Vulnerability Reportopensearchproject/opensearch:2.4.1

opensearchproject/opensearch:2.4.1
digestsha256:cf80040045595329691a966fe47dedc49dacd262260855dcb768ffce297abed2

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
TRUSTED

This image is safe for production use. It has no exposed attack surface (exposed_total=0), and all 37 detected issues are post-exploit-only, with the highest severity at 4.58. The most notable finding is CVE-2023-38545 in curl, but it requires a non-default configuration (curl using a SOCKS5 proxy), so it is not reachable in standard deployments. No exposed surface vulnerabilities or high-severity post-exploit issues are present.

Vulnerabilities

Vulnerability Log

670 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2023-38545MEDIUM4.58
curl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.4
78.5%
Actively Exploited
Post-Exploit
CVE-2025-15079MEDIUM4.13
curl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.12
0.5%
Theoretical Threat
Post-Exploit
CVE-2023-23916LOW3.9
curl
7.79.1-7.amzn2.0.1
fixed in 7.88.0-1.amzn2.0.1
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2023-46218LOW3.9
curl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.6
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2024-9681LOW3.9
curl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.8
2.0%
Low-Moderate Risk
Post-Exploit
CVE-2025-68973LOW3.57
gnupg2
2.0.22-5.amzn2.0.5
fixed in 2.0.22-5.amzn2.0.6
0.1%
Theoretical Threat
Post-Exploit
CVE-2022-43552LOW3.54
curl
7.79.1-7.amzn2.0.1
fixed in 7.87.0-2.amzn2.0.1
2.5%
Low-Moderate Risk
Post-Exploit
CVE-2023-27535LOW3.54
curl
7.79.1-7.amzn2.0.1
fixed in 8.0.1-1.amzn2.0.1
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2023-27536LOW3.54
curl
7.79.1-7.amzn2.0.1
fixed in 8.0.1-1.amzn2.0.1
1.6%
Low-Moderate Risk
Post-Exploit
CVE-2023-27537LOW3.54
curl
7.79.1-7.amzn2.0.1
fixed in 8.0.1-1.amzn2.0.1
1.9%
Low-Moderate Risk
Post-Exploit
CVE-2023-28321LOW3.54
curl
7.79.1-7.amzn2.0.1
fixed in 8.2.1-1.amzn2.0.2
1.8%
Low-Moderate Risk
Post-Exploit
CVE-2023-38039LOW3.51
curl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.1
62.2%
Actively Exploited
Post-Exploit
CVE-2025-14819LOW3.47
curl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.12
0.7%
Theoretical Threat
Post-Exploit
CVE-2023-23915LOW3.31
curl
7.79.1-7.amzn2.0.1
fixed in 7.88.0-1.amzn2.0.1
0.9%
Theoretical Threat
Post-Exploit
CVE-2025-11563LOW3.31
curl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-14524LOW3.31
curl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.12
0.6%
Theoretical Threat
Post-Exploit
CVE-2023-27538LOW3.3
curl
7.79.1-7.amzn2.0.1
fixed in 8.0.1-1.amzn2.0.1
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2022-48303LOW3.3
tar
2:1.26-35.amzn2
fixed in 2:1.26-35.amzn2.0.1
4.5%
Low-Moderate Risk
Post-Exploit
CVE-2024-2004LOW3.18
curl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.7
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2025-9086LOW3.18
curl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.10
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2023-46219LOW3.18
curl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.5
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2023-27533LOW3.17
curl
7.79.1-7.amzn2.0.1
fixed in 8.0.1-1.amzn2.0.1
2.0%
Low-Moderate Risk
Post-Exploit
CVE-2023-27534LOW3.17
curl
7.79.1-7.amzn2.0.1
fixed in 8.0.1-1.amzn2.0.1
2.2%
Low-Moderate Risk
Post-Exploit
CVE-2022-43551LOW3.1
curl
7.79.1-7.amzn2.0.1
fixed in 7.87.0-2.amzn2.0.1
16.5%
High Exploitation Risk
Post-Exploit
CVE-2024-2398LOW3.1
curl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.7
36.1%
High Exploitation Risk
Post-Exploit
CVE-2025-10966LOW3.01
curl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.12
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-4641LOW2.8
shadow-utils
2:4.1.5.1-24.amzn2.0.2
fixed in 2:4.1.5.1-24.amzn2.0.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2023-23914LOW2.78
curl
7.79.1-7.amzn2.0.1
fixed in 7.88.0-1.amzn2.0.1
0.9%
Theoretical Threat
Post-Exploit
CVE-2022-27781LOW2.7
curl
7.79.1-7.amzn2.0.1
fixed in 7.87.0-2.amzn2.0.1
2.6%
Low-Moderate Risk
Post-Exploit
CVE-2023-28319LOW2.7
curl
7.79.1-7.amzn2.0.1
fixed in 8.2.1-1.amzn2.0.2
2.5%
Low-Moderate Risk
Post-Exploit
CVE-2019-9923LOW2.7
tar
2:1.26-35.amzn2
fixed in 2:1.26-35.amzn2.0.2
3.0%
Low-Moderate Risk
Post-Exploit
CVE-2025-14017LOW2.45
curl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.12
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-15224LOW2.4
curl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.12
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-38546LOW2.22
curl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.4
6.2%
Low-Moderate Risk
Post-Exploit
CVE-2023-28322LOW2.22
curl
7.79.1-7.amzn2.0.1
fixed in 8.2.1-1.amzn2.0.2
2.2%
Low-Moderate Risk
Post-Exploit
CVE-2020-19909LOW1.68
curl
7.79.1-7.amzn2.0.1
fixed in 8.2.1-1.amzn2.0.2
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-39804LOW1.68
tar
2:1.26-35.amzn2
fixed in 2:1.26-35.amzn2.0.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2023-37920NONE0
ca-certificates
2021.2.50-72.amzn2.0.3
fixed in 2021.2.50-72.amzn2.0.8
0.6%
Theoretical Threat
Not Applicable
CVE-2018-16428NONE0
glib2
2.56.1-9.amzn2.0.2
fixed in 2.56.1-9.amzn2.0.3
4.7%
Low-Moderate Risk
Not Applicable
CVE-2025-14087NONE0
glib2
2.56.1-9.amzn2.0.2
fixed in 2.56.1-9.amzn2.0.13
0.8%
Theoretical Threat
Not Applicable
CVE-2015-8390NONE0
glib2
2.56.1-9.amzn2.0.2
fixed in 2.56.1-9.amzn2.0.6
4.6%
Low-Moderate Risk
Not Applicable
CVE-2015-8394NONE0
glib2
2.56.1-9.amzn2.0.2
fixed in 2.56.1-9.amzn2.0.6
4.8%
Low-Moderate Risk
Not Applicable
CVE-2023-38545NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.4
78.5%
Actively Exploited
Not Applicable
CVE-2024-56171NONE0
libxml2
2.9.1-6.amzn2.5.6
fixed in 2.9.1-6.amzn2.5.16
1.1%
Low-Moderate Risk
Not Applicable
CVE-2026-6653NONE0
libxml2
2.9.1-6.amzn2.5.6
fixed in 2.9.1-6.amzn2.5.25
0.4%
Theoretical Threat
Not Applicable
CVE-2015-8390NONE0
pcre
8.32-17.amzn2.0.2
fixed in 8.32-17.amzn2.0.3
4.6%
Low-Moderate Risk
Not Applicable
CVE-2015-8394NONE0
pcre
8.32-17.amzn2.0.2
fixed in 8.32-17.amzn2.0.3
4.8%
Low-Moderate Risk
Not Applicable
CVE-2022-48565NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.7
4.3%
Low-Moderate Risk
Not Applicable
CVE-2022-48565NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.7
4.3%
Low-Moderate Risk
Not Applicable
CVE-2023-45853NONE0
zlib
1.2.7-19.amzn2.0.2
fixed in 1.2.7-19.amzn2.0.3
3.2%
Low-Moderate Risk
Not Applicable
CVE-2026-42581NONE0
io.netty:netty-codec-http
4.1.77.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42581NONE0
io.netty:netty-codec-http
4.1.79.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42581NONE0
io.netty:netty-codec-http
4.1.84.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2022-46364NONE0
org.apache.cxf:cxf-core
3.4.5
fixed in 3.4.10, 3.5.5
2.1%
Low-Moderate Risk
Not Applicable
CVE-2023-32697NONE0
org.xerial:sqlite-jdbc
3.32.3.2
fixed in 3.41.2.2
1.6%
Low-Moderate Risk
Not Applicable
CVE-2022-1471NONE0
org.yaml:snakeyaml
1.32
fixed in 2.0
99.6%
Actively Exploited
Not Applicable
CVE-2026-58016NONE0
glib2
2.56.1-9.amzn2.0.2
fixed in 2.56.1-9.amzn2.0.14
0.4%
Theoretical Threat
Not Applicable
CVE-2024-37371NONE0
krb5-libs
1.15.1-37.amzn2.2.4
fixed in 1.15.1-55.amzn2.2.8
1.9%
Low-Moderate Risk
Not Applicable
CVE-2023-23914NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 7.88.0-1.amzn2.0.1
0.9%
Theoretical Threat
Not Applicable
CVE-2019-3859NONE0
libssh2
1.4.3-12.amzn2.2.3
fixed in 1.4.3-12.amzn2.2.4
6.3%
Low-Moderate Risk
Not Applicable
CVE-2019-3860NONE0
libssh2
1.4.3-12.amzn2.2.3
fixed in 1.4.3-12.amzn2.2.4
5.1%
Low-Moderate Risk
Not Applicable
CVE-2026-7598NONE0
libssh2
1.4.3-12.amzn2.2.3
fixed in 1.4.3-12.amzn2.2.7
0.5%
Theoretical Threat
Not Applicable
CVE-2021-46848NONE0
libtasn1
4.10-1.amzn2.0.2
fixed in 4.10-1.amzn2.0.3
2.0%
Low-Moderate Risk
Not Applicable
CVE-2025-49794NONE0
libxml2
2.9.1-6.amzn2.5.6
fixed in 2.9.1-6.amzn2.5.19
0.7%
Theoretical Threat
Not Applicable
CVE-2025-49796NONE0
libxml2
2.9.1-6.amzn2.5.6
fixed in 2.9.1-6.amzn2.5.19
1.4%
Low-Moderate Risk
Not Applicable
CVE-2026-42584NONE0
io.netty:netty-codec-http
4.1.77.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.8%
Theoretical Threat
Not Applicable
CVE-2026-42584NONE0
io.netty:netty-codec-http
4.1.79.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.8%
Theoretical Threat
Not Applicable
CVE-2026-42584NONE0
io.netty:netty-codec-http
4.1.84.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.8%
Theoretical Threat
Not Applicable
CVE-2024-2961NONE0
glibc
2.26-62.amzn2
fixed in 2.26-64.amzn2.0.1
88.3%
Actively Exploited
Not Applicable
CVE-2024-2961NONE0
glibc-common
2.26-62.amzn2
fixed in 2.26-64.amzn2.0.1
88.3%
Actively Exploited
Not Applicable
CVE-2024-2961NONE0
glibc-langpack-en
2.26-62.amzn2
fixed in 2.26-64.amzn2.0.1
88.3%
Actively Exploited
Not Applicable
CVE-2024-2961NONE0
glibc-minimal-langpack
2.26-62.amzn2
fixed in 2.26-64.amzn2.0.1
88.3%
Actively Exploited
Not Applicable
CVE-2022-42898NONE0
krb5-libs
1.15.1-37.amzn2.2.4
fixed in 1.15.1-55.amzn2.2.5
6.4%
Low-Moderate Risk
Not Applicable
CVE-2024-2961NONE0
libcrypt
2.26-62.amzn2
fixed in 2.26-64.amzn2.0.1
88.3%
Actively Exploited
Not Applicable
CVE-2023-27533NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 8.0.1-1.amzn2.0.1
2.0%
Low-Moderate Risk
Not Applicable
CVE-2023-27534NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 8.0.1-1.amzn2.0.1
2.2%
Low-Moderate Risk
Not Applicable
CVE-2023-0767NONE0
nss
3.79.0-4.amzn2
fixed in 3.79.0-4.amzn2.0.1
0.8%
Theoretical Threat
Not Applicable
CVE-2023-0767NONE0
nss-sysinit
3.79.0-4.amzn2
fixed in 3.79.0-4.amzn2.0.1
0.8%
Theoretical Threat
Not Applicable
CVE-2023-0767NONE0
nss-tools
3.79.0-4.amzn2
fixed in 3.79.0-4.amzn2.0.1
0.8%
Theoretical Threat
Not Applicable
CVE-2026-47162NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Not Applicable
CVE-2026-47162NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Not Applicable
CVE-2025-48734NONE0
commons-beanutils:commons-beanutils
1.9.4
fixed in 1.11.0
1.5%
Low-Moderate Risk
Not Applicable
CVE-2026-34982NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.5
0.5%
Theoretical Threat
Not Applicable
CVE-2026-34982NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.5
0.5%
Theoretical Threat
Not Applicable
CVE-2025-15079NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.12
0.5%
Theoretical Threat
Not Applicable
CVE-2026-45447NONE0
openssl-libs
1:1.0.2k-24.amzn2.0.4
fixed in 1:1.0.2k-24.amzn2.0.21
5.2%
Low-Moderate Risk
Not Applicable
CVE-2026-6100NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.19
0.6%
Theoretical Threat
Not Applicable
CVE-2026-6100NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.19
0.6%
Theoretical Threat
Not Applicable
CVE-2026-54512NONE0
com.fasterxml.jackson.core:jackson-databind
2.13.4.2
fixed in 2.18.8, 3.1.4, 2.21.4
0.8%
Theoretical Threat
Not Applicable
CVE-2026-54513NONE0
com.fasterxml.jackson.core:jackson-databind
2.13.4.2
fixed in 2.18.8, 2.21.4, 3.1.4
0.7%
Theoretical Threat
Not Applicable
CVE-2026-54512NONE0
com.fasterxml.jackson.core:jackson-databind
2.14.0
fixed in 2.18.8, 3.1.4, 2.21.4
0.8%
Theoretical Threat
Not Applicable
CVE-2026-54513NONE0
com.fasterxml.jackson.core:jackson-databind
2.14.0
fixed in 2.18.8, 2.21.4, 3.1.4
0.7%
Theoretical Threat
Not Applicable
CVE-2026-54512NONE0
com.fasterxml.jackson.core:jackson-databind
2.14.1
fixed in 2.18.8, 3.1.4, 2.21.4
0.8%
Theoretical Threat
Not Applicable
CVE-2026-54513NONE0
com.fasterxml.jackson.core:jackson-databind
2.14.1
fixed in 2.18.8, 2.21.4, 3.1.4
0.7%
Theoretical Threat
Not Applicable
CVE-2026-44249NONE0
io.netty:netty-handler
4.1.77.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2026-44249NONE0
io.netty:netty-handler
4.1.79.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2026-44249NONE0
io.netty:netty-handler
4.1.84.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2021-38185NONE0
cpio
2.11-28.amzn2
fixed in 2.12-11.amzn2
4.1%
Low-Moderate Risk
Not Applicable
CVE-2026-25210NONE0
expat
2.1.0-15.amzn2.0.2
fixed in 2.1.0-15.amzn2.0.6
0.2%
Theoretical Threat
Not Applicable
CVE-2020-35457NONE0
glib2
2.56.1-9.amzn2.0.2
fixed in 2.56.1-9.amzn2.0.8
0.6%
Theoretical Threat
Not Applicable
CVE-2023-32643NONE0
glib2
2.56.1-9.amzn2.0.2
fixed in 2.56.1-9.amzn2.0.9
0.4%
Theoretical Threat
Not Applicable
CVE-2017-10140NONE0
libdb
5.3.21-24.amzn2.0.3
fixed in 5.3.21-24.amzn2.0.4
0.6%
Theoretical Threat
Not Applicable
CVE-2017-10140NONE0
libdb-utils
5.3.21-24.amzn2.0.3
fixed in 5.3.21-24.amzn2.0.4
0.6%
Theoretical Threat
Not Applicable
CVE-2022-49043NONE0
libxml2
2.9.1-6.amzn2.5.6
fixed in 2.9.1-6.amzn2.5.15
0.3%
Theoretical Threat
Not Applicable
CVE-2025-7425NONE0
libxml2
2.9.1-6.amzn2.5.6
fixed in 2.9.1-6.amzn2.5.20
0.3%
Theoretical Threat
Not Applicable
CVE-2022-40304NONE0
libxml2
2.9.1-6.amzn2.5.6
fixed in 2.9.1-6.amzn2.5.7
6.8%
Low-Moderate Risk
Not Applicable
CVE-2023-29491NONE0
ncurses
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.5
0.9%
Theoretical Threat
Not Applicable
CVE-2023-29491NONE0
ncurses-base
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.5
0.9%
Theoretical Threat
Not Applicable
CVE-2023-29491NONE0
ncurses-libs
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.5
0.9%
Theoretical Threat
Not Applicable
CVE-2022-2522NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.6%
Theoretical Threat
Not Applicable
CVE-2022-2571NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-2580NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-2581NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-3134NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-3234NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-3235NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-3256NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-3296NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-3297NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-3324NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-3352NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-3491NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-4141NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1006-1.amzn2.0.1
0.4%
Theoretical Threat
Not Applicable
CVE-2022-4292NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1160-1.amzn2.0.1
0.7%
Theoretical Threat
Not Applicable
CVE-2022-47024NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.3%
Theoretical Threat
Not Applicable
CVE-2023-0049NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1160-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2023-0051NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2023-0054NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2023-0288NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2023-0433NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.6%
Theoretical Threat
Not Applicable
CVE-2023-0512NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2023-2610NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1592-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2023-4733NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2023-4734NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.6%
Theoretical Threat
Not Applicable
CVE-2023-4735NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.6%
Theoretical Threat
Not Applicable
CVE-2023-4738NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.6%
Theoretical Threat
Not Applicable
CVE-2023-4750NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2023-4751NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.6%
Theoretical Threat
Not Applicable
CVE-2023-4752NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.6%
Theoretical Threat
Not Applicable
CVE-2023-4781NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.6%
Theoretical Threat
Not Applicable
CVE-2026-52858NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Not Applicable
CVE-2026-52860NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Not Applicable
CVE-2026-55693NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.8
0.1%
Theoretical Threat
Not Applicable
CVE-2026-55895NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.8
0.2%
Theoretical Threat
Not Applicable
CVE-2026-57456NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.8
0.1%
Theoretical Threat
Not Applicable
CVE-2024-22667NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.1
0.6%
Theoretical Threat
Not Applicable
CVE-2025-1215NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.4
0.5%
Theoretical Threat
Not Applicable
CVE-2023-1127NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1367-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2023-5535NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.3
0.5%
Theoretical Threat
Not Applicable
CVE-2022-2522NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.6%
Theoretical Threat
Not Applicable
CVE-2022-2571NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-2580NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-2581NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-3134NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-3234NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-3235NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-3256NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-3296NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-3297NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-3324NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-3352NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-3491NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-4141NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1006-1.amzn2.0.1
0.4%
Theoretical Threat
Not Applicable
CVE-2022-4292NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1160-1.amzn2.0.1
0.7%
Theoretical Threat
Not Applicable
CVE-2022-47024NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.3%
Theoretical Threat
Not Applicable
CVE-2023-0049NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1160-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2023-0051NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2023-0054NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2023-0288NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2023-0433NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.6%
Theoretical Threat
Not Applicable
CVE-2023-0512NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2023-2610NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1592-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2023-4733NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2023-4734NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.6%
Theoretical Threat
Not Applicable
CVE-2023-4735NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.6%
Theoretical Threat
Not Applicable
CVE-2023-4738NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.6%
Theoretical Threat
Not Applicable
CVE-2023-4750NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2023-4751NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.6%
Theoretical Threat
Not Applicable
CVE-2023-4752NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.6%
Theoretical Threat
Not Applicable
CVE-2023-4781NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.6%
Theoretical Threat
Not Applicable
CVE-2026-52858NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Not Applicable
CVE-2026-52860NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Not Applicable
CVE-2026-55693NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.8
0.1%
Theoretical Threat
Not Applicable
CVE-2026-55895NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.8
0.2%
Theoretical Threat
Not Applicable
CVE-2026-57456NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.8
0.1%
Theoretical Threat
Not Applicable
CVE-2024-22667NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.1
0.6%
Theoretical Threat
Not Applicable
CVE-2025-1215NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.4
0.5%
Theoretical Threat
Not Applicable
CVE-2023-1127NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1367-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2023-5535NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.3
0.5%
Theoretical Threat
Not Applicable
CVE-2025-13601NONE0
glib2
2.56.1-9.amzn2.0.2
fixed in 2.56.1-9.amzn2.0.12
0.3%
Theoretical Threat
Not Applicable
CVE-2025-24928NONE0
libxml2
2.9.1-6.amzn2.5.6
fixed in 2.9.1-6.amzn2.5.16
0.4%
Theoretical Threat
Not Applicable
CVE-2025-6965NONE0
sqlite
3.7.17-8.amzn2.1.1
fixed in 3.7.17-8.amzn2.1.3
74.4%
Actively Exploited
Not Applicable
CVE-2022-23491NONE0
ca-certificates
2021.2.50-72.amzn2.0.3
fixed in 2021.2.50-72.amzn2.0.5
0.5%
Theoretical Threat
Not Applicable
CVE-2024-39689NONE0
ca-certificates
2021.2.50-72.amzn2.0.3
fixed in 2023.2.68-1.amzn2.0.1
1.0%
Low-Moderate Risk
Not Applicable
CVE-2022-23990NONE0
expat
2.1.0-15.amzn2.0.2
fixed in 2.1.0-15.amzn2.0.3
4.0%
Low-Moderate Risk
Not Applicable
CVE-2024-45490NONE0
expat
2.1.0-15.amzn2.0.2
fixed in 2.1.0-15.amzn2.0.4
1.7%
Low-Moderate Risk
Not Applicable
CVE-2018-16429NONE0
glib2
2.56.1-9.amzn2.0.2
fixed in 2.56.1-9.amzn2.0.3
3.5%
Low-Moderate Risk
Not Applicable
CVE-2023-32636NONE0
glib2
2.56.1-9.amzn2.0.2
fixed in 2.56.1-9.amzn2.0.9
0.8%
Theoretical Threat
Not Applicable
CVE-2023-29499NONE0
glib2
2.56.1-9.amzn2.0.2
fixed in 2.56.1-9.amzn2.0.9
0.8%
Theoretical Threat
Not Applicable
CVE-2021-43618NONE0
gmp
1:6.0.0-15.amzn2.0.2
fixed in 1:6.0.0-15.amzn2.0.3
3.4%
Low-Moderate Risk
Not Applicable
CVE-2024-37370NONE0
krb5-libs
1.15.1-37.amzn2.2.4
fixed in 1.15.1-55.amzn2.2.8
0.7%
Theoretical Threat
Not Applicable
CVE-2023-38039NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.1
62.2%
Actively Exploited
Not Applicable
CVE-2022-27781NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 7.87.0-2.amzn2.0.1
2.6%
Low-Moderate Risk
Not Applicable
CVE-2022-43551NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 7.87.0-2.amzn2.0.1
16.5%
High Exploitation Risk
Not Applicable
CVE-2023-28319NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 8.2.1-1.amzn2.0.2
2.5%
Low-Moderate Risk
Not Applicable
CVE-2024-2398NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.7
36.1%
High Exploitation Risk
Not Applicable
CVE-2023-35945NONE0
libnghttp2
1.41.0-1.amzn2
fixed in 1.41.0-1.amzn2.0.1
1.3%
Low-Moderate Risk
Not Applicable
CVE-2023-44487NONE0
libnghttp2
1.41.0-1.amzn2
fixed in 1.41.0-1.amzn2.0.4
100.0%
Actively Exploited
Not Applicable
CVE-2026-27135NONE0
libnghttp2
1.41.0-1.amzn2
fixed in 1.41.0-1.amzn2.0.6
0.8%
Theoretical Threat
Not Applicable
CVE-2020-22218NONE0
libssh2
1.4.3-12.amzn2.2.3
fixed in 1.4.3-12.amzn2.2.6
0.9%
Theoretical Threat
Not Applicable
CVE-2026-58050NONE0
libssh2
1.4.3-12.amzn2.2.3
fixed in 1.4.3-12.amzn2.2.8
0.4%
Theoretical Threat
Not Applicable
CVE-2025-27113NONE0
libxml2
2.9.1-6.amzn2.5.6
fixed in 2.9.1-6.amzn2.5.16
1.0%
Low-Moderate Risk
Not Applicable
CVE-2025-6021NONE0
libxml2
2.9.1-6.amzn2.5.6
fixed in 2.9.1-6.amzn2.5.18
1.1%
Low-Moderate Risk
Not Applicable
CVE-2022-40303NONE0
libxml2
2.9.1-6.amzn2.5.6
fixed in 2.9.1-6.amzn2.5.7
22.8%
High Exploitation Risk
Not Applicable
CVE-2025-32414NONE0
libxml2
2.9.1-6.amzn2.5.6
fixed in 2.9.1-6.amzn2.5.17
0.4%
Theoretical Threat
Not Applicable
CVE-2025-32415NONE0
libxml2
2.9.1-6.amzn2.5.6
fixed in 2.9.1-6.amzn2.5.17
0.6%
Theoretical Threat
Not Applicable
CVE-2019-13565NONE0
openldap
2.4.44-23.amzn2.0.4
fixed in 2.4.44-25.amzn2.0.5
5.0%
Low-Moderate Risk
Not Applicable
CVE-2020-36221NONE0
openldap
2.4.44-23.amzn2.0.4
fixed in 2.4.44-25.amzn2.0.5
84.2%
Actively Exploited
Not Applicable
CVE-2020-36222NONE0
openldap
2.4.44-23.amzn2.0.4
fixed in 2.4.44-25.amzn2.0.5
77.7%
Actively Exploited
Not Applicable
CVE-2020-36223NONE0
openldap
2.4.44-23.amzn2.0.4
fixed in 2.4.44-25.amzn2.0.5
4.3%
Low-Moderate Risk
Not Applicable
CVE-2020-36224NONE0
openldap
2.4.44-23.amzn2.0.4
fixed in 2.4.44-25.amzn2.0.5
4.3%
Low-Moderate Risk
Not Applicable
CVE-2020-36226NONE0
openldap
2.4.44-23.amzn2.0.4
fixed in 2.4.44-25.amzn2.0.5
4.3%
Low-Moderate Risk
Not Applicable
CVE-2020-36227NONE0
openldap
2.4.44-23.amzn2.0.4
fixed in 2.4.44-25.amzn2.0.5
77.7%
Actively Exploited
Not Applicable
CVE-2020-36228NONE0
openldap
2.4.44-23.amzn2.0.4
fixed in 2.4.44-25.amzn2.0.5
83.4%
Actively Exploited
Not Applicable
CVE-2020-36229NONE0
openldap
2.4.44-23.amzn2.0.4
fixed in 2.4.44-25.amzn2.0.5
4.3%
Low-Moderate Risk
Not Applicable
CVE-2020-36230NONE0
openldap
2.4.44-23.amzn2.0.4
fixed in 2.4.44-25.amzn2.0.5
12.3%
High Exploitation Risk
Not Applicable
CVE-2021-27212NONE0
openldap
2.4.44-23.amzn2.0.4
fixed in 2.4.44-25.amzn2.0.5
64.1%
Actively Exploited
Not Applicable
CVE-2023-2953NONE0
openldap
2.4.44-23.amzn2.0.4
fixed in 2.4.44-25.amzn2.0.6
1.9%
Low-Moderate Risk
Not Applicable
CVE-2023-0215NONE0
openssl-libs
1:1.0.2k-24.amzn2.0.4
fixed in 1:1.0.2k-24.amzn2.0.6
4.5%
Low-Moderate Risk
Not Applicable
CVE-2025-69421NONE0
openssl-libs
1:1.0.2k-24.amzn2.0.4
fixed in 1:1.0.2k-24.amzn2.0.17
0.8%
Theoretical Threat
Not Applicable
CVE-2026-28388NONE0
openssl-libs
1:1.0.2k-24.amzn2.0.4
fixed in 1:1.0.2k-24.amzn2.0.20
1.1%
Low-Moderate Risk
Not Applicable
CVE-2026-28389NONE0
openssl-libs
1:1.0.2k-24.amzn2.0.4
fixed in 1:1.0.2k-24.amzn2.0.20
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-28390NONE0
openssl-libs
1:1.0.2k-24.amzn2.0.4
fixed in 1:1.0.2k-24.amzn2.0.20
1.0%
Low-Moderate Risk
Not Applicable
CVE-2023-0464NONE0
openssl-libs
1:1.0.2k-24.amzn2.0.4
fixed in 1:1.0.2k-24.amzn2.0.7
3.7%
Low-Moderate Risk
Not Applicable
CVE-2022-45061NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.6
2.5%
Low-Moderate Risk
Not Applicable
CVE-2025-8194NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.14
0.6%
Theoretical Threat
Not Applicable
CVE-2026-3644NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.17
0.4%
Theoretical Threat
Not Applicable
CVE-2026-4224NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.17
0.6%
Theoretical Threat
Not Applicable
CVE-2023-24329NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.6
20.5%
High Exploitation Risk
Not Applicable
CVE-2024-7592NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.11
2.3%
Low-Moderate Risk
Not Applicable
CVE-2022-45061NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.6
2.5%
Low-Moderate Risk
Not Applicable
CVE-2025-8194NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.14
0.6%
Theoretical Threat
Not Applicable
CVE-2026-3644NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.17
0.4%
Theoretical Threat
Not Applicable
CVE-2026-4224NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.17
0.6%
Theoretical Threat
Not Applicable
CVE-2023-24329NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.6
20.5%
High Exploitation Risk
Not Applicable
CVE-2024-7592NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.11
2.3%
Low-Moderate Risk
Not Applicable
CVE-2022-35737NONE0
sqlite
3.7.17-8.amzn2.1.1
fixed in 3.7.17-8.amzn2.1.2
18.0%
High Exploitation Risk
Not Applicable
CVE-2023-5344NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.2
1.2%
Low-Moderate Risk
Not Applicable
CVE-2023-5344NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.2
1.2%
Low-Moderate Risk
Not Applicable
CVE-2025-52999NONE0
com.fasterxml.jackson.core:jackson-core
2.13.4
fixed in 2.15.0
0.6%
Theoretical Threat
Not Applicable
CVE-2025-52999NONE0
com.fasterxml.jackson.core:jackson-core
2.14.1
fixed in 2.15.0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-50193NONE0
com.fasterxml.jackson.core:jackson-databind
2.13.4.2
fixed in 2.14.0
0.5%
Theoretical Threat
Not Applicable
CVE-2024-7254NONE0
com.google.protobuf:protobuf-java
3.21.8
fixed in 3.25.5, 4.27.5, 4.28.2
2.8%
Low-Moderate Risk
Not Applicable
CVE-2024-7254NONE0
com.google.protobuf:protobuf-java
3.21.9
fixed in 3.25.5, 4.27.5, 4.28.2
2.8%
Low-Moderate Risk
Not Applicable
CVE-2023-3635NONE0
com.squareup.okio:okio
2.8.0
fixed in 3.4.0, 1.17.6
1.3%
Low-Moderate Risk
Not Applicable
CVE-2026-42583NONE0
io.netty:netty-codec
4.1.77.Final
fixed in 4.1.133.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-59901NONE0
io.netty:netty-codec
4.1.77.Final
fixed in 4.1.136.Final
0.2%
Theoretical Threat
Not Applicable
CVE-2025-58057NONE0
io.netty:netty-codec
4.1.77.Final
fixed in 4.1.125.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42583NONE0
io.netty:netty-codec
4.1.79.Final
fixed in 4.1.133.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-59901NONE0
io.netty:netty-codec
4.1.79.Final
fixed in 4.1.136.Final
0.2%
Theoretical Threat
Not Applicable
CVE-2025-58057NONE0
io.netty:netty-codec
4.1.79.Final
fixed in 4.1.125.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42583NONE0
io.netty:netty-codec
4.1.84.Final
fixed in 4.1.133.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-59901NONE0
io.netty:netty-codec
4.1.84.Final
fixed in 4.1.136.Final
0.2%
Theoretical Threat
Not Applicable
CVE-2025-58057NONE0
io.netty:netty-codec
4.1.84.Final
fixed in 4.1.125.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2026-33870NONE0
io.netty:netty-codec-http
4.1.77.Final
fixed in 4.1.132.Final, 4.2.10.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42587NONE0
io.netty:netty-codec-http
4.1.77.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Not Applicable
CVE-2026-55831NONE0
io.netty:netty-codec-http
4.1.77.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-55833NONE0
io.netty:netty-codec-http
4.1.77.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-56745NONE0
io.netty:netty-codec-http
4.1.77.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.5%
Theoretical Threat
Not Applicable
CVE-2026-42585NONE0
io.netty:netty-codec-http
4.1.77.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.2%
Theoretical Threat
Not Applicable
CVE-2026-56746NONE0
io.netty:netty-codec-http
4.1.77.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-59899NONE0
io.netty:netty-codec-http
4.1.77.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2025-58056NONE0
io.netty:netty-codec-http
4.1.77.Final
fixed in 4.1.125.Final, 4.2.5.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2026-33870NONE0
io.netty:netty-codec-http
4.1.79.Final
fixed in 4.1.132.Final, 4.2.10.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42587NONE0
io.netty:netty-codec-http
4.1.79.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Not Applicable
CVE-2026-55831NONE0
io.netty:netty-codec-http
4.1.79.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-55833NONE0
io.netty:netty-codec-http
4.1.79.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-56745NONE0
io.netty:netty-codec-http
4.1.79.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.5%
Theoretical Threat
Not Applicable
CVE-2026-42585NONE0
io.netty:netty-codec-http
4.1.79.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.2%
Theoretical Threat
Not Applicable
CVE-2026-56746NONE0
io.netty:netty-codec-http
4.1.79.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-59899NONE0
io.netty:netty-codec-http
4.1.79.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2025-58056NONE0
io.netty:netty-codec-http
4.1.79.Final
fixed in 4.1.125.Final, 4.2.5.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2026-33870NONE0
io.netty:netty-codec-http
4.1.84.Final
fixed in 4.1.132.Final, 4.2.10.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42587NONE0
io.netty:netty-codec-http
4.1.84.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Not Applicable
CVE-2026-55831NONE0
io.netty:netty-codec-http
4.1.84.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-55833NONE0
io.netty:netty-codec-http
4.1.84.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-56745NONE0
io.netty:netty-codec-http
4.1.84.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.5%
Theoretical Threat
Not Applicable
CVE-2026-42585NONE0
io.netty:netty-codec-http
4.1.84.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.2%
Theoretical Threat
Not Applicable
CVE-2026-56746NONE0
io.netty:netty-codec-http
4.1.84.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-59899NONE0
io.netty:netty-codec-http
4.1.84.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2025-58056NONE0
io.netty:netty-codec-http
4.1.84.Final
fixed in 4.1.125.Final, 4.2.5.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2025-55163NONE0
io.netty:netty-codec-http2
4.1.77.Final
fixed in 4.2.4.Final, 4.1.124.Final
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-33871NONE0
io.netty:netty-codec-http2
4.1.77.Final
fixed in 4.1.132.Final, 4.2.11.Final
1.1%
Low-Moderate Risk
Not Applicable
CVE-2026-42587NONE0
io.netty:netty-codec-http2
4.1.77.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Not Applicable
CVE-2026-48043NONE0
io.netty:netty-codec-http2
4.1.77.Final
fixed in 4.1.135.Final, 4.2.15.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2025-55163NONE0
io.netty:netty-codec-http2
4.1.79.Final
fixed in 4.2.4.Final, 4.1.124.Final
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-33871NONE0
io.netty:netty-codec-http2
4.1.79.Final
fixed in 4.1.132.Final, 4.2.11.Final
1.1%
Low-Moderate Risk
Not Applicable
CVE-2026-42587NONE0
io.netty:netty-codec-http2
4.1.79.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Not Applicable
CVE-2026-48043NONE0
io.netty:netty-codec-http2
4.1.79.Final
fixed in 4.1.135.Final, 4.2.15.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2026-45416NONE0
io.netty:netty-handler
4.1.77.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.5%
Theoretical Threat
Not Applicable
CVE-2026-50010NONE0
io.netty:netty-handler
4.1.77.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-45416NONE0
io.netty:netty-handler
4.1.79.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.5%
Theoretical Threat
Not Applicable
CVE-2026-50010NONE0
io.netty:netty-handler
4.1.79.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-45416NONE0
io.netty:netty-handler
4.1.84.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.5%
Theoretical Threat
Not Applicable
CVE-2026-50010NONE0
io.netty:netty-handler
4.1.84.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42578NONE0
io.netty:netty-handler-proxy
4.1.77.Final
fixed in 4.1.133.Final, 4.2.13.Final
1.0%
Theoretical Threat
Not Applicable
CVE-2026-42578NONE0
io.netty:netty-handler-proxy
4.1.79.Final
fixed in 4.1.133.Final, 4.2.13.Final
1.0%
Theoretical Threat
Not Applicable
CVE-2023-1370NONE0
net.minidev:json-smart
2.4.7
fixed in 2.4.9
1.1%
Low-Moderate Risk
Not Applicable
CVE-2022-46363NONE0
org.apache.cxf:cxf-core
3.4.5
fixed in 3.4.10, 3.5.5
1.2%
Low-Moderate Risk
Not Applicable
CVE-2025-23184NONE0
org.apache.cxf:cxf-core
3.4.5
fixed in 3.5.10, 3.6.5, 4.0.6
2.0%
Low-Moderate Risk
Not Applicable
CVE-2024-32007NONE0
org.apache.cxf:cxf-rt-rs-security-jose
3.4.5
fixed in 4.0.5, 3.6.4, 3.5.9
1.3%
Low-Moderate Risk
Not Applicable
CVE-2026-34480NONE0
org.apache.logging.log4j:log4j-core
2.17.1
fixed in 2.25.4
0.9%
Theoretical Threat
Not Applicable
CVE-2026-5588NONE0
org.bouncycastle:bcpkix-jdk15on
1.70
fixed in 1.84
0.4%
Theoretical Threat
Not Applicable
CVE-2022-45688NONE0
org.json:json
20180813
fixed in 20230227
1.2%
Low-Moderate Risk
Not Applicable
CVE-2023-5072NONE0
org.json:json
20180813
fixed in 20231013
1.4%
Low-Moderate Risk
Not Applicable
CVE-2025-66566NONE0
org.lz4:lz4-java
1.7.1
No fix yet
0.6%
Theoretical Threat
Not Applicable
CVE-2025-41249NONE0
org.springframework:spring-core
5.3.22
fixed in 6.2.11
0.5%
Theoretical Threat
Not Applicable
CVE-2026-41848NONE0
org.springframework:spring-core
5.3.22
fixed in 7.0.8, 6.2.19
0.3%
Theoretical Threat
Not Applicable
CVE-2026-41851NONE0
org.springframework:spring-expression
5.3.22
fixed in 7.0.8, 6.2.19
0.4%
Theoretical Threat
Not Applicable
CVE-2023-34455NONE0
org.xerial.snappy:snappy-java
1.1.8.1
fixed in 1.1.10.1
1.8%
Low-Moderate Risk
Not Applicable
CVE-2023-43642NONE0
org.xerial.snappy:snappy-java
1.1.8.1
fixed in 1.1.10.4
1.0%
Low-Moderate Risk
Not Applicable
CVE-2023-34453NONE0
org.xerial.snappy:snappy-java
1.1.8.1
fixed in 1.1.10.1
1.7%
Low-Moderate Risk
Not Applicable
CVE-2023-34454NONE0
org.xerial.snappy:snappy-java
1.1.8.1
fixed in 1.1.10.1
1.5%
Low-Moderate Risk
Not Applicable
CVE-2023-0286NONE0
openssl-libs
1:1.0.2k-24.amzn2.0.4
fixed in 1:1.0.2k-24.amzn2.0.6
59.5%
Actively Exploited
Not Applicable
CVE-2023-7104NONE0
nss
3.79.0-4.amzn2
fixed in 3.90.0-2.amzn2.0.2
1.2%
Low-Moderate Risk
Not Applicable
CVE-2023-7104NONE0
nss-sysinit
3.79.0-4.amzn2
fixed in 3.90.0-2.amzn2.0.2
1.2%
Low-Moderate Risk
Not Applicable
CVE-2023-7104NONE0
nss-tools
3.79.0-4.amzn2
fixed in 3.90.0-2.amzn2.0.2
1.2%
Low-Moderate Risk
Not Applicable
CVE-2026-41411NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.6
0.5%
Theoretical Threat
Not Applicable
CVE-2026-41411NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.6
0.5%
Theoretical Threat
Not Applicable
CVE-2023-4156NONE0
gawk
4.0.2-4.amzn2.1.2
fixed in 4.0.2-4.amzn2.1.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-4786NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.19
0.3%
Theoretical Threat
Not Applicable
CVE-2026-4786NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.19
0.3%
Theoretical Threat
Not Applicable
CVE-2023-2976NONE0
com.google.guava:guava
30.0-jre
fixed in 32.0.0-android
0.2%
Theoretical Threat
Not Applicable
CVE-2023-2976NONE0
com.google.guava:guava
30.1-jre
fixed in 32.0.0-android
0.2%
Theoretical Threat
Not Applicable
CVE-2023-2976NONE0
com.google.guava:guava
31.0.1-jre
fixed in 32.0.0-android
0.2%
Theoretical Threat
Not Applicable
CVE-2023-2976NONE0
com.google.guava:guava
31.1-android
fixed in 32.0.0-android
0.2%
Theoretical Threat
Not Applicable
CVE-2026-56132NONE0
expat
2.1.0-15.amzn2.0.2
fixed in 2.1.0-15.amzn2.0.7
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56403NONE0
expat
2.1.0-15.amzn2.0.2
fixed in 2.1.0-15.amzn2.0.8
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56406NONE0
expat
2.1.0-15.amzn2.0.2
fixed in 2.1.0-15.amzn2.0.8
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56407NONE0
expat
2.1.0-15.amzn2.0.2
fixed in 2.1.0-15.amzn2.0.8
0.1%
Theoretical Threat
Not Applicable
CVE-2025-14819NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.12
0.7%
Theoretical Threat
Not Applicable
CVE-2007-4559NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.12
27.1%
High Exploitation Risk
Not Applicable
CVE-2024-6923NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.11
0.8%
Theoretical Threat
Not Applicable
CVE-2025-0938NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.11
1.5%
Low-Moderate Risk
Not Applicable
CVE-2007-4559NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.12
27.1%
High Exploitation Risk
Not Applicable
CVE-2024-6923NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.11
0.8%
Theoretical Threat
Not Applicable
CVE-2025-0938NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.11
1.5%
Low-Moderate Risk
Not Applicable
CVE-2026-35554NONE0
org.apache.kafka:kafka-clients
3.0.2
fixed in 3.9.2, 4.0.2, 4.1.2
0.3%
Theoretical Threat
Not Applicable
CVE-2023-1170NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1403-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2023-1175NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1403-1.amzn2.0.1
0.4%
Theoretical Threat
Not Applicable
CVE-2023-1170NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1403-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2023-1175NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1403-1.amzn2.0.1
0.4%
Theoretical Threat
Not Applicable
CVE-2022-25313NONE0
expat
2.1.0-15.amzn2.0.2
fixed in 2.1.0-15.amzn2.0.3
3.3%
Low-Moderate Risk
Not Applicable
CVE-2023-36054NONE0
krb5-libs
1.15.1-37.amzn2.2.4
fixed in 1.15.1-55.amzn2.2.6
2.8%
Low-Moderate Risk
Not Applicable
CVE-2025-24528NONE0
krb5-libs
1.15.1-37.amzn2.2.4
fixed in 1.15.1-55.amzn2.2.9
0.6%
Theoretical Threat
Not Applicable
CVE-2023-23915NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 7.88.0-1.amzn2.0.1
0.9%
Theoretical Threat
Not Applicable
CVE-2023-23916NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 7.88.0-1.amzn2.0.1
1.7%
Low-Moderate Risk
Not Applicable
CVE-2023-46218NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.6
1.7%
Low-Moderate Risk
Not Applicable
CVE-2024-9681NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.8
2.0%
Low-Moderate Risk
Not Applicable
CVE-2025-11563NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.11
0.3%
Theoretical Threat
Not Applicable
CVE-2025-14524NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.12
0.6%
Theoretical Threat
Not Applicable
CVE-2026-58051NONE0
libssh2
1.4.3-12.amzn2.2.3
fixed in 1.4.3-12.amzn2.2.8
0.3%
Theoretical Threat
Not Applicable
CVE-2023-45322NONE0
libxml2
2.9.1-6.amzn2.5.6
fixed in 2.9.1-6.amzn2.5.13
0.8%
Theoretical Threat
Not Applicable
CVE-2023-28484NONE0
libxml2
2.9.1-6.amzn2.5.6
fixed in 2.9.1-6.amzn2.5.8
1.1%
Low-Moderate Risk
Not Applicable
CVE-2023-29469NONE0
libxml2
2.9.1-6.amzn2.5.6
fixed in 2.9.1-6.amzn2.5.8
1.0%
Low-Moderate Risk
Not Applicable
CVE-2023-39615NONE0
libxml2
2.9.1-6.amzn2.5.6
fixed in 2.9.1-6.amzn2.5.11
0.7%
Theoretical Threat
Not Applicable
CVE-2020-19185NONE0
ncurses
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.6
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19186NONE0
ncurses
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.6
1.5%
Low-Moderate Risk
Not Applicable
CVE-2020-19187NONE0
ncurses
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.6
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19188NONE0
ncurses
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.6
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19189NONE0
ncurses
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.6
1.9%
Low-Moderate Risk
Not Applicable
CVE-2020-19190NONE0
ncurses
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.6
1.4%
Low-Moderate Risk
Not Applicable
CVE-2023-50495NONE0
ncurses
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.7
1.0%
Theoretical Threat
Not Applicable
CVE-2020-19185NONE0
ncurses-base
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.6
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19186NONE0
ncurses-base
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.6
1.5%
Low-Moderate Risk
Not Applicable
CVE-2020-19187NONE0
ncurses-base
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.6
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19188NONE0
ncurses-base
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.6
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19189NONE0
ncurses-base
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.6
1.9%
Low-Moderate Risk
Not Applicable
CVE-2020-19190NONE0
ncurses-base
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.6
1.4%
Low-Moderate Risk
Not Applicable
CVE-2023-50495NONE0
ncurses-base
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.7
1.0%
Theoretical Threat
Not Applicable
CVE-2020-19185NONE0
ncurses-libs
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.6
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19186NONE0
ncurses-libs
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.6
1.5%
Low-Moderate Risk
Not Applicable
CVE-2020-19187NONE0
ncurses-libs
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.6
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19188NONE0
ncurses-libs
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.6
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19189NONE0
ncurses-libs
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.6
1.9%
Low-Moderate Risk
Not Applicable
CVE-2020-19190NONE0
ncurses-libs
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.6
1.4%
Low-Moderate Risk
Not Applicable
CVE-2023-50495NONE0
ncurses-libs
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.7
1.0%
Theoretical Threat
Not Applicable
CVE-2023-5388NONE0
nss-softokn
3.79.0-4.amzn2
fixed in 3.90.0-6.amzn2.0.1
0.8%
Theoretical Threat
Not Applicable
CVE-2023-5388NONE0
nss-softokn-freebl
3.79.0-4.amzn2
fixed in 3.90.0-6.amzn2.0.1
0.8%
Theoretical Threat
Not Applicable
CVE-2023-2650NONE0
openssl-libs
1:1.0.2k-24.amzn2.0.4
fixed in 1:1.0.2k-24.amzn2.0.7
75.1%
Actively Exploited
Not Applicable
CVE-2026-11972NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.21
0.4%
Theoretical Threat
Not Applicable
CVE-2026-11972NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.21
0.4%
Theoretical Threat
Not Applicable
CVE-2025-67735NONE0
io.netty:netty-codec-http
4.1.77.Final
fixed in 4.2.8.Final, 4.1.129.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-41417NONE0
io.netty:netty-codec-http
4.1.77.Final
fixed in 4.1.133.Final, 4.2.13.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42580NONE0
io.netty:netty-codec-http
4.1.77.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2025-67735NONE0
io.netty:netty-codec-http
4.1.79.Final
fixed in 4.2.8.Final, 4.1.129.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-41417NONE0
io.netty:netty-codec-http
4.1.79.Final
fixed in 4.1.133.Final, 4.2.13.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42580NONE0
io.netty:netty-codec-http
4.1.79.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2022-41915NONE0
io.netty:netty-codec-http
4.1.84.Final
fixed in 4.1.86.Final
0.9%
Theoretical Threat
Not Applicable
CVE-2025-67735NONE0
io.netty:netty-codec-http
4.1.84.Final
fixed in 4.2.8.Final, 4.1.129.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-41417NONE0
io.netty:netty-codec-http
4.1.84.Final
fixed in 4.1.133.Final, 4.2.13.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42580NONE0
io.netty:netty-codec-http
4.1.84.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-59900NONE0
io.netty:netty-codec-http2
4.1.77.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-59900NONE0
io.netty:netty-codec-http2
4.1.79.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2023-34462NONE0
io.netty:netty-handler
4.1.77.Final
fixed in 4.1.94.Final
2.5%
Low-Moderate Risk
Not Applicable
CVE-2023-34462NONE0
io.netty:netty-handler
4.1.79.Final
fixed in 4.1.94.Final
2.5%
Low-Moderate Risk
Not Applicable
CVE-2023-34462NONE0
io.netty:netty-handler
4.1.84.Final
fixed in 4.1.94.Final
2.5%
Low-Moderate Risk
Not Applicable
CVE-2023-44483NONE0
org.apache.santuario:xmlsec
2.2.3
fixed in 2.3.4, 2.2.6, 3.0.3
1.2%
Low-Moderate Risk
Not Applicable
CVE-2024-29857NONE0
org.bouncycastle:bc-fips
1.0.2.3
fixed in 1.0.2.5
1.1%
Low-Moderate Risk
Not Applicable
CVE-2024-29857NONE0
org.bouncycastle:bcprov-jdk15on
1.67
fixed in 1.78
1.1%
Low-Moderate Risk
Not Applicable
CVE-2024-29857NONE0
org.bouncycastle:bcprov-jdk15on
1.70
fixed in 1.78
1.1%
Low-Moderate Risk
Not Applicable
CVE-2025-12183NONE0
org.lz4:lz4-java
1.7.1
fixed in 1.8.1
0.7%
Theoretical Threat
Not Applicable
CVE-2023-20863NONE0
org.springframework:spring-expression
5.3.22
fixed in 6.0.8, 5.3.27, 5.2.24.RELEASE
1.1%
Low-Moderate Risk
Not Applicable
CVE-2023-20861NONE0
org.springframework:spring-expression
5.3.22
fixed in 6.0.7, 5.3.26, 5.2.23.RELEASE
1.0%
Theoretical Threat
Not Applicable
CVE-2026-1757NONE0
libxml2
2.9.1-6.amzn2.5.6
fixed in 2.9.1-6.amzn2.5.24
0.2%
Theoretical Threat
Not Applicable
CVE-2024-0450NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.11
0.3%
Theoretical Threat
Not Applicable
CVE-2024-0450NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.11
0.3%
Theoretical Threat
Not Applicable
CVE-2025-1390NONE0
libcap
2.54-1.amzn2.0.1
fixed in 2.54-1.amzn2.0.3
0.2%
Theoretical Threat
Not Applicable
CVE-2026-6766NONE0
nss
3.79.0-4.amzn2
fixed in 3.90.0-2.amzn2.0.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-6767NONE0
nss
3.79.0-4.amzn2
fixed in 3.90.0-2.amzn2.0.3
0.2%
Theoretical Threat
Not Applicable
CVE-2026-6772NONE0
nss
3.79.0-4.amzn2
fixed in 3.90.0-2.amzn2.0.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-6766NONE0
nss-sysinit
3.79.0-4.amzn2
fixed in 3.90.0-2.amzn2.0.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-6767NONE0
nss-sysinit
3.79.0-4.amzn2
fixed in 3.90.0-2.amzn2.0.3
0.2%
Theoretical Threat
Not Applicable
CVE-2026-6772NONE0
nss-sysinit
3.79.0-4.amzn2
fixed in 3.90.0-2.amzn2.0.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-6766NONE0
nss-tools
3.79.0-4.amzn2
fixed in 3.90.0-2.amzn2.0.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-6767NONE0
nss-tools
3.79.0-4.amzn2
fixed in 3.90.0-2.amzn2.0.3
0.2%
Theoretical Threat
Not Applicable
CVE-2026-6772NONE0
nss-tools
3.79.0-4.amzn2
fixed in 3.90.0-2.amzn2.0.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-6019NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.20
0.2%
Theoretical Threat
Not Applicable
CVE-2026-6019NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.20
0.2%
Theoretical Threat
Not Applicable
CVE-2024-50602NONE0
expat
2.1.0-15.amzn2.0.2
fixed in 2.1.0-15.amzn2.0.5
1.0%
Low-Moderate Risk
Not Applicable
CVE-2024-26458NONE0
krb5-libs
1.15.1-37.amzn2.2.4
fixed in 1.15.1-55.amzn2.2.7
0.8%
Theoretical Threat
Not Applicable
CVE-2024-26461NONE0
krb5-libs
1.15.1-37.amzn2.2.4
fixed in 1.15.1-55.amzn2.2.7
1.1%
Low-Moderate Risk
Not Applicable
CVE-2025-3576NONE0
krb5-libs
1.15.1-37.amzn2.2.4
fixed in 1.15.1-55.amzn2.2.9
0.3%
Theoretical Threat
Not Applicable
CVE-2022-43552NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 7.87.0-2.amzn2.0.1
2.5%
Low-Moderate Risk
Not Applicable
CVE-2023-27535NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 8.0.1-1.amzn2.0.1
1.6%
Low-Moderate Risk
Not Applicable
CVE-2023-27536NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 8.0.1-1.amzn2.0.1
1.6%
Low-Moderate Risk
Not Applicable
CVE-2023-27537NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 8.0.1-1.amzn2.0.1
1.9%
Low-Moderate Risk
Not Applicable
CVE-2023-28321NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 8.2.1-1.amzn2.0.2
1.8%
Low-Moderate Risk
Not Applicable
CVE-2025-10966NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.12
0.4%
Theoretical Threat
Not Applicable
CVE-2025-13151NONE0
libtasn1
4.10-1.amzn2.0.2
fixed in 4.10-1.amzn2.0.8
1.1%
Low-Moderate Risk
Not Applicable
CVE-2026-0990NONE0
libxml2
2.9.1-6.amzn2.5.6
fixed in 2.9.1-6.amzn2.5.22
0.8%
Theoretical Threat
Not Applicable
CVE-2022-4304NONE0
openssl-libs
1:1.0.2k-24.amzn2.0.4
fixed in 1:1.0.2k-24.amzn2.0.6
16.2%
High Exploitation Risk
Not Applicable
CVE-2025-69420NONE0
openssl-libs
1:1.0.2k-24.amzn2.0.4
fixed in 1:1.0.2k-24.amzn2.0.17
0.8%
Theoretical Threat
Not Applicable
CVE-2026-22796NONE0
openssl-libs
1:1.0.2k-24.amzn2.0.4
fixed in 1:1.0.2k-24.amzn2.0.17
0.5%
Theoretical Threat
Not Applicable
CVE-2026-9076NONE0
openssl-libs
1:1.0.2k-24.amzn2.0.4
fixed in 1:1.0.2k-24.amzn2.0.21
0.6%
Theoretical Threat
Not Applicable
CVE-2024-5535NONE0
openssl-libs
1:1.0.2k-24.amzn2.0.4
fixed in 1:1.0.2k-24.amzn2.0.13
5.6%
Low-Moderate Risk
Not Applicable
CVE-2022-48566NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.8
1.1%
Low-Moderate Risk
Not Applicable
CVE-2022-48566NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.8
1.1%
Low-Moderate Risk
Not Applicable
CVE-2026-34477NONE0
org.apache.logging.log4j:log4j-core
2.17.1
fixed in 2.25.4
0.4%
Theoretical Threat
Not Applicable
CVE-2024-30171NONE0
org.bouncycastle:bcprov-jdk15on
1.67
fixed in 1.78
0.9%
Theoretical Threat
Not Applicable
CVE-2024-30171NONE0
org.bouncycastle:bcprov-jdk15on
1.70
fixed in 1.78
0.9%
Theoretical Threat
Not Applicable
CVE-2026-41849NONE0
org.springframework:spring-expression
5.3.22
No fix yet
0.3%
Theoretical Threat
Not Applicable
CVE-2026-41850NONE0
org.springframework:spring-expression
5.3.22
fixed in 7.0.8, 6.2.19
0.4%
Theoretical Threat
Not Applicable
CVE-2024-38808NONE0
org.springframework:spring-expression
5.3.22
fixed in 5.3.39
0.6%
Theoretical Threat
Not Applicable
CVE-2026-59921NONE0
io.netty:netty-codec-http
4.1.77.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-59921NONE0
io.netty:netty-codec-http
4.1.79.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-59921NONE0
io.netty:netty-codec-http
4.1.84.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2025-9230NONE0
openssl-libs
1:1.0.2k-24.amzn2.0.4
fixed in 1:1.0.2k-24.amzn2.0.16
1.7%
Low-Moderate Risk
Not Applicable
CVE-2020-21047NONE0
elfutils-libelf
0.176-2.amzn2
fixed in 0.176-2.amzn2.0.2
0.2%
Theoretical Threat
Not Applicable
CVE-2021-33294NONE0
elfutils-libelf
0.176-2.amzn2
fixed in 0.176-2.amzn2.0.1
0.3%
Theoretical Threat
Not Applicable
CVE-2021-3800NONE0
glib2
2.56.1-9.amzn2.0.2
fixed in 2.56.1-9.amzn2.0.5
0.5%
Theoretical Threat
Not Applicable
CVE-2023-32611NONE0
glib2
2.56.1-9.amzn2.0.2
fixed in 2.56.1-9.amzn2.0.9
0.4%
Theoretical Threat
Not Applicable
CVE-2023-32665NONE0
glib2
2.56.1-9.amzn2.0.2
fixed in 2.56.1-9.amzn2.0.9
0.4%
Theoretical Threat
Not Applicable
CVE-2025-0395NONE0
glibc
2.26-62.amzn2
fixed in 2.26-64.amzn2.0.4
0.3%
Theoretical Threat
Not Applicable
CVE-2025-0395NONE0
glibc-common
2.26-62.amzn2
fixed in 2.26-64.amzn2.0.4
0.3%
Theoretical Threat
Not Applicable
CVE-2025-0395NONE0
glibc-langpack-en
2.26-62.amzn2
fixed in 2.26-64.amzn2.0.4
0.3%
Theoretical Threat
Not Applicable
CVE-2025-0395NONE0
glibc-minimal-langpack
2.26-62.amzn2
fixed in 2.26-64.amzn2.0.4
0.3%
Theoretical Threat
Not Applicable
CVE-2021-37600NONE0
libblkid
2.30.2-2.amzn2.0.10
fixed in 2.30.2-2.amzn2.0.11
0.7%
Theoretical Threat
Not Applicable
CVE-2025-0395NONE0
libcrypt
2.26-62.amzn2
fixed in 2.26-64.amzn2.0.4
0.3%
Theoretical Threat
Not Applicable
CVE-2023-27538NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 8.0.1-1.amzn2.0.1
1.3%
Low-Moderate Risk
Not Applicable
CVE-2021-37600NONE0
libmount
2.30.2-2.amzn2.0.10
fixed in 2.30.2-2.amzn2.0.11
0.7%
Theoretical Threat
Not Applicable
CVE-2021-37600NONE0
libuuid
2.30.2-2.amzn2.0.10
fixed in 2.30.2-2.amzn2.0.11
0.7%
Theoretical Threat
Not Applicable
CVE-2024-34459NONE0
libxml2
2.9.1-6.amzn2.5.6
fixed in 2.9.1-6.amzn2.5.14
2.3%
Low-Moderate Risk
Not Applicable
CVE-2026-7383NONE0
openssl-libs
1:1.0.2k-24.amzn2.0.4
fixed in 1:1.0.2k-24.amzn2.0.21
0.6%
Theoretical Threat
Not Applicable
CVE-2024-0727NONE0
openssl-libs
1:1.0.2k-24.amzn2.0.4
fixed in 1:1.0.2k-24.amzn2.0.12
3.2%
Low-Moderate Risk
Not Applicable
CVE-2025-6075NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.16
0.1%
Theoretical Threat
Not Applicable
CVE-2025-6075NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.16
0.1%
Theoretical Threat
Not Applicable
CVE-2021-3236NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.3%
Theoretical Threat
Not Applicable
CVE-2022-2874NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-3153NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-3278NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.9%
Theoretical Threat
Not Applicable
CVE-2023-2609NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1592-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2023-1264NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1403-1.amzn2.0.1
0.4%
Theoretical Threat
Not Applicable
CVE-2023-1355NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1403-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2023-46246NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2081-1.amzn2.0.1
0.4%
Theoretical Threat
Not Applicable
CVE-2025-24014NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.3
0.3%
Theoretical Threat
Not Applicable
CVE-2023-5441NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.3
0.4%
Theoretical Threat
Not Applicable
CVE-2021-3236NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.3%
Theoretical Threat
Not Applicable
CVE-2022-2874NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-3153NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2022-3278NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1314-1.amzn2.0.1
0.9%
Theoretical Threat
Not Applicable
CVE-2023-2609NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1592-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2023-1264NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1403-1.amzn2.0.1
0.4%
Theoretical Threat
Not Applicable
CVE-2023-1355NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1403-1.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2023-46246NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2081-1.amzn2.0.1
0.4%
Theoretical Threat
Not Applicable
CVE-2025-24014NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.3
0.3%
Theoretical Threat
Not Applicable
CVE-2023-5441NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.3
0.4%
Theoretical Threat
Not Applicable
CVE-2024-47535NONE0
io.netty:netty-common
4.1.79.Final
fixed in 4.1.115.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2025-25193NONE0
io.netty:netty-common
4.1.79.Final
fixed in 4.1.118.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2024-47535NONE0
io.netty:netty-common
4.1.84.Final
fixed in 4.1.115.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2025-25193NONE0
io.netty:netty-common
4.1.84.Final
fixed in 4.1.118.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2024-25710NONE0
org.apache.commons:commons-compress
1.21
fixed in 1.26.0
0.4%
Theoretical Threat
Not Applicable
CVE-2024-26308NONE0
org.apache.commons:commons-compress
1.21
fixed in 1.26.0
0.9%
Theoretical Threat
Not Applicable
CVE-2022-45146NONE0
org.bouncycastle:bc-fips
1.0.2.3
fixed in 1.0.2.4
0.4%
Theoretical Threat
Not Applicable
CVE-2023-33202NONE0
org.bouncycastle:bcprov-jdk15on
1.67
fixed in 1.70
0.9%
Theoretical Threat
Not Applicable
CVE-2019-17595NONE0
ncurses
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.6
2.0%
Low-Moderate Risk
Not Applicable
CVE-2019-17595NONE0
ncurses-base
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.6
2.0%
Low-Moderate Risk
Not Applicable
CVE-2019-17595NONE0
ncurses-libs
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.6
2.0%
Low-Moderate Risk
Not Applicable
CVE-2021-28153NONE0
glib2
2.56.1-9.amzn2.0.2
fixed in 2.56.1-9.amzn2.0.7
2.6%
Low-Moderate Risk
Not Applicable
CVE-2026-4046NONE0
glibc
2.26-62.amzn2
fixed in 2.26-64.amzn2.0.6
0.4%
Theoretical Threat
Not Applicable
CVE-2024-33600NONE0
glibc
2.26-62.amzn2
fixed in 2.26-64.amzn2.0.3
1.2%
Low-Moderate Risk
Not Applicable
CVE-2026-4046NONE0
glibc-common
2.26-62.amzn2
fixed in 2.26-64.amzn2.0.6
0.4%
Theoretical Threat
Not Applicable
CVE-2024-33600NONE0
glibc-common
2.26-62.amzn2
fixed in 2.26-64.amzn2.0.3
1.2%
Low-Moderate Risk
Not Applicable
CVE-2026-4046NONE0
glibc-langpack-en
2.26-62.amzn2
fixed in 2.26-64.amzn2.0.6
0.4%
Theoretical Threat
Not Applicable
CVE-2024-33600NONE0
glibc-langpack-en
2.26-62.amzn2
fixed in 2.26-64.amzn2.0.3
1.2%
Low-Moderate Risk
Not Applicable
CVE-2026-4046NONE0
glibc-minimal-langpack
2.26-62.amzn2
fixed in 2.26-64.amzn2.0.6
0.4%
Theoretical Threat
Not Applicable
CVE-2024-33600NONE0
glibc-minimal-langpack
2.26-62.amzn2
fixed in 2.26-64.amzn2.0.3
1.2%
Low-Moderate Risk
Not Applicable
CVE-2026-4046NONE0
libcrypt
2.26-62.amzn2
fixed in 2.26-64.amzn2.0.6
0.4%
Theoretical Threat
Not Applicable
CVE-2024-33600NONE0
libcrypt
2.26-62.amzn2
fixed in 2.26-64.amzn2.0.3
1.2%
Low-Moderate Risk
Not Applicable
CVE-2024-2004NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.7
1.7%
Low-Moderate Risk
Not Applicable
CVE-2025-9086NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.10
1.3%
Low-Moderate Risk
Not Applicable
CVE-2023-46219NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.5
1.1%
Low-Moderate Risk
Not Applicable
CVE-2024-28182NONE0
libnghttp2
1.41.0-1.amzn2
fixed in 1.41.0-1.amzn2.0.5
84.8%
Actively Exploited
Not Applicable
CVE-2024-12133NONE0
libtasn1
4.10-1.amzn2.0.2
fixed in 4.10-1.amzn2.0.7
1.1%
Low-Moderate Risk
Not Applicable
CVE-2019-17594NONE0
ncurses
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.6
0.5%
Theoretical Threat
Not Applicable
CVE-2019-17594NONE0
ncurses-base
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.6
0.5%
Theoretical Threat
Not Applicable
CVE-2019-17594NONE0
ncurses-libs
6.0-8.20170212.amzn2.1.4
fixed in 6.0-8.20170212.amzn2.1.6
0.5%
Theoretical Threat
Not Applicable
CVE-2026-42766NONE0
openssl-libs
1:1.0.2k-24.amzn2.0.4
fixed in 1:1.0.2k-24.amzn2.0.21
1.0%
Theoretical Threat
Not Applicable
CVE-2023-0465NONE0
openssl-libs
1:1.0.2k-24.amzn2.0.4
fixed in 1:1.0.2k-24.amzn2.0.7
1.6%
Low-Moderate Risk
Not Applicable
CVE-2023-0466NONE0
openssl-libs
1:1.0.2k-24.amzn2.0.4
fixed in 1:1.0.2k-24.amzn2.0.7
1.6%
Low-Moderate Risk
Not Applicable
CVE-2023-3446NONE0
openssl-libs
1:1.0.2k-24.amzn2.0.4
fixed in 1:1.0.2k-24.amzn2.0.9
6.5%
Low-Moderate Risk
Not Applicable
CVE-2023-3817NONE0
openssl-libs
1:1.0.2k-24.amzn2.0.4
fixed in 1:1.0.2k-24.amzn2.0.9
2.6%
Low-Moderate Risk
Not Applicable
CVE-2023-5678NONE0
openssl-libs
1:1.0.2k-24.amzn2.0.4
fixed in 1:1.0.2k-24.amzn2.0.11
4.5%
Low-Moderate Risk
Not Applicable
CVE-2023-27043NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.9
2.5%
Low-Moderate Risk
Not Applicable
CVE-2023-40217NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.12
0.8%
Theoretical Threat
Not Applicable
CVE-2025-12084NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.15
0.7%
Theoretical Threat
Not Applicable
CVE-2023-27043NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.9
2.5%
Low-Moderate Risk
Not Applicable
CVE-2023-40217NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.12
0.8%
Theoretical Threat
Not Applicable
CVE-2025-12084NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.15
0.7%
Theoretical Threat
Not Applicable
CVE-2026-47167NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.7
0.1%
Theoretical Threat
Not Applicable
CVE-2026-47167NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.7
0.1%
Theoretical Threat
Not Applicable
CVE-2026-54514NONE0
com.fasterxml.jackson.core:jackson-databind
2.13.4.2
fixed in 2.18.8, 2.21.4, 3.1.4
0.2%
Theoretical Threat
Not Applicable
CVE-2026-54515NONE0
com.fasterxml.jackson.core:jackson-databind
2.13.4.2
fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1
0.3%
Theoretical Threat
Not Applicable
CVE-2026-54514NONE0
com.fasterxml.jackson.core:jackson-databind
2.14.0
fixed in 2.18.8, 2.21.4, 3.1.4
0.2%
Theoretical Threat
Not Applicable
CVE-2026-54515NONE0
com.fasterxml.jackson.core:jackson-databind
2.14.0
fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1
0.3%
Theoretical Threat
Not Applicable
CVE-2026-54514NONE0
com.fasterxml.jackson.core:jackson-databind
2.14.1
fixed in 2.18.8, 2.21.4, 3.1.4
0.2%
Theoretical Threat
Not Applicable
CVE-2026-54515NONE0
com.fasterxml.jackson.core:jackson-databind
2.14.1
fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1
0.3%
Theoretical Threat
Not Applicable
CVE-2023-51074NONE0
com.jayway.jsonpath:json-path
2.4.0
fixed in 2.9.0
0.7%
Theoretical Threat
Not Applicable
CVE-2024-29025NONE0
io.netty:netty-codec-http
4.1.77.Final
fixed in 4.1.108.Final
1.4%
Low-Moderate Risk
Not Applicable
CVE-2026-50020NONE0
io.netty:netty-codec-http
4.1.77.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Not Applicable
CVE-2026-59898NONE0
io.netty:netty-codec-http
4.1.77.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2024-29025NONE0
io.netty:netty-codec-http
4.1.79.Final
fixed in 4.1.108.Final
1.4%
Low-Moderate Risk
Not Applicable
CVE-2026-50020NONE0
io.netty:netty-codec-http
4.1.79.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Not Applicable
CVE-2026-59898NONE0
io.netty:netty-codec-http
4.1.79.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2024-29025NONE0
io.netty:netty-codec-http
4.1.84.Final
fixed in 4.1.108.Final
1.4%
Low-Moderate Risk
Not Applicable
CVE-2026-50020NONE0
io.netty:netty-codec-http
4.1.84.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Not Applicable
CVE-2026-59898NONE0
io.netty:netty-codec-http
4.1.84.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-47244NONE0
io.netty:netty-codec-http2
4.1.77.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-50560NONE0
io.netty:netty-codec-http2
4.1.77.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-47244NONE0
io.netty:netty-codec-http2
4.1.79.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-50560NONE0
io.netty:netty-codec-http2
4.1.79.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2024-31141NONE0
org.apache.kafka:kafka-clients
3.0.2
fixed in 3.7.1
1.1%
Low-Moderate Risk
Not Applicable
CVE-2025-8885NONE0
org.bouncycastle:bc-fips
1.0.2.3
fixed in 1.0.2.6, 2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2025-8916NONE0
org.bouncycastle:bcpkix-jdk15on
1.70
fixed in 1.79
0.5%
Theoretical Threat
Not Applicable
CVE-2023-33201NONE0
org.bouncycastle:bcprov-jdk15on
1.67
No fix yet
0.8%
Theoretical Threat
Not Applicable
CVE-2024-34447NONE0
org.bouncycastle:bcprov-jdk15on
1.67
fixed in 1.78
0.8%
Theoretical Threat
Not Applicable
CVE-2023-33201NONE0
org.bouncycastle:bcprov-jdk15on
1.70
No fix yet
0.8%
Theoretical Threat
Not Applicable
CVE-2024-34447NONE0
org.bouncycastle:bcprov-jdk15on
1.70
fixed in 1.78
0.8%
Theoretical Threat
Not Applicable
CVE-2021-28170NONE0
org.glassfish:javax.el
3.0.0
No fix yet
2.1%
Low-Moderate Risk
Not Applicable
CVE-2024-38820NONE0
org.springframework:spring-context
5.3.22
fixed in 6.1.14
0.6%
Theoretical Threat
Not Applicable
CVE-2026-41852NONE0
org.springframework:spring-expression
5.3.22
fixed in 7.0.8, 6.2.19
0.2%
Theoretical Threat
Not Applicable
CVE-2026-11850NONE0
krb5-libs
1.15.1-37.amzn2.2.4
fixed in 1.15.1-55.amzn2.2.10
0.3%
Theoretical Threat
Not Applicable
CVE-2026-34180NONE0
openssl-libs
1:1.0.2k-24.amzn2.0.4
fixed in 1:1.0.2k-24.amzn2.0.21
1.0%
Low-Moderate Risk
Not Applicable
CVE-2025-14017NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.12
0.1%
Theoretical Threat
Not Applicable
CVE-2023-4039NONE0
libgcc
7.3.1-15.amzn2
fixed in 7.3.1-17.amzn2
0.8%
Theoretical Threat
Not Applicable
CVE-2023-4039NONE0
libstdc++
7.3.1-15.amzn2
fixed in 7.3.1-17.amzn2
0.8%
Theoretical Threat
Not Applicable
CVE-2025-15282NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.16
0.5%
Theoretical Threat
Not Applicable
CVE-2026-0672NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.16
0.4%
Theoretical Threat
Not Applicable
CVE-2025-15282NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.16
0.5%
Theoretical Threat
Not Applicable
CVE-2026-0672NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.16
0.4%
Theoretical Threat
Not Applicable
CVE-2025-48795NONE0
org.apache.cxf:cxf-core
3.4.5
fixed in 3.5.11, 3.6.6, 4.0.7, 4.1.1
0.6%
Theoretical Threat
Not Applicable
CVE-2025-68161NONE0
org.apache.logging.log4j:log4j-core
2.17.1
fixed in 2.25.3
0.8%
Theoretical Threat
Not Applicable
CVE-2025-15224NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.12
0.4%
Theoretical Threat
Not Applicable
CVE-2025-68160NONE0
openssl-libs
1:1.0.2k-24.amzn2.0.4
fixed in 1:1.0.2k-24.amzn2.0.17
0.2%
Theoretical Threat
Not Applicable
CVE-2024-13176NONE0
openssl-libs
1:1.0.2k-24.amzn2.0.4
fixed in 1:1.0.2k-24.amzn2.0.15
0.6%
Theoretical Threat
Not Applicable
CVE-2023-48706NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.1
0.4%
Theoretical Threat
Not Applicable
CVE-2023-48706NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.1
0.4%
Theoretical Threat
Not Applicable
CVE-2025-11468NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.16
0.5%
Theoretical Threat
Not Applicable
CVE-2026-0865NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.16
0.5%
Theoretical Threat
Not Applicable
CVE-2025-11468NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.16
0.5%
Theoretical Threat
Not Applicable
CVE-2026-0865NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.16
0.5%
Theoretical Threat
Not Applicable
CVE-2024-43802NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.2
0.3%
Theoretical Threat
Not Applicable
CVE-2024-43802NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.2
0.3%
Theoretical Threat
Not Applicable
CVE-2025-29768NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.4
0.3%
Theoretical Threat
Not Applicable
CVE-2025-29768NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.4
0.3%
Theoretical Threat
Not Applicable
CVE-2023-6135NONE0
nss-softokn
3.79.0-4.amzn2
fixed in 3.90.0-6.amzn2.0.2
0.7%
Theoretical Threat
Not Applicable
CVE-2023-6135NONE0
nss-softokn-freebl
3.79.0-4.amzn2
fixed in 3.90.0-6.amzn2.0.2
0.7%
Theoretical Threat
Not Applicable
CVE-2025-6069NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.13
0.5%
Theoretical Threat
Not Applicable
CVE-2025-6069NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.13
0.5%
Theoretical Threat
Not Applicable
CVE-2023-48231NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Not Applicable
CVE-2023-48232NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Not Applicable
CVE-2023-48233NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Not Applicable
CVE-2023-48234NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Not Applicable
CVE-2023-48235NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Not Applicable
CVE-2023-48236NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Not Applicable
CVE-2023-48237NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Not Applicable
CVE-2023-48231NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Not Applicable
CVE-2023-48232NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Not Applicable
CVE-2023-48233NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Not Applicable
CVE-2023-48234NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Not Applicable
CVE-2023-48235NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Not Applicable
CVE-2023-48236NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Not Applicable
CVE-2023-48237NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Not Applicable
CVE-2024-47554NONE0
commons-io:commons-io
2.11.0
fixed in 2.14.0
1.2%
Low-Moderate Risk
Not Applicable
CVE-2024-47554NONE0
commons-io:commons-io
2.7
fixed in 2.14.0
1.2%
Low-Moderate Risk
Not Applicable
CVE-2025-8058NONE0
glibc
2.26-62.amzn2
fixed in 2.26-64.amzn2.0.5
0.2%
Theoretical Threat
Not Applicable
CVE-2025-8058NONE0
glibc-common
2.26-62.amzn2
fixed in 2.26-64.amzn2.0.5
0.2%
Theoretical Threat
Not Applicable
CVE-2025-8058NONE0
glibc-langpack-en
2.26-62.amzn2
fixed in 2.26-64.amzn2.0.5
0.2%
Theoretical Threat
Not Applicable
CVE-2025-8058NONE0
glibc-minimal-langpack
2.26-62.amzn2
fixed in 2.26-64.amzn2.0.5
0.2%
Theoretical Threat
Not Applicable
CVE-2025-8058NONE0
libcrypt
2.26-62.amzn2
fixed in 2.26-64.amzn2.0.5
0.2%
Theoretical Threat
Not Applicable
CVE-2025-26603NONE0
vim-data
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.4
0.2%
Theoretical Threat
Not Applicable
CVE-2025-26603NONE0
vim-minimal
2:9.0.828-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.4
0.2%
Theoretical Threat
Not Applicable
CVE-2023-38546NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.4
6.2%
Low-Moderate Risk
Not Applicable
CVE-2023-28322NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 8.2.1-1.amzn2.0.2
2.2%
Low-Moderate Risk
Not Applicable
CVE-2026-0989NONE0
libxml2
2.9.1-6.amzn2.5.6
fixed in 2.9.1-6.amzn2.5.23
0.4%
Theoretical Threat
Not Applicable
CVE-2024-11168NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.11
0.7%
Theoretical Threat
Not Applicable
CVE-2024-11168NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.11
0.7%
Theoretical Threat
Not Applicable
CVE-2025-48924NONE0
commons-lang:commons-lang
2.4
No fix yet
2.2%
Low-Moderate Risk
Not Applicable
CVE-2025-48924NONE0
commons-lang:commons-lang
2.6
No fix yet
2.2%
Low-Moderate Risk
Not Applicable
CVE-2025-48924NONE0
org.apache.commons:commons-lang3
3.10
fixed in 3.18.0
2.2%
Low-Moderate Risk
Not Applicable
CVE-2025-48924NONE0
org.apache.commons:commons-lang3
3.12.0
fixed in 3.18.0
2.2%
Low-Moderate Risk
Not Applicable
CVE-2025-48924NONE0
org.apache.commons:commons-lang3
3.4
fixed in 3.18.0
2.2%
Low-Moderate Risk
Not Applicable
CVE-2025-48924NONE0
org.apache.commons:commons-lang3
3.9
fixed in 3.18.0
2.2%
Low-Moderate Risk
Not Applicable
CVE-2023-2602NONE0
libcap
2.54-1.amzn2.0.1
fixed in 2.54-1.amzn2.0.2
0.4%
Theoretical Threat
Not Applicable
CVE-2020-19909NONE0
libcurl
7.79.1-7.amzn2.0.1
fixed in 8.2.1-1.amzn2.0.2
0.4%
Theoretical Threat
Not Applicable
CVE-2021-36084NONE0
libsepol
2.5-8.1.amzn2.0.2
fixed in 2.5-10.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2021-36085NONE0
libsepol
2.5-8.1.amzn2.0.2
fixed in 2.5-10.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2021-36086NONE0
libsepol
2.5-8.1.amzn2.0.2
fixed in 2.5-10.amzn2.0.1
0.6%
Theoretical Threat
Not Applicable
CVE-2021-36087NONE0
libsepol
2.5-8.1.amzn2.0.2
fixed in 2.5-10.amzn2.0.1
0.5%
Theoretical Threat
Not Applicable
CVE-2025-8732NONE0
libxml2
2.9.1-6.amzn2.5.6
fixed in 2.9.1-6.amzn2.5.21
0.2%
Theoretical Threat
Not Applicable
CVE-2025-13462NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.18
0.2%
Theoretical Threat
Not Applicable
CVE-2026-4519NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.18
0.3%
Theoretical Threat
Not Applicable
CVE-2026-3479NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.18
0.2%
Theoretical Threat
Not Applicable
CVE-2025-13462NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.18
0.2%
Theoretical Threat
Not Applicable
CVE-2026-4519NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.18
0.3%
Theoretical Threat
Not Applicable
CVE-2026-3479NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.18
0.2%
Theoretical Threat
Not Applicable
CVE-2020-8908NONE0
com.google.guava:guava
30.0-jre
fixed in 32.0.0-android
1.0%
Theoretical Threat
Not Applicable
CVE-2020-8908NONE0
com.google.guava:guava
30.1-jre
fixed in 32.0.0-android
1.0%
Theoretical Threat
Not Applicable
CVE-2020-8908NONE0
com.google.guava:guava
31.0.1-jre
fixed in 32.0.0-android
1.0%
Theoretical Threat
Not Applicable
CVE-2020-8908NONE0
com.google.guava:guava
31.1-android
fixed in 32.0.0-android
1.0%
Theoretical Threat
Not Applicable
CVE-2026-0992NONE0
libxml2
2.9.1-6.amzn2.5.6
fixed in 2.9.1-6.amzn2.5.22
0.4%
Theoretical Threat
Not Applicable
CVE-2024-5642NONE0
python
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.10
0.7%
Theoretical Threat
Not Applicable
CVE-2024-5642NONE0
python-libs
2.7.18-1.amzn2.0.5
fixed in 2.7.18-1.amzn2.0.10
0.7%
Theoretical Threat
Not Applicable
CVE-2015-1197NONE0
cpio
2.11-28.amzn2
fixed in 2.12-11.amzn2.0.1
2.9%
Low-Moderate Risk
Not Applicable
CVE-2023-32803NONE0
ca-certificates
2021.2.50-72.amzn2.0.3
fixed in 2021.2.50-72.amzn2.0.7
Not Applicable
CVE-2026-53615NONE0
libblkid
2.30.2-2.amzn2.0.10
fixed in 2.30.2-2.amzn2.0.14
Not Applicable
CVE-2026-53615NONE0
libmount
2.30.2-2.amzn2.0.10
fixed in 2.30.2-2.amzn2.0.14
Not Applicable
CVE-2026-53615NONE0
libuuid
2.30.2-2.amzn2.0.10
fixed in 2.30.2-2.amzn2.0.14
Not Applicable
CVE-2024-37902NONE0
ai.djl:api
0.19.0
fixed in 0.28.0
0.7%
Theoretical Threat
Not Applicable
CVE-2025-0851NONE0
ai.djl:api
0.19.0
fixed in 0.31.1
23.3%
High Exploitation Risk
Not Applicable
GHSA-r7wm-3cxj-wff9NONE0
com.fasterxml.jackson.core:jackson-core
2.13.4
fixed in 2.18.8, 2.21.4, 2.22.1
Not Applicable
GHSA-72hv-8253-57qqNONE0
com.fasterxml.jackson.core:jackson-core
2.13.4
fixed in 2.21.1, 2.18.6
Not Applicable
GHSA-r7wm-3cxj-wff9NONE0
com.fasterxml.jackson.core:jackson-core
2.14.1
fixed in 2.18.8, 2.21.4, 2.22.1
Not Applicable
GHSA-72hv-8253-57qqNONE0
com.fasterxml.jackson.core:jackson-core
2.14.1
fixed in 2.21.1, 2.18.6
Not Applicable
GHSA-xpw8-rcwv-8f8pNONE0
io.netty:netty-codec-http2
4.1.77.Final
fixed in 4.1.100.Final
Not Applicable
GHSA-xpw8-rcwv-8f8pNONE0
io.netty:netty-codec-http2
4.1.79.Final
fixed in 4.1.100.Final
Not Applicable
CVE-2026-33558NONE0
org.apache.kafka:kafka-clients
3.0.2
fixed in 3.9.2, 4.0.1
0.6%
Theoretical Threat
Not Applicable
CVE-2026-59949NONE0
org.lz4:lz4-java
1.7.1
No fix yet
Not Applicable
GHSA-6g3j-p5g6-992fNONE0
org.opensearch:opensearch
2.4.1
fixed in 1.3.14, 2.11.1
Not Applicable
CVE-2025-22233NONE0
org.springframework:spring-context
5.3.22
fixed in 6.2.7, 6.1.20
0.4%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.