1
fixed in 2.34-181.amzn2023.0.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-22795MEDIUM4.67
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.2.2-1.amzn2023.0.5
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.5.5-1.amzn2023.0.5
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-0864MEDIUM4.67
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.8
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-13837MEDIUM4.67
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.2
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-6075MEDIUM4.67
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-25193MEDIUM4.67
io.netty:netty-common
4.1.115.Final
fixed in 4.1.118.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-25193MEDIUM4.67
io.netty:netty-common
4.1.117.Final
fixed in 4.1.118.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-27142MEDIUM4.59
libcap
2.48-2.amzn2023.0.3
fixed in 2.73-1.amzn2023.0.7
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39823MEDIUM4.59
libcap
2.48-2.amzn2023.0.3
fixed in 2.73-1.amzn2023.0.7
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc
2.34-117.amzn2023.0.1
fixed in 2.34-231.amzn2023.0.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc-common
2.34-117.amzn2023.0.1
fixed in 2.34-231.amzn2023.0.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc-minimal-langpack
2.34-117.amzn2023.0.1
fixed in 2.34-231.amzn2023.0.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-47912MEDIUM4.5
libcap
2.48-2.amzn2023.0.3
fixed in 2.73-1.amzn2023.0.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58185MEDIUM4.5
libcap
2.48-2.amzn2023.0.3
fixed in 2.73-1.amzn2023.0.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58186MEDIUM4.5
libcap
2.48-2.amzn2023.0.3
fixed in 2.73-1.amzn2023.0.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58187MEDIUM4.5
libcap
2.48-2.amzn2023.0.3
fixed in 2.73-1.amzn2023.0.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58188MEDIUM4.5
libcap
2.48-2.amzn2023.0.3
fixed in 2.73-1.amzn2023.0.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58189MEDIUM4.5
libcap
2.48-2.amzn2023.0.3
fixed in 2.73-1.amzn2023.0.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-61723MEDIUM4.5
libcap
2.48-2.amzn2023.0.3
fixed in 2.73-1.amzn2023.0.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61724MEDIUM4.5
libcap
2.48-2.amzn2023.0.3
fixed in 2.73-1.amzn2023.0.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-61725MEDIUM4.5
libcap
2.48-2.amzn2023.0.3
fixed in 2.73-1.amzn2023.0.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61730MEDIUM4.5
libcap
2.48-2.amzn2023.0.3
fixed in 2.73-1.amzn2023.0.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.5.5-1.amzn2023.0.5
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.5.5-1.amzn2023.0.5
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-3276MEDIUM4.5
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.8
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-12084MEDIUM4.5
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.2
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-3446MEDIUM4.5
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.7
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-54514MEDIUM4.5
com.fasterxml.jackson.core:jackson-databind
2.14.1
fixed in 2.18.8, 2.21.4, 3.1.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-54515MEDIUM4.5
com.fasterxml.jackson.core:jackson-databind
2.14.1
fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-54514MEDIUM4.5
com.fasterxml.jackson.core:jackson-databind
2.17.1
fixed in 2.18.8, 2.21.4, 3.1.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-54515MEDIUM4.5
com.fasterxml.jackson.core:jackson-databind
2.17.1
fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-54514MEDIUM4.5
com.fasterxml.jackson.core:jackson-databind
2.18.2
fixed in 2.18.8, 2.21.4, 3.1.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-54515MEDIUM4.5
com.fasterxml.jackson.core:jackson-databind
2.18.2
fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-50020MEDIUM4.5
io.netty:netty-codec-http
4.1.108.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-59898MEDIUM4.5
io.netty:netty-codec-http
4.1.108.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-50020MEDIUM4.5
io.netty:netty-codec-http
4.1.115.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-59898MEDIUM4.5
io.netty:netty-codec-http
4.1.115.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-50020MEDIUM4.5
io.netty:netty-codec-http
4.1.117.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-59898MEDIUM4.5
io.netty:netty-codec-http
4.1.117.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-47244MEDIUM4.5
io.netty:netty-codec-http2
4.1.108.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-50560MEDIUM4.5
io.netty:netty-codec-http2
4.1.108.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-47244MEDIUM4.5
io.netty:netty-codec-http2
4.1.115.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-50560MEDIUM4.5
io.netty:netty-codec-http2
4.1.115.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-47244MEDIUM4.5
io.netty:netty-codec-http2
4.1.117.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-50560MEDIUM4.5
io.netty:netty-codec-http2
4.1.117.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-8885MEDIUM4.5
org.bouncycastle:bc-fips
2.0.0
fixed in 1.0.2.6, 2.0.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-8916MEDIUM4.5
org.bouncycastle:bcpkix-jdk15to18
1.78.1
fixed in 1.79
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-8916MEDIUM4.5
org.bouncycastle:bcpkix-jdk18on
1.78
fixed in 1.79
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-8916MEDIUM4.5
org.bouncycastle:bcpkix-jdk18on
1.78.1
fixed in 1.79
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-4516MEDIUM4.33
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.22-1.amzn2023.0.2
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-11850MEDIUM4.25
krb5-libs
1.21.3-1.amzn2023.0.1
fixed in 1.21.3-8.amzn2023.0.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-5917MEDIUM4.25
libarchive
3.7.4-2.amzn2023.0.2
fixed in 3.7.4-2.amzn2023.0.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-15282MEDIUM4.08
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-0672MEDIUM4.08
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-68161MEDIUM4.08
org.apache.logging.log4j:log4j-core
2.21.0
fixed in 2.25.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-15467MEDIUM4.06
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.2.2-1.amzn2023.0.4
47.6%
High Exploitation Risk
Post-Exploit
CVE-2025-68160MEDIUM4
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.2.2-1.amzn2023.0.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-13176MEDIUM4
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.0.8-1.amzn2023.0.19
0.6%
Theoretical Threat
Directly Exposed
CVE-2024-33601MEDIUM4
glibc
2.34-117.amzn2023.0.1
fixed in 2.34-181.amzn2023.0.1
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2024-33601MEDIUM4
glibc-common
2.34-117.amzn2023.0.1
fixed in 2.34-181.amzn2023.0.1
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2024-33601MEDIUM4
glibc-minimal-langpack
2.34-117.amzn2023.0.1
fixed in 2.34-181.amzn2023.0.1
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-24882LOW3.98
gnupg2-minimal
2.3.7-1.amzn2023.0.4
fixed in 2.3.7-1.amzn2023.0.7
0.4%
Theoretical Threat
Post-Exploit
CVE-2024-9287LOW3.98
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.21-1.amzn2023.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2024-9681LOW3.9
libcurl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.11.1-4.amzn2023.0.1
2.0%
Low-Moderate Risk
Post-Exploit
CVE-2024-12718LOW3.88
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.23-1.amzn2023.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-4435LOW3.82
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.23-1.amzn2023.0.1
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-8194LOW3.82
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.23-1.amzn2023.0.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-3644LOW3.82
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-4224LOW3.82
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-7210LOW3.82
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.7
0.8%
Theoretical Threat
Post-Exploit
CVE-2025-66418LOW3.82
python3-pip-wheel
21.3.1-2.amzn2023.0.10
fixed in 21.3.1-2.amzn2023.0.15
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-66471LOW3.82
python3-pip-wheel
21.3.1-2.amzn2023.0.10
fixed in 21.3.1-2.amzn2023.0.15
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-11468LOW3.82
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-0865LOW3.82
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-27817LOW3.79
org.apache.kafka:kafka-clients
3.7.1
fixed in 3.9.1
64.7%
Actively Exploited
Post-Exploit
CVE-2025-4330LOW3.72
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.23-1.amzn2023.0.1
0.8%
Theoretical Threat
Post-Exploit
CVE-2025-48924LOW3.7
org.apache.commons:commons-lang3
3.10
fixed in 3.18.0
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-48924LOW3.7
org.apache.commons:commons-lang3
3.12.0
fixed in 3.18.0
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-48924LOW3.7
org.apache.commons:commons-lang3
3.13.0
fixed in 3.18.0
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-48924LOW3.7
org.apache.commons:commons-lang3
3.14.0
fixed in 3.18.0
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-48924LOW3.7
org.apache.commons:commons-lang3
3.17.0
fixed in 3.18.0
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-6069LOW3.65
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.23-1.amzn2023.0.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-8291LOW3.65
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.24-1.amzn2023.0.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-1299LOW3.62
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-4786LOW3.62
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.5
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-6965LOW3.61
sqlite-libs
3.40.0-1.amzn2023.0.4
fixed in 3.40.0-1.amzn2023.0.6
74.4%
Actively Exploited
Post-Exploit
CVE-2025-68973LOW3.57
gnupg2-minimal
2.3.7-1.amzn2023.0.4
fixed in 2.3.7-1.amzn2023.0.6
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-8058LOW3.57
glibc
2.34-117.amzn2023.0.1
fixed in 2.34-231.amzn2023.0.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-8058LOW3.57
glibc-common
2.34-117.amzn2023.0.1
fixed in 2.34-231.amzn2023.0.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-8058LOW3.57
glibc-minimal-langpack
2.34-117.amzn2023.0.1
fixed in 2.34-231.amzn2023.0.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-11053LOW3.54
curl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.15.0-4.amzn2023.0.1
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2024-11053LOW3.54
libcurl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.15.0-4.amzn2023.0.1
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2024-56171LOW3.53
libxml2
2.10.4-1.amzn2023.0.7
fixed in 2.10.4-1.amzn2023.0.9
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2025-13034LOW3.47
curl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.17.0-1.amzn2023.0.1
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-14819LOW3.47
curl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.17.0-1.amzn2023.0.1
0.7%
Theoretical Threat
Post-Exploit
CVE-2025-13034LOW3.47
libcurl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.17.0-1.amzn2023.0.1
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-14819LOW3.47
libcurl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.17.0-1.amzn2023.0.1
0.7%
Theoretical Threat
Post-Exploit
CVE-2024-33602LOW3.4
glibc
2.34-117.amzn2023.0.1
fixed in 2.34-181.amzn2023.0.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-33602LOW3.4
glibc-common
2.34-117.amzn2023.0.1
fixed in 2.34-181.amzn2023.0.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-33602LOW3.4
glibc-minimal-langpack
2.34-117.amzn2023.0.1
fixed in 2.34-181.amzn2023.0.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69418LOW3.4
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.2.2-1.amzn2023.0.5
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-11563LOW3.31
curl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.11.1-4.amzn2023.0.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-14524LOW3.31
curl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.17.0-1.amzn2023.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-11563LOW3.31
libcurl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.11.1-4.amzn2023.0.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-14524LOW3.31
libcurl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.17.0-1.amzn2023.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-11972LOW3.31
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.8
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-49796LOW3.28
libxml2
2.10.4-1.amzn2023.0.7
fixed in 2.10.4-1.amzn2023.0.12
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2026-3805LOW3.21
curl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.17.0-1.amzn2023.0.3
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-3805LOW3.21
libcurl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.17.0-1.amzn2023.0.3
0.7%
Theoretical Threat
Post-Exploit
CVE-2025-9086LOW3.18
curl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.15.0-4.amzn2023.0.1
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-9086LOW3.18
libcurl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.15.0-4.amzn2023.0.1
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-47273LOW3.17
python3-setuptools-wheel
59.6.0-2.amzn2023.0.5
fixed in 59.6.0-2.amzn2023.0.6
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2025-48734LOW3.17
commons-beanutils:commons-beanutils
1.9.4
fixed in 1.11.0
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2025-3360LOW3.15
glib2
2.82.2-764.amzn2023
fixed in 2.82.2-766.amzn2023
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-0989LOW3.15
libxml2
2.10.4-1.amzn2023.0.7
fixed in 2.10.4-1.amzn2023.0.17
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.5.5-1.amzn2023.0.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-11168LOW3.15
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.21-1.amzn2023.0.1
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-6019LOW3.11
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.6
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-50181LOW3.11
python3-pip-wheel
21.3.1-2.amzn2023.0.10
fixed in 21.3.1-2.amzn2023.0.13
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-68121LOW3.06
libcap
2.48-2.amzn2023.0.3
fixed in 2.73-1.amzn2023.0.6
0.8%
Theoretical Threat
Post-Exploit
CVE-2025-10966LOW3.01
curl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.15.0-4.amzn2023.0.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-10966LOW3.01
libcurl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.15.0-4.amzn2023.0.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-9669LOW3.01
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.8
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-14087LOW3
glib2
2.82.2-764.amzn2023
fixed in 2.82.2-769.amzn2023
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-6653LOW3
libxml2
2.10.4-1.amzn2023.0.7
fixed in 2.10.4-1.amzn2023.0.19
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6357LOW2.96
python3-pip-wheel
21.3.1-2.amzn2023.0.10
fixed in 21.3.1-2.amzn2023.0.19
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-45447LOW2.92
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.5.5-1.amzn2023.0.5
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2007-4559LOW2.81
python3-pip-wheel
21.3.1-2.amzn2023.0.10
fixed in 21.3.1-2.amzn2023.0.11
27.1%
High Exploitation Risk
Post-Exploit
CVE-2026-0864LOW2.8
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.8
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-13837LOW2.8
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.2
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-6075LOW2.8
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.1
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-8643LOW2.8
python3-pip-wheel
21.3.1-2.amzn2023.0.10
fixed in 21.3.1-2.amzn2023.0.20
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-8732LOW2.8
libxml2
2.10.4-1.amzn2023.0.7
fixed in 2.10.4-1.amzn2023.0.15
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-13462LOW2.8
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.7
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-4519LOW2.8
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-2297LOW2.8
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-3479LOW2.8
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.7
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-58016LOW2.78
glib2
2.82.2-764.amzn2023
fixed in 2.82.2-770.amzn2023
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-49794LOW2.78
libxml2
2.10.4-1.amzn2023.0.7
fixed in 2.10.4-1.amzn2023.0.12
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl-libs
1:3.0.8-1.amzn2023.0.18
fixed in 1:3.5.5-1.amzn2023.0.5
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-42584LOW2.78
io.netty:netty-codec-http
4.1.108.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-42584LOW2.78
io.netty:netty-codec-http
4.1.115.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-42584LOW2.78
io.netty:netty-codec-http
4.1.117.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.8%
Theoretical Threat
Post-Exploit
CVE-2024-33599LOW2.74
glibc
2.34-117.amzn2023.0.1
fixed in 2.34-181.amzn2023.0.1
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2024-33599LOW2.74
glibc-common
2.34-117.amzn2023.0.1
fixed in 2.34-181.amzn2023.0.1
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2024-33599LOW2.74
glibc-minimal-langpack
2.34-117.amzn2023.0.1
fixed in 2.34-181.amzn2023.0.1
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-4517LOW2.74
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.23-1.amzn2023.0.1
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2025-4517LOW2.74
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.23-1.amzn2023.0.1
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2021-43396LOW2.7
glibc
2.34-117.amzn2023.0.1
fixed in 2.34-181.amzn2023.0.1
3.1%
Low-Moderate Risk
Post-Exploit
CVE-2025-4138LOW2.7
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.23-1.amzn2023.0.1
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-21441LOW2.7
python3-pip-wheel
21.3.1-2.amzn2023.0.10
fixed in 21.3.1-2.amzn2023.0.16
2.7%
Low-Moderate Risk
Post-Exploit
CVE-2026-3276LOW2.7
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.8
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-12084LOW2.7
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.2
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-3446LOW2.7
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-8869LOW2.7
python3-pip-wheel
21.3.1-2.amzn2023.0.10
fixed in 21.3.1-2.amzn2023.0.14
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-1795LOW2.63
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.21-1.amzn2023.0.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-4516LOW2.6
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.22-1.amzn2023.0.2
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-15079LOW2.48
curl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.17.0-1.amzn2023.0.1
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-15079LOW2.48
libcurl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.17.0-1.amzn2023.0.1
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-6100LOW2.48
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.5
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-0992LOW2.46
libxml2
2.10.4-1.amzn2023.0.7
fixed in 2.10.4-1.amzn2023.0.16
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-0938LOW2.45
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.21-1.amzn2023.0.2
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2025-10148LOW2.45
curl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.15.0-4.amzn2023.0.1
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-14017LOW2.45
curl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.17.0-1.amzn2023.0.1
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-10148LOW2.45
libcurl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.15.0-4.amzn2023.0.1
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-14017LOW2.45
libcurl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.17.0-1.amzn2023.0.1
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-15282LOW2.45
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-0672LOW2.45
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-15224LOW2.4
curl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.17.0-1.amzn2023.0.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-30258LOW2.4
gnupg2-minimal
2.3.7-1.amzn2023.0.4
fixed in 2.3.7-1.amzn2023.0.5
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-15224LOW2.4
libcurl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.17.0-1.amzn2023.0.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2024-9681LOW2.34
curl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.11.1-4.amzn2023.0.1
2.0%
Low-Moderate Risk
Post-Exploit
CVE-2025-11468LOW2.29
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-0865LOW2.29
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-5278LOW2.24
coreutils-single
8.32-30.amzn2023.0.3
fixed in 8.32-30.amzn2023.0.4
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-6069LOW2.19
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.23-1.amzn2023.0.2
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-8291LOW2.19
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.24-1.amzn2023.0.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-1703LOW1.99
python3-pip-wheel
21.3.1-2.amzn2023.0.10
fixed in 21.3.1-2.amzn2023.0.17
0.4%
Theoretical Threat
Post-Exploit
CVE-2024-11168LOW1.89
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.21-1.amzn2023.0.1
0.7%
Theoretical Threat
Post-Exploit
CVE-2025-13462LOW1.68
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-4519LOW1.68
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-2297LOW1.68
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-3479LOW1.68
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-1795LOW1.58
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.21-1.amzn2023.0.3
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-57062LOW1.48
gnupg2-minimal
2.3.7-1.amzn2023.0.4
fixed in 2.3.7-1.amzn2023.0.9
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-1372NONE0
elfutils-default-yama-scope
0.188-3.amzn2023.0.2
fixed in 0.188-3.amzn2023.0.3
0.3%
Theoretical Threat
Not Applicable
CVE-2025-1352NONE0
elfutils-default-yama-scope
0.188-3.amzn2023.0.2
fixed in 0.188-3.amzn2023.0.3
0.7%
Theoretical Threat
Not Applicable
CVE-2025-48924NONE0
commons-lang:commons-lang
2.6
No fix yet
2.2%
Low-Moderate Risk
Not Applicable
CVE-2025-0167NONE0
curl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.15.0-4.amzn2023.0.1
0.7%
Theoretical Threat
Not Applicable
CVE-2026-53615NONE0
libblkid
2.37.4-1.amzn2023.0.4
fixed in 2.37.4-1.amzn2023.0.5
Not Applicable
CVE-2025-0167NONE0
libcurl-minimal
8.5.0-1.amzn2023.0.4
fixed in 8.15.0-4.amzn2023.0.1
0.7%
Theoretical Threat
Not Applicable
CVE-2026-53615NONE0
libmount
2.37.4-1.amzn2023.0.4
fixed in 2.37.4-1.amzn2023.0.5
Not Applicable
CVE-2026-53615NONE0
libsmartcols
2.37.4-1.amzn2023.0.4
fixed in 2.37.4-1.amzn2023.0.5
Not Applicable
CVE-2026-53615NONE0
libuuid
2.37.4-1.amzn2023.0.4
fixed in 2.37.4-1.amzn2023.0.5
Not Applicable
CVE-2026-11940NONE0
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.8
0.6%
Theoretical Threat
Not Applicable
CVE-2026-8328NONE0
python3
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.7
0.5%
Theoretical Threat
Not Applicable
CVE-2026-11940NONE0
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.8
0.6%
Theoretical Threat
Not Applicable
CVE-2026-8328NONE0
python3-libs
3.9.20-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.7
0.5%
Theoretical Threat
Not Applicable
CVE-2026-11822NONE0
sqlite-libs
3.40.0-1.amzn2023.0.4
fixed in 3.40.0-1.amzn2023.0.8
0.2%
Theoretical Threat
Not Applicable
CVE-2026-11824NONE0
sqlite-libs
3.40.0-1.amzn2023.0.4
fixed in 3.40.0-1.amzn2023.0.8
0.2%
Theoretical Threat
Not Applicable
GHSA-r7wm-3cxj-wff9NONE0
com.fasterxml.jackson.core:jackson-core
2.18.2
fixed in 2.18.8, 2.21.4, 2.22.1
Not Applicable
GHSA-72hv-8253-57qqNONE0
com.fasterxml.jackson.core:jackson-core
2.18.2
fixed in 2.21.1, 2.18.6
Not Applicable
CVE-2026-59889NONE0
com.fasterxml.jackson.core:jackson-databind
2.18.2
fixed in 2.21.5, 2.18.9, 2.22.1
0.3%
Theoretical Threat
Not Applicable
GHSA-mhm7-754m-9p8wNONE0
com.fasterxml.jackson.core:jackson-databind
2.18.2
fixed in 2.18.9, 2.21.5
Not Applicable
CVE-2026-33558NONE0
org.apache.kafka:kafka-clients
3.7.1
fixed in 3.9.2, 4.0.1
0.6%
Theoretical Threat
Not Applicable
CVE-2026-10050NONE0
org.eclipse.jetty:jetty-security
9.4.56.v20240826
fixed in 9.4.63, 10.0.31, 11.0.31, 12.0.36, 12.1.10
Not Applicable
CVE-2026-6790NONE0
org.eclipse.jetty:jetty-server
9.4.56.v20240826
fixed in 12.0.35, 12.1.9
0.2%
Theoretical Threat
Not Applicable
CVE-2026-59949NONE0
org.lz4:lz4-java
1.8.0
No fix yet
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.