Vulnerability Reportopensearchproject/opensearch:2.8.0

opensearchproject/opensearch:2.8.0
digestsha256:7d7f306996c0901956e0c413c817f4e249bd3d27c9c9ea6460bd7da88df73039

Executive Summary

Last scanned:

Threat Score
74/100CAUTION
Reputation
TRUSTED

This image carries significant risk; production deployment is highly discouraged without strict compensating controls. The exposure surface is broad, with 216 detected issues and a maximum severity of 8.33; an attacker could remotely exploit the Netty request smuggling flaw (CVE-2026-42581) to bypass HTTP boundaries on the OpenSearch REST API, or trigger denial of service via libexpat parsing issues (CVE-2024-45490). Upgrading Netty and libexpat to patched versions would fully address these specific vulnerabilities. Note that some high-severity issues such as the OpenSSL delta CRL NULL pointer dereference require non-default configuration flags (X509_V_FLAG_USE_DELTAS) to be exploitable.

Vulnerabilities

Vulnerability Log

448 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-42581HIGH8.33
io.netty:netty-codec-http
4.1.91.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.6%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2022-23990HIGH7.5
expat
2.1.0-15.amzn2.0.2
fixed in 2.1.0-15.amzn2.0.3
4.0%
Low-Moderate Risk
Directly Exposed
CVE-2024-45490HIGH7.5
expat
2.1.0-15.amzn2.0.2
fixed in 2.1.0-15.amzn2.0.4
1.7%
Low-Moderate Risk
Directly Exposed
CVE-2023-35945HIGH7.5
libnghttp2
1.41.0-1.amzn2
fixed in 1.41.0-1.amzn2.0.1
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2025-27113HIGH7.5
libxml2
2.9.1-6.amzn2.5.8
fixed in 2.9.1-6.amzn2.5.16
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2025-6021HIGH7.5
libxml2
2.9.1-6.amzn2.5.8
fixed in 2.9.1-6.amzn2.5.18
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-28388HIGH7.5
openssl-libs
1:1.0.2k-24.amzn2.0.7
fixed in 1:1.0.2k-24.amzn2.0.20
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-28389HIGH7.5
openssl-libs
1:1.0.2k-24.amzn2.0.7
fixed in 1:1.0.2k-24.amzn2.0.20
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-28390HIGH7.5
openssl-libs
1:1.0.2k-24.amzn2.0.7
fixed in 1:1.0.2k-24.amzn2.0.20
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2024-7254HIGH7.5
com.google.protobuf:protobuf-java
3.22.1
fixed in 3.25.5, 4.27.5, 4.28.2
2.8%
Low-Moderate Risk
Directly Exposed
CVE-2023-3635HIGH7.5
com.squareup.okio:okio
2.8.0
fixed in 3.4.0, 1.17.6
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2025-55163HIGH7.5
io.netty:netty-codec-http2
4.1.91.Final
fixed in 4.2.4.Final, 4.1.124.Final
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-33871HIGH7.5
io.netty:netty-codec-http2
4.1.91.Final
fixed in 4.1.132.Final, 4.2.11.Final
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2025-24970HIGH7.5
io.netty:netty-handler
4.1.91.Final
fixed in 4.1.118.Final
2.1%
Low-Moderate Risk
Directly Exposed
CVE-2025-23184HIGH7.5
org.apache.cxf:cxf-core
3.5.5
fixed in 3.5.10, 3.6.5, 4.0.6
2.0%
Low-Moderate Risk
Directly Exposed
CVE-2024-32007HIGH7.5
org.apache.cxf:cxf-rt-rs-security-jose
3.5.5
fixed in 4.0.5, 3.6.4, 3.5.9
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2023-5072HIGH7.5
org.json:json
20230227
fixed in 20231013
1.4%
Low-Moderate Risk
Directly Exposed
CVE-2023-34455HIGH7.5
org.xerial.snappy:snappy-java
1.1.8.4
fixed in 1.1.10.1
1.8%
Low-Moderate Risk
Directly Exposed
CVE-2023-43642HIGH7.5
org.xerial.snappy:snappy-java
1.1.8.4
fixed in 1.1.10.4
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2023-34453HIGH7.5
org.xerial.snappy:snappy-java
1.1.8.4
fixed in 1.1.10.1
1.7%
Low-Moderate Risk
Directly Exposed
CVE-2023-34454HIGH7.5
org.xerial.snappy:snappy-java
1.1.8.4
fixed in 1.1.10.1
1.5%
Low-Moderate Risk
Directly Exposed
CVE-2023-7104HIGH7.3
nss
3.79.0-4.amzn2.0.1
fixed in 3.90.0-2.amzn2.0.2
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2023-7104HIGH7.3
nss-sysinit
3.79.0-4.amzn2.0.1
fixed in 3.90.0-2.amzn2.0.2
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2024-28182MEDIUM6.89
libnghttp2
1.41.0-1.amzn2
fixed in 1.41.0-1.amzn2.0.5
84.8%
Actively Exploited
Directly Exposed
CVE-2026-54512MEDIUM6.88
com.fasterxml.jackson.core:jackson-databind
2.14.1
fixed in 2.18.8, 3.1.4, 2.21.4
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-54513MEDIUM6.88
com.fasterxml.jackson.core:jackson-databind
2.14.1
fixed in 2.18.8, 2.21.4, 3.1.4
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-54512MEDIUM6.88
com.fasterxml.jackson.core:jackson-databind
2.15.1
fixed in 2.18.8, 3.1.4, 2.21.4
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-54513MEDIUM6.88
com.fasterxml.jackson.core:jackson-databind
2.15.1
fixed in 2.18.8, 2.21.4, 3.1.4
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-44249MEDIUM6.88
io.netty:netty-handler
4.1.91.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-25210MEDIUM6.63
expat
2.1.0-15.amzn2.0.2
fixed in 2.1.0-15.amzn2.0.6
0.2%
Theoretical Threat
Directly Exposed
CVE-2020-35457MEDIUM6.63
glib2
2.56.1-9.amzn2.0.6
fixed in 2.56.1-9.amzn2.0.8
0.6%
Theoretical Threat
Directly Exposed
CVE-2023-32643MEDIUM6.63
glib2
2.56.1-9.amzn2.0.6
fixed in 2.56.1-9.amzn2.0.9
0.4%
Theoretical Threat
Directly Exposed
CVE-2022-49043MEDIUM6.63
libxml2
2.9.1-6.amzn2.5.8
fixed in 2.9.1-6.amzn2.5.15
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-7425MEDIUM6.63
libxml2
2.9.1-6.amzn2.5.8
fixed in 2.9.1-6.amzn2.5.20
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-13601MEDIUM6.54
glib2
2.56.1-9.amzn2.0.6
fixed in 2.56.1-9.amzn2.0.12
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-24928MEDIUM6.54
libxml2
2.9.1-6.amzn2.5.8
fixed in 2.9.1-6.amzn2.5.16
0.4%
Theoretical Threat
Directly Exposed
CVE-2022-25313MEDIUM6.5
expat
2.1.0-15.amzn2.0.2
fixed in 2.1.0-15.amzn2.0.3
3.3%
Low-Moderate Risk
Directly Exposed
CVE-2023-36054MEDIUM6.5
krb5-libs
1.15.1-55.amzn2.2.5
fixed in 1.15.1-55.amzn2.2.6
2.8%
Low-Moderate Risk
Directly Exposed
CVE-2023-34462MEDIUM6.5
io.netty:netty-handler
4.1.91.Final
fixed in 4.1.94.Final
2.5%
Low-Moderate Risk
Directly Exposed
CVE-2023-44483MEDIUM6.5
org.apache.santuario:xmlsec
2.2.3
fixed in 2.3.4, 2.2.6, 3.0.3
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2024-29857MEDIUM6.5
org.bouncycastle:bc-fips
1.0.2.3
fixed in 1.0.2.5
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2024-29857MEDIUM6.5
org.bouncycastle:bcprov-jdk15on
1.67
fixed in 1.78
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2024-29857MEDIUM6.5
org.bouncycastle:bcprov-jdk15on
1.70
fixed in 1.78
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2023-32636MEDIUM6.38
glib2
2.56.1-9.amzn2.0.6
fixed in 2.56.1-9.amzn2.0.9
0.8%
Theoretical Threat
Directly Exposed
CVE-2023-29499MEDIUM6.38
glib2
2.56.1-9.amzn2.0.6
fixed in 2.56.1-9.amzn2.0.9
0.8%
Theoretical Threat
Directly Exposed
CVE-2024-37370MEDIUM6.38
krb5-libs
1.15.1-55.amzn2.2.5
fixed in 1.15.1-55.amzn2.2.8
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-27135MEDIUM6.38
libnghttp2
1.41.0-1.amzn2
fixed in 1.41.0-1.amzn2.0.6
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-32414MEDIUM6.38
libxml2
2.9.1-6.amzn2.5.8
fixed in 2.9.1-6.amzn2.5.17
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-32415MEDIUM6.38
libxml2
2.9.1-6.amzn2.5.8
fixed in 2.9.1-6.amzn2.5.17
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-69421MEDIUM6.38
openssl-libs
1:1.0.2k-24.amzn2.0.7
fixed in 1:1.0.2k-24.amzn2.0.17
0.8%
Theoretical Threat
Directly Exposed
CVE-2023-1428MEDIUM6.38
io.grpc:grpc-protobuf
1.52.1
fixed in 1.53.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42583MEDIUM6.38
io.netty:netty-codec
4.1.91.Final
fixed in 4.1.133.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59901MEDIUM6.38
io.netty:netty-codec
4.1.91.Final
fixed in 4.1.136.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-58057MEDIUM6.38
io.netty:netty-codec
4.1.91.Final
fixed in 4.1.125.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-33870MEDIUM6.38
io.netty:netty-codec-http
4.1.91.Final
fixed in 4.1.132.Final, 4.2.10.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42587MEDIUM6.38
io.netty:netty-codec-http
4.1.91.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-55831MEDIUM6.38
io.netty:netty-codec-http
4.1.91.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-55833MEDIUM6.38
io.netty:netty-codec-http
4.1.91.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-56745MEDIUM6.38
io.netty:netty-codec-http
4.1.91.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42585MEDIUM6.38
io.netty:netty-codec-http
4.1.91.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-56746MEDIUM6.38
io.netty:netty-codec-http
4.1.91.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59899MEDIUM6.38
io.netty:netty-codec-http
4.1.91.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-58056MEDIUM6.38
io.netty:netty-codec-http
4.1.91.Final
fixed in 4.1.125.Final, 4.2.5.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42587MEDIUM6.38
io.netty:netty-codec-http2
4.1.91.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-48043MEDIUM6.38
io.netty:netty-codec-http2
4.1.91.Final
fixed in 4.1.135.Final, 4.2.15.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-45416MEDIUM6.38
io.netty:netty-handler
4.1.91.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-50010MEDIUM6.38
io.netty:netty-handler
4.1.91.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42578MEDIUM6.38
io.netty:netty-handler-proxy
4.1.91.Final
fixed in 4.1.133.Final, 4.2.13.Final
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-34480MEDIUM6.38
org.apache.logging.log4j:log4j-core
2.17.1
fixed in 2.25.4
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-5588MEDIUM6.38
org.bouncycastle:bcpkix-jdk15on
1.70
fixed in 1.84
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-66566MEDIUM6.38
org.lz4:lz4-java
1.8.0
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-9624MEDIUM6.38
org.opensearch:opensearch-common
2.8.0
fixed in 3.3.0, 2.19.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-21634MEDIUM6.38
software.amazon.ion:ion-java
1.0.2
fixed in 1.10.5
0.8%
Theoretical Threat
Directly Exposed
CVE-2023-2976MEDIUM6.03
com.google.guava:guava
30.0-jre
fixed in 32.0.0-android
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-2976MEDIUM6.03
com.google.guava:guava
31.0.1-jre
fixed in 32.0.0-android
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-2976MEDIUM6.03
com.google.guava:guava
31.1-jre
fixed in 32.0.0-android
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-50602MEDIUM5.9
expat
2.1.0-15.amzn2.0.2
fixed in 2.1.0-15.amzn2.0.5
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2024-26461MEDIUM5.9
krb5-libs
1.15.1-55.amzn2.2.5
fixed in 1.15.1-55.amzn2.2.7
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2025-13151MEDIUM5.9
libtasn1
4.10-1.amzn2.0.3
fixed in 4.10-1.amzn2.0.8
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2024-5535MEDIUM5.9
openssl-libs
1:1.0.2k-24.amzn2.0.7
fixed in 1:1.0.2k-24.amzn2.0.13
5.6%
Low-Moderate Risk
Directly Exposed
CVE-2026-56132MEDIUM5.87
expat
2.1.0-15.amzn2.0.2
fixed in 2.1.0-15.amzn2.0.7
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56403MEDIUM5.87
expat
2.1.0-15.amzn2.0.2
fixed in 2.1.0-15.amzn2.0.8
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56406MEDIUM5.87
expat
2.1.0-15.amzn2.0.2
fixed in 2.1.0-15.amzn2.0.8
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56407MEDIUM5.87
expat
2.1.0-15.amzn2.0.2
fixed in 2.1.0-15.amzn2.0.8
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-35554MEDIUM5.78
org.apache.kafka:kafka-clients
3.4.0
fixed in 3.9.2, 4.0.2, 4.1.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-9230MEDIUM5.6
openssl-libs
1:1.0.2k-24.amzn2.0.7
fixed in 1:1.0.2k-24.amzn2.0.16
1.7%
Low-Moderate Risk
Directly Exposed
CVE-2025-24528MEDIUM5.52
krb5-libs
1.15.1-55.amzn2.2.5
fixed in 1.15.1-55.amzn2.2.9
0.6%
Theoretical Threat
Directly Exposed
CVE-2023-45322MEDIUM5.52
libxml2
2.9.1-6.amzn2.5.8
fixed in 2.9.1-6.amzn2.5.13
0.8%
Theoretical Threat
Directly Exposed
CVE-2023-39615MEDIUM5.52
libxml2
2.9.1-6.amzn2.5.8
fixed in 2.9.1-6.amzn2.5.11
0.7%
Theoretical Threat
Directly Exposed
CVE-2023-5388MEDIUM5.52
nss-softokn
3.79.0-4.amzn2
fixed in 3.90.0-6.amzn2.0.1
0.8%
Theoretical Threat
Directly Exposed
CVE-2023-5388MEDIUM5.52
nss-softokn-freebl
3.79.0-4.amzn2
fixed in 3.90.0-6.amzn2.0.1
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-59888MEDIUM5.52
com.fasterxml.jackson.core:jackson-databind
2.15.1
fixed in 2.18.8, 2.21.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-67735MEDIUM5.52
io.netty:netty-codec-http
4.1.91.Final
fixed in 4.2.8.Final, 4.1.129.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-41417MEDIUM5.52
io.netty:netty-codec-http
4.1.91.Final
fixed in 4.1.133.Final, 4.2.13.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42580MEDIUM5.52
io.netty:netty-codec-http
4.1.91.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59900MEDIUM5.52
io.netty:netty-codec-http2
4.1.91.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-12183MEDIUM5.52
org.lz4:lz4-java
1.8.0
fixed in 1.8.1
0.7%
Theoretical Threat
Directly Exposed
CVE-2024-34459MEDIUM5.5
libxml2
2.9.1-6.amzn2.5.8
fixed in 2.9.1-6.amzn2.5.14
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2024-0727MEDIUM5.5
openssl-libs
1:1.0.2k-24.amzn2.0.7
fixed in 1:1.0.2k-24.amzn2.0.12
3.2%
Low-Moderate Risk
Directly Exposed
CVE-2021-28153MEDIUM5.3
glib2
2.56.1-9.amzn2.0.6
fixed in 2.56.1-9.amzn2.0.7
2.6%
Low-Moderate Risk
Directly Exposed
CVE-2024-33600MEDIUM5.3
glibc
2.26-63.amzn2
fixed in 2.26-64.amzn2.0.3
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2024-33600MEDIUM5.3
glibc-common
2.26-63.amzn2
fixed in 2.26-64.amzn2.0.3
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2024-33600MEDIUM5.3
glibc-langpack-en
2.26-63.amzn2
fixed in 2.26-64.amzn2.0.3
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2024-33600MEDIUM5.3
glibc-minimal-langpack
2.26-63.amzn2
fixed in 2.26-64.amzn2.0.3
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2024-33600MEDIUM5.3
libcrypt
2.26-63.amzn2
fixed in 2.26-64.amzn2.0.3
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2024-12133MEDIUM5.3
libtasn1
4.10-1.amzn2.0.3
fixed in 4.10-1.amzn2.0.7
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2023-3446MEDIUM5.3
openssl-libs
1:1.0.2k-24.amzn2.0.7
fixed in 1:1.0.2k-24.amzn2.0.9
6.5%
Low-Moderate Risk
Directly Exposed
CVE-2023-3817MEDIUM5.3
openssl-libs
1:1.0.2k-24.amzn2.0.7
fixed in 1:1.0.2k-24.amzn2.0.9
2.6%
Low-Moderate Risk
Directly Exposed
CVE-2023-5678MEDIUM5.3
openssl-libs
1:1.0.2k-24.amzn2.0.7
fixed in 1:1.0.2k-24.amzn2.0.11
4.5%
Low-Moderate Risk
Directly Exposed
CVE-2024-29025MEDIUM5.3
io.netty:netty-codec-http
4.1.91.Final
fixed in 4.1.108.Final
1.4%
Low-Moderate Risk
Directly Exposed
CVE-2024-31141MEDIUM5.3
org.apache.kafka:kafka-clients
3.4.0
fixed in 3.7.1
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2021-28170MEDIUM5.3
org.glassfish:javax.el
3.0.0
No fix yet
2.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-1757MEDIUM5.27
libxml2
2.9.1-6.amzn2.5.8
fixed in 2.9.1-6.amzn2.5.24
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-1390MEDIUM5.18
libcap
2.54-1.amzn2.0.1
fixed in 2.54-1.amzn2.0.3
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-6766MEDIUM5.18
nss
3.79.0-4.amzn2.0.1
fixed in 3.90.0-2.amzn2.0.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6767MEDIUM5.18
nss
3.79.0-4.amzn2.0.1
fixed in 3.90.0-2.amzn2.0.3
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-6772MEDIUM5.18
nss
3.79.0-4.amzn2.0.1
fixed in 3.90.0-2.amzn2.0.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6766MEDIUM5.18
nss-sysinit
3.79.0-4.amzn2.0.1
fixed in 3.90.0-2.amzn2.0.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-6767MEDIUM5.18
nss-sysinit
3.79.0-4.amzn2.0.1
fixed in 3.90.0-2.amzn2.0.3
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-6772MEDIUM5.18
nss-sysinit
3.79.0-4.amzn2.0.1
fixed in 3.90.0-2.amzn2.0.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-26458MEDIUM5.02
krb5-libs
1.15.1-55.amzn2.2.5
fixed in 1.15.1-55.amzn2.2.7
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-3576MEDIUM5.02
krb5-libs
1.15.1-55.amzn2.2.5
fixed in 1.15.1-55.amzn2.2.9
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-0990MEDIUM5.02
libxml2
2.9.1-6.amzn2.5.8
fixed in 2.9.1-6.amzn2.5.22
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-69420MEDIUM5.02
openssl-libs
1:1.0.2k-24.amzn2.0.7
fixed in 1:1.0.2k-24.amzn2.0.17
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-22796MEDIUM5.02
openssl-libs
1:1.0.2k-24.amzn2.0.7
fixed in 1:1.0.2k-24.amzn2.0.17
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
openssl-libs
1:1.0.2k-24.amzn2.0.7
fixed in 1:1.0.2k-24.amzn2.0.21
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-34477MEDIUM5.02
org.apache.logging.log4j:log4j-core
2.17.1
fixed in 2.25.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-30171MEDIUM5.02
org.bouncycastle:bcprov-jdk15on
1.67
fixed in 1.78
0.9%
Theoretical Threat
Directly Exposed
CVE-2024-30171MEDIUM5.02
org.bouncycastle:bcprov-jdk15on
1.70
fixed in 1.78
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM5
openssl-libs
1:1.0.2k-24.amzn2.0.7
fixed in 1:1.0.2k-24.amzn2.0.21
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-59921MEDIUM4.84
io.netty:netty-codec-http
4.1.91.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2007-4559MEDIUM4.69
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.12
27.1%
High Exploitation Risk
Post-Exploit
CVE-2020-21047MEDIUM4.67
elfutils-libelf
0.176-2.amzn2
fixed in 0.176-2.amzn2.0.2
0.2%
Theoretical Threat
Directly Exposed
CVE-2021-33294MEDIUM4.67
elfutils-libelf
0.176-2.amzn2
fixed in 0.176-2.amzn2.0.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2023-32611MEDIUM4.67
glib2
2.56.1-9.amzn2.0.6
fixed in 2.56.1-9.amzn2.0.9
0.4%
Theoretical Threat
Directly Exposed
CVE-2023-32665MEDIUM4.67
glib2
2.56.1-9.amzn2.0.6
fixed in 2.56.1-9.amzn2.0.9
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-0395MEDIUM4.67
glibc
2.26-63.amzn2
fixed in 2.26-64.amzn2.0.4
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-0395MEDIUM4.67
glibc-common
2.26-63.amzn2
fixed in 2.26-64.amzn2.0.4
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-0395MEDIUM4.67
glibc-langpack-en
2.26-63.amzn2
fixed in 2.26-64.amzn2.0.4
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-0395MEDIUM4.67
glibc-minimal-langpack
2.26-63.amzn2
fixed in 2.26-64.amzn2.0.4
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-0395MEDIUM4.67
libcrypt
2.26-63.amzn2
fixed in 2.26-64.amzn2.0.4
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
openssl-libs
1:1.0.2k-24.amzn2.0.7
fixed in 1:1.0.2k-24.amzn2.0.21
0.6%
Theoretical Threat
Directly Exposed
CVE-2024-47535MEDIUM4.67
io.netty:netty-common
4.1.91.Final
fixed in 4.1.115.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-25193MEDIUM4.67
io.netty:netty-common
4.1.91.Final
fixed in 4.1.118.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-25710MEDIUM4.67
org.apache.commons:commons-compress
1.21
fixed in 1.26.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-26308MEDIUM4.67
org.apache.commons:commons-compress
1.21
fixed in 1.26.0
0.9%
Theoretical Threat
Directly Exposed
CVE-2023-42503MEDIUM4.67
org.apache.commons:commons-compress
1.23.0
fixed in 1.24.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2024-25710MEDIUM4.67
org.apache.commons:commons-compress
1.23.0
fixed in 1.26.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-26308MEDIUM4.67
org.apache.commons:commons-compress
1.23.0
fixed in 1.26.0
0.9%
Theoretical Threat
Directly Exposed
CVE-2022-45146MEDIUM4.67
org.bouncycastle:bc-fips
1.0.2.3
fixed in 1.0.2.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2023-33202MEDIUM4.67
org.bouncycastle:bcprov-ext-jdk15on
1.70
fixed in 1.73
0.9%
Theoretical Threat
Directly Exposed
CVE-2023-33202MEDIUM4.67
org.bouncycastle:bcprov-jdk15on
1.67
fixed in 1.70
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-7598MEDIUM4.64
libssh2
1.4.3-12.amzn2.2.4
fixed in 1.4.3-12.amzn2.2.7
0.5%
Theoretical Threat
Post-Exploit
CVE-2023-38545MEDIUM4.58
curl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.4
78.5%
Actively Exploited
Post-Exploit
CVE-2023-38545MEDIUM4.58
libcurl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.4
78.5%
Actively Exploited
Post-Exploit
CVE-2023-28319MEDIUM4.5
curl
8.0.1-1.amzn2.0.1
fixed in 8.2.1-1.amzn2.0.2
2.5%
Low-Moderate Risk
Post-Exploit
CVE-2023-28319MEDIUM4.5
libcurl
8.0.1-1.amzn2.0.1
fixed in 8.2.1-1.amzn2.0.2
2.5%
Low-Moderate Risk
Post-Exploit
CVE-2024-7592MEDIUM4.5
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.11
2.3%
Low-Moderate Risk
Post-Exploit
CVE-2024-7592MEDIUM4.5
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.11
2.3%
Low-Moderate Risk
Post-Exploit
CVE-2023-5344MEDIUM4.5
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.2
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2023-5344MEDIUM4.5
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.2
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-4046MEDIUM4.5
glibc
2.26-63.amzn2
fixed in 2.26-64.amzn2.0.6
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc-common
2.26-63.amzn2
fixed in 2.26-64.amzn2.0.6
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc-langpack-en
2.26-63.amzn2
fixed in 2.26-64.amzn2.0.6
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc-minimal-langpack
2.26-63.amzn2
fixed in 2.26-64.amzn2.0.6
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
libcrypt
2.26-63.amzn2
fixed in 2.26-64.amzn2.0.6
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
openssl-libs
1:1.0.2k-24.amzn2.0.7
fixed in 1:1.0.2k-24.amzn2.0.21
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-54514MEDIUM4.5
com.fasterxml.jackson.core:jackson-databind
2.14.1
fixed in 2.18.8, 2.21.4, 3.1.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-54515MEDIUM4.5
com.fasterxml.jackson.core:jackson-databind
2.14.1
fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-54514MEDIUM4.5
com.fasterxml.jackson.core:jackson-databind
2.15.1
fixed in 2.18.8, 2.21.4, 3.1.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-54515MEDIUM4.5
com.fasterxml.jackson.core:jackson-databind
2.15.1
fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2023-51074MEDIUM4.5
com.jayway.jsonpath:json-path
2.4.0
fixed in 2.9.0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-50020MEDIUM4.5
io.netty:netty-codec-http
4.1.91.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-59898MEDIUM4.5
io.netty:netty-codec-http
4.1.91.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-47244MEDIUM4.5
io.netty:netty-codec-http2
4.1.91.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-50560MEDIUM4.5
io.netty:netty-codec-http2
4.1.91.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-8885MEDIUM4.5
org.bouncycastle:bc-fips
1.0.2.3
fixed in 1.0.2.6, 2.0.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-8916MEDIUM4.5
org.bouncycastle:bcpkix-jdk15on
1.70
fixed in 1.79
0.5%
Theoretical Threat
Directly Exposed
CVE-2023-33201MEDIUM4.5
org.bouncycastle:bcprov-ext-jdk15on
1.70
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2023-33201MEDIUM4.5
org.bouncycastle:bcprov-jdk15on
1.67
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2024-34447MEDIUM4.5
org.bouncycastle:bcprov-jdk15on
1.67
fixed in 1.78
0.8%
Theoretical Threat
Directly Exposed
CVE-2023-33201MEDIUM4.5
org.bouncycastle:bcprov-jdk15on
1.70
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2024-34447MEDIUM4.5
org.bouncycastle:bcprov-jdk15on
1.70
fixed in 1.78
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-47162MEDIUM4.49
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-47162MEDIUM4.49
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2023-7104MEDIUM4.38
nss-tools
3.79.0-4.amzn2.0.1
fixed in 3.90.0-2.amzn2.0.2
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2024-47554MEDIUM4.3
commons-io:commons-io
2.11.0
fixed in 2.14.0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2024-47554MEDIUM4.3
commons-io:commons-io
2.7
fixed in 2.14.0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2024-47554MEDIUM4.3
commons-io:commons-io
2.8.0
fixed in 2.14.0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-11850MEDIUM4.25
krb5-libs
1.15.1-55.amzn2.2.5
fixed in 1.15.1-55.amzn2.2.10
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-34982MEDIUM4.18
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.5
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-34982MEDIUM4.18
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.5
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-15079MEDIUM4.13
curl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.12
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-15079MEDIUM4.13
libcurl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.12
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-6100MEDIUM4.13
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.19
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-6100MEDIUM4.13
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.19
0.6%
Theoretical Threat
Post-Exploit
CVE-2024-2961MEDIUM4.12
glibc
2.26-63.amzn2
fixed in 2.26-64.amzn2.0.1
88.3%
Actively Exploited
Post-Exploit
CVE-2024-2961MEDIUM4.12
glibc-common
2.26-63.amzn2
fixed in 2.26-64.amzn2.0.1
88.3%
Actively Exploited
Post-Exploit
CVE-2024-2961MEDIUM4.12
glibc-langpack-en
2.26-63.amzn2
fixed in 2.26-64.amzn2.0.1
88.3%
Actively Exploited
Post-Exploit
CVE-2024-2961MEDIUM4.12
glibc-minimal-langpack
2.26-63.amzn2
fixed in 2.26-64.amzn2.0.1
88.3%
Actively Exploited
Post-Exploit
CVE-2024-2961MEDIUM4.12
libcrypt
2.26-63.amzn2
fixed in 2.26-64.amzn2.0.1
88.3%
Actively Exploited
Post-Exploit
CVE-2025-0938MEDIUM4.08
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.11
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2025-0938MEDIUM4.08
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.11
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2023-4039MEDIUM4.08
libgcc
7.3.1-15.amzn2
fixed in 7.3.1-17.amzn2
0.8%
Theoretical Threat
Directly Exposed
CVE-2023-4039MEDIUM4.08
libstdc++
7.3.1-15.amzn2
fixed in 7.3.1-17.amzn2
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-48795MEDIUM4.08
org.apache.cxf:cxf-core
3.5.5
fixed in 3.5.11, 3.6.6, 4.0.7, 4.1.1
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-68161MEDIUM4.08
org.apache.logging.log4j:log4j-core
2.17.1
fixed in 2.25.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-68160MEDIUM4
openssl-libs
1:1.0.2k-24.amzn2.0.7
fixed in 1:1.0.2k-24.amzn2.0.17
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-13176MEDIUM4
openssl-libs
1:1.0.2k-24.amzn2.0.7
fixed in 1:1.0.2k-24.amzn2.0.15
0.6%
Theoretical Threat
Directly Exposed
CVE-2023-4733LOW3.98
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.5%
Theoretical Threat
Post-Exploit
CVE-2023-4734LOW3.98
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2023-4735LOW3.98
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2023-4738LOW3.98
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2023-4750LOW3.98
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.5%
Theoretical Threat
Post-Exploit
CVE-2023-4751LOW3.98
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2023-4752LOW3.98
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2023-4781LOW3.98
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-52858LOW3.98
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-52860LOW3.98
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-55693LOW3.98
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.8
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-55895LOW3.98
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-57456LOW3.98
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.8
0.1%
Theoretical Threat
Post-Exploit
CVE-2024-22667LOW3.98
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-1215LOW3.98
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.4
0.5%
Theoretical Threat
Post-Exploit
CVE-2023-5535LOW3.98
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.3
0.5%
Theoretical Threat
Post-Exploit
CVE-2023-4733LOW3.98
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.5%
Theoretical Threat
Post-Exploit
CVE-2023-4734LOW3.98
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2023-4735LOW3.98
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2023-4738LOW3.98
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2023-4750LOW3.98
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.5%
Theoretical Threat
Post-Exploit
CVE-2023-4751LOW3.98
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2023-4752LOW3.98
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2023-4781LOW3.98
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-52858LOW3.98
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-52860LOW3.98
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-55693LOW3.98
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.8
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-55895LOW3.98
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-57456LOW3.98
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.8
0.1%
Theoretical Threat
Post-Exploit
CVE-2024-22667LOW3.98
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-1215LOW3.98
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.4
0.5%
Theoretical Threat
Post-Exploit
CVE-2023-5535LOW3.98
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.3
0.5%
Theoretical Threat
Post-Exploit
CVE-2023-46218LOW3.9
curl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.6
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2024-9681LOW3.9
curl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.8
2.0%
Low-Moderate Risk
Post-Exploit
CVE-2023-46218LOW3.9
libcurl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.6
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2024-9681LOW3.9
libcurl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.8
2.0%
Low-Moderate Risk
Post-Exploit
CVE-2020-22218LOW3.82
libssh2
1.4.3-12.amzn2.2.4
fixed in 1.4.3-12.amzn2.2.6
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-58050LOW3.82
libssh2
1.4.3-12.amzn2.2.4
fixed in 1.4.3-12.amzn2.2.8
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-8194LOW3.82
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.14
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-3644LOW3.82
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.17
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-4224LOW3.82
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.17
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-8194LOW3.82
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.14
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-3644LOW3.82
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.17
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-4224LOW3.82
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.17
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-27817LOW3.79
org.apache.kafka:kafka-clients
3.4.0
fixed in 3.9.1
64.7%
Actively Exploited
Post-Exploit
CVE-2026-41411LOW3.72
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.6
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-41411LOW3.72
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.6
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-48924LOW3.7
org.apache.commons:commons-lang3
3.10
fixed in 3.18.0
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-48924LOW3.7
org.apache.commons:commons-lang3
3.12.0
fixed in 3.18.0
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-48924LOW3.7
org.apache.commons:commons-lang3
3.4
fixed in 3.18.0
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-48924LOW3.7
org.apache.commons:commons-lang3
3.9
fixed in 3.18.0
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2023-6135LOW3.65
nss-softokn
3.79.0-4.amzn2
fixed in 3.90.0-6.amzn2.0.2
0.7%
Theoretical Threat
Directly Exposed
CVE-2023-6135LOW3.65
nss-softokn-freebl
3.79.0-4.amzn2
fixed in 3.90.0-6.amzn2.0.2
0.7%
Theoretical Threat
Directly Exposed
CVE-2023-4156LOW3.62
gawk
4.0.2-4.amzn2.1.2
fixed in 4.0.2-4.amzn2.1.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-4786LOW3.62
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.19
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-4786LOW3.62
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.19
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-6965LOW3.61
sqlite
3.7.17-8.amzn2.1.2
fixed in 3.7.17-8.amzn2.1.3
74.4%
Actively Exploited
Post-Exploit
CVE-2025-68973LOW3.57
gnupg2
2.0.22-5.amzn2.0.5
fixed in 2.0.22-5.amzn2.0.6
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-8058LOW3.57
glibc
2.26-63.amzn2
fixed in 2.26-64.amzn2.0.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-8058LOW3.57
glibc-common
2.26-63.amzn2
fixed in 2.26-64.amzn2.0.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-8058LOW3.57
glibc-langpack-en
2.26-63.amzn2
fixed in 2.26-64.amzn2.0.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-8058LOW3.57
glibc-minimal-langpack
2.26-63.amzn2
fixed in 2.26-64.amzn2.0.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-8058LOW3.57
libcrypt
2.26-63.amzn2
fixed in 2.26-64.amzn2.0.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-28321LOW3.54
curl
8.0.1-1.amzn2.0.1
fixed in 8.2.1-1.amzn2.0.2
1.8%
Low-Moderate Risk
Post-Exploit
CVE-2023-28321LOW3.54
libcurl
8.0.1-1.amzn2.0.1
fixed in 8.2.1-1.amzn2.0.2
1.8%
Low-Moderate Risk
Post-Exploit
CVE-2022-48566LOW3.54
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.8
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2022-48566LOW3.54
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.8
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2024-56171LOW3.53
libxml2
2.9.1-6.amzn2.5.8
fixed in 2.9.1-6.amzn2.5.16
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2022-48565LOW3.53
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.7
4.3%
Low-Moderate Risk
Post-Exploit
CVE-2022-48565LOW3.53
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.7
4.3%
Low-Moderate Risk
Post-Exploit
CVE-2023-45853LOW3.53
zlib
1.2.7-19.amzn2.0.2
fixed in 1.2.7-19.amzn2.0.3
3.2%
Low-Moderate Risk
Post-Exploit
CVE-2023-38039LOW3.51
curl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.1
62.2%
Actively Exploited
Post-Exploit
CVE-2023-38039LOW3.51
libcurl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.1
62.2%
Actively Exploited
Post-Exploit
CVE-2023-44487LOW3.51
libnghttp2
1.41.0-1.amzn2
fixed in 1.41.0-1.amzn2.0.4
100.0%
Actively Exploited
Post-Exploit
CVE-2025-14819LOW3.47
curl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.12
0.7%
Theoretical Threat
Post-Exploit
CVE-2025-14819LOW3.47
libcurl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.12
0.7%
Theoretical Threat
Post-Exploit
CVE-2024-6923LOW3.47
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.11
0.8%
Theoretical Threat
Post-Exploit
CVE-2024-6923LOW3.47
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.11
0.8%
Theoretical Threat
Post-Exploit
CVE-2025-11563LOW3.31
curl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-14524LOW3.31
curl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.12
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-11563LOW3.31
libcurl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-14524LOW3.31
libcurl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.12
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-58051LOW3.31
libssh2
1.4.3-12.amzn2.2.4
fixed in 1.4.3-12.amzn2.2.8
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-11972LOW3.31
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.21
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-11972LOW3.31
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.21
0.4%
Theoretical Threat
Post-Exploit
CVE-2024-37371LOW3.28
krb5-libs
1.15.1-55.amzn2.2.5
fixed in 1.15.1-55.amzn2.2.8
1.9%
Low-Moderate Risk
Post-Exploit
CVE-2025-49796LOW3.28
libxml2
2.9.1-6.amzn2.5.8
fixed in 2.9.1-6.amzn2.5.19
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2024-2004LOW3.18
curl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.7
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2025-9086LOW3.18
curl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.10
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2023-46219LOW3.18
curl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.5
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2024-2004LOW3.18
libcurl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.7
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2025-9086LOW3.18
libcurl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.10
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2023-46219LOW3.18
libcurl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.5
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2023-27043LOW3.18
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.9
2.5%
Low-Moderate Risk
Post-Exploit
CVE-2023-27043LOW3.18
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.9
2.5%
Low-Moderate Risk
Post-Exploit
CVE-2025-48734LOW3.17
commons-beanutils:commons-beanutils
1.9.4
fixed in 1.11.0
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2024-0450LOW3.16
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2024-0450LOW3.16
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.11
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-0989LOW3.15
libxml2
2.9.1-6.amzn2.5.8
fixed in 2.9.1-6.amzn2.5.23
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-6766LOW3.11
nss-tools
3.79.0-4.amzn2.0.1
fixed in 3.90.0-2.amzn2.0.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6767LOW3.11
nss-tools
3.79.0-4.amzn2.0.1
fixed in 3.90.0-2.amzn2.0.3
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-6772LOW3.11
nss-tools
3.79.0-4.amzn2.0.1
fixed in 3.90.0-2.amzn2.0.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6019LOW3.11
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.20
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-6019LOW3.11
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.20
0.2%
Theoretical Threat
Post-Exploit
CVE-2024-2398LOW3.1
curl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.7
36.1%
High Exploitation Risk
Post-Exploit
CVE-2024-2398LOW3.1
libcurl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.7
36.1%
High Exploitation Risk
Post-Exploit
CVE-2025-10966LOW3.01
curl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.12
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-10966LOW3.01
libcurl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.12
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-14087LOW3
glib2
2.56.1-9.amzn2.0.6
fixed in 2.56.1-9.amzn2.0.13
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-6653LOW3
libxml2
2.9.1-6.amzn2.5.8
fixed in 2.9.1-6.amzn2.5.25
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-45447LOW2.92
openssl-libs
1:1.0.2k-24.amzn2.0.7
fixed in 1:1.0.2k-24.amzn2.0.21
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2007-4559LOW2.81
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.12
27.1%
High Exploitation Risk
Post-Exploit
CVE-2025-6075LOW2.8
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.16
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-6075LOW2.8
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.16
0.1%
Theoretical Threat
Post-Exploit
CVE-2023-4641LOW2.8
shadow-utils
2:4.1.5.1-24.amzn2.0.2
fixed in 2:4.1.5.1-24.amzn2.0.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2021-3236LOW2.8
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.3%
Theoretical Threat
Post-Exploit
CVE-2023-46246LOW2.8
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2081-1.amzn2.0.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-24014LOW2.8
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2023-5441LOW2.8
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2021-3236LOW2.8
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.1
0.3%
Theoretical Threat
Post-Exploit
CVE-2023-46246LOW2.8
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2081-1.amzn2.0.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-24014LOW2.8
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2023-5441LOW2.8
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.1882-1.amzn2.0.3
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-2602LOW2.8
libcap
2.54-1.amzn2.0.1
fixed in 2.54-1.amzn2.0.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2021-36084LOW2.8
libsepol
2.5-8.1.amzn2.0.2
fixed in 2.5-10.amzn2.0.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2021-36085LOW2.8
libsepol
2.5-8.1.amzn2.0.2
fixed in 2.5-10.amzn2.0.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2021-36086LOW2.8
libsepol
2.5-8.1.amzn2.0.2
fixed in 2.5-10.amzn2.0.1
0.6%
Theoretical Threat
Directly Exposed
CVE-2021-36087LOW2.8
libsepol
2.5-8.1.amzn2.0.2
fixed in 2.5-10.amzn2.0.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-8732LOW2.8
libxml2
2.9.1-6.amzn2.5.8
fixed in 2.9.1-6.amzn2.5.21
0.2%
Theoretical Threat
Directly Exposed
CVE-2020-8908LOW2.8
com.google.guava:guava
30.0-jre
fixed in 32.0.0-android
1.0%
Theoretical Threat
Directly Exposed
CVE-2020-8908LOW2.8
com.google.guava:guava
31.0.1-jre
fixed in 32.0.0-android
1.0%
Theoretical Threat
Directly Exposed
CVE-2020-8908LOW2.8
com.google.guava:guava
31.1-jre
fixed in 32.0.0-android
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-58016LOW2.78
glib2
2.56.1-9.amzn2.0.6
fixed in 2.56.1-9.amzn2.0.14
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-49794LOW2.78
libxml2
2.9.1-6.amzn2.5.8
fixed in 2.9.1-6.amzn2.5.19
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-42584LOW2.78
io.netty:netty-codec-http
4.1.91.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.8%
Theoretical Threat
Post-Exploit
CVE-2021-43618LOW2.7
gmp
1:6.0.0-15.amzn2.0.2
fixed in 1:6.0.0-15.amzn2.0.3
3.4%
Low-Moderate Risk
Post-Exploit
CVE-2023-40217LOW2.7
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.12
0.8%
Theoretical Threat
Post-Exploit
CVE-2025-12084LOW2.7
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.15
0.7%
Theoretical Threat
Post-Exploit
CVE-2023-40217LOW2.7
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.12
0.8%
Theoretical Threat
Post-Exploit
CVE-2025-12084LOW2.7
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.15
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-47167LOW2.7
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.7
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-47167LOW2.7
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.7
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-0992LOW2.46
libxml2
2.9.1-6.amzn2.5.8
fixed in 2.9.1-6.amzn2.5.22
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-14017LOW2.45
curl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.12
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-14017LOW2.45
libcurl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.12
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-15282LOW2.45
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.16
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-0672LOW2.45
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.16
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-15282LOW2.45
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.16
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-0672LOW2.45
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.16
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-15224LOW2.4
curl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.12
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-15224LOW2.4
libcurl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.12
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-48706LOW2.4
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-48706LOW2.4
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-11468LOW2.29
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.16
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-0865LOW2.29
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.16
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-11468LOW2.29
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.16
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-0865LOW2.29
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.16
0.5%
Theoretical Threat
Post-Exploit
CVE-2024-43802LOW2.29
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.2
0.3%
Theoretical Threat
Post-Exploit
CVE-2024-43802LOW2.29
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.2
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-29768LOW2.24
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.4
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-29768LOW2.24
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.4
0.3%
Theoretical Threat
Post-Exploit
CVE-2023-38546LOW2.22
curl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.4
6.2%
Low-Moderate Risk
Post-Exploit
CVE-2023-28322LOW2.22
curl
8.0.1-1.amzn2.0.1
fixed in 8.2.1-1.amzn2.0.2
2.2%
Low-Moderate Risk
Post-Exploit
CVE-2023-38546LOW2.22
libcurl
8.0.1-1.amzn2.0.1
fixed in 8.3.0-1.amzn2.0.4
6.2%
Low-Moderate Risk
Post-Exploit
CVE-2023-28322LOW2.22
libcurl
8.0.1-1.amzn2.0.1
fixed in 8.2.1-1.amzn2.0.2
2.2%
Low-Moderate Risk
Post-Exploit
CVE-2025-6069LOW2.19
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.13
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-6069LOW2.19
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.13
0.5%
Theoretical Threat
Post-Exploit
CVE-2023-48231LOW2.19
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Post-Exploit
CVE-2023-48232LOW2.19
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Post-Exploit
CVE-2023-48233LOW2.19
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Post-Exploit
CVE-2023-48234LOW2.19
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Post-Exploit
CVE-2023-48235LOW2.19
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Post-Exploit
CVE-2023-48236LOW2.19
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Post-Exploit
CVE-2023-48237LOW2.19
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Post-Exploit
CVE-2023-48231LOW2.19
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Post-Exploit
CVE-2023-48232LOW2.19
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Post-Exploit
CVE-2023-48233LOW2.19
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Post-Exploit
CVE-2023-48234LOW2.19
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Post-Exploit
CVE-2023-48235LOW2.19
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Post-Exploit
CVE-2023-48236LOW2.19
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Post-Exploit
CVE-2023-48237LOW2.19
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2120-1.amzn2.0.1
0.7%
Theoretical Threat
Post-Exploit
CVE-2025-26603LOW2.14
vim-data
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.4
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-26603LOW2.14
vim-minimal
2:9.0.1592-1.amzn2.0.1
fixed in 2:9.0.2153-1.amzn2.0.4
0.2%
Theoretical Threat
Post-Exploit
CVE-2024-11168LOW1.89
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.11
0.7%
Theoretical Threat
Post-Exploit
CVE-2024-11168LOW1.89
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.11
0.7%
Theoretical Threat
Post-Exploit
CVE-2020-19909LOW1.68
curl
8.0.1-1.amzn2.0.1
fixed in 8.2.1-1.amzn2.0.2
0.4%
Theoretical Threat
Post-Exploit
CVE-2020-19909LOW1.68
libcurl
8.0.1-1.amzn2.0.1
fixed in 8.2.1-1.amzn2.0.2
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-13462LOW1.68
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.18
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-4519LOW1.68
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.18
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-3479LOW1.68
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.18
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-13462LOW1.68
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.18
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-4519LOW1.68
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.18
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-3479LOW1.68
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.18
0.2%
Theoretical Threat
Post-Exploit
CVE-2023-39804LOW1.68
tar
2:1.26-35.amzn2.0.2
fixed in 2:1.26-35.amzn2.0.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2024-5642LOW1.38
python
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.10
0.7%
Theoretical Threat
Post-Exploit
CVE-2024-5642LOW1.38
python-libs
2.7.18-1.amzn2.0.6
fixed in 2.7.18-1.amzn2.0.10
0.7%
Theoretical Threat
Post-Exploit
CVE-2015-1197LOW1.14
cpio
2.12-11.amzn2
fixed in 2.12-11.amzn2.0.1
2.9%
Low-Moderate Risk
Post-Exploit
CVE-2023-37920NONE0
ca-certificates
2021.2.50-72.amzn2.0.7
fixed in 2021.2.50-72.amzn2.0.8
0.6%
Theoretical Threat
Not Applicable
CVE-2024-39689NONE0
ca-certificates
2021.2.50-72.amzn2.0.7
fixed in 2023.2.68-1.amzn2.0.1
1.0%
Low-Moderate Risk
Not Applicable
CVE-2020-19185NONE0
ncurses
6.0-8.20170212.amzn2.1.5
fixed in 6.0-8.20170212.amzn2.1.6
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19186NONE0
ncurses
6.0-8.20170212.amzn2.1.5
fixed in 6.0-8.20170212.amzn2.1.6
1.5%
Low-Moderate Risk
Not Applicable
CVE-2020-19187NONE0
ncurses
6.0-8.20170212.amzn2.1.5
fixed in 6.0-8.20170212.amzn2.1.6
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19188NONE0
ncurses
6.0-8.20170212.amzn2.1.5
fixed in 6.0-8.20170212.amzn2.1.6
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19189NONE0
ncurses
6.0-8.20170212.amzn2.1.5
fixed in 6.0-8.20170212.amzn2.1.6
1.9%
Low-Moderate Risk
Not Applicable
CVE-2020-19190NONE0
ncurses
6.0-8.20170212.amzn2.1.5
fixed in 6.0-8.20170212.amzn2.1.6
1.4%
Low-Moderate Risk
Not Applicable
CVE-2023-50495NONE0
ncurses
6.0-8.20170212.amzn2.1.5
fixed in 6.0-8.20170212.amzn2.1.7
1.0%
Theoretical Threat
Not Applicable
CVE-2020-19185NONE0
ncurses-base
6.0-8.20170212.amzn2.1.5
fixed in 6.0-8.20170212.amzn2.1.6
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19186NONE0
ncurses-base
6.0-8.20170212.amzn2.1.5
fixed in 6.0-8.20170212.amzn2.1.6
1.5%
Low-Moderate Risk
Not Applicable
CVE-2020-19187NONE0
ncurses-base
6.0-8.20170212.amzn2.1.5
fixed in 6.0-8.20170212.amzn2.1.6
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19188NONE0
ncurses-base
6.0-8.20170212.amzn2.1.5
fixed in 6.0-8.20170212.amzn2.1.6
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19189NONE0
ncurses-base
6.0-8.20170212.amzn2.1.5
fixed in 6.0-8.20170212.amzn2.1.6
1.9%
Low-Moderate Risk
Not Applicable
CVE-2020-19190NONE0
ncurses-base
6.0-8.20170212.amzn2.1.5
fixed in 6.0-8.20170212.amzn2.1.6
1.4%
Low-Moderate Risk
Not Applicable
CVE-2023-50495NONE0
ncurses-base
6.0-8.20170212.amzn2.1.5
fixed in 6.0-8.20170212.amzn2.1.7
1.0%
Theoretical Threat
Not Applicable
CVE-2020-19185NONE0
ncurses-libs
6.0-8.20170212.amzn2.1.5
fixed in 6.0-8.20170212.amzn2.1.6
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19186NONE0
ncurses-libs
6.0-8.20170212.amzn2.1.5
fixed in 6.0-8.20170212.amzn2.1.6
1.5%
Low-Moderate Risk
Not Applicable
CVE-2020-19187NONE0
ncurses-libs
6.0-8.20170212.amzn2.1.5
fixed in 6.0-8.20170212.amzn2.1.6
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19188NONE0
ncurses-libs
6.0-8.20170212.amzn2.1.5
fixed in 6.0-8.20170212.amzn2.1.6
1.4%
Low-Moderate Risk
Not Applicable
CVE-2020-19189NONE0
ncurses-libs
6.0-8.20170212.amzn2.1.5
fixed in 6.0-8.20170212.amzn2.1.6
1.9%
Low-Moderate Risk
Not Applicable
CVE-2020-19190NONE0
ncurses-libs
6.0-8.20170212.amzn2.1.5
fixed in 6.0-8.20170212.amzn2.1.6
1.4%
Low-Moderate Risk
Not Applicable
CVE-2023-50495NONE0
ncurses-libs
6.0-8.20170212.amzn2.1.5
fixed in 6.0-8.20170212.amzn2.1.7
1.0%
Theoretical Threat
Not Applicable
CVE-2019-17595NONE0
ncurses
6.0-8.20170212.amzn2.1.5
fixed in 6.0-8.20170212.amzn2.1.6
2.0%
Low-Moderate Risk
Not Applicable
CVE-2019-17595NONE0
ncurses-base
6.0-8.20170212.amzn2.1.5
fixed in 6.0-8.20170212.amzn2.1.6
2.0%
Low-Moderate Risk
Not Applicable
CVE-2019-17595NONE0
ncurses-libs
6.0-8.20170212.amzn2.1.5
fixed in 6.0-8.20170212.amzn2.1.6
2.0%
Low-Moderate Risk
Not Applicable
CVE-2019-17594NONE0
ncurses
6.0-8.20170212.amzn2.1.5
fixed in 6.0-8.20170212.amzn2.1.6
0.5%
Theoretical Threat
Not Applicable
CVE-2019-17594NONE0
ncurses-base
6.0-8.20170212.amzn2.1.5
fixed in 6.0-8.20170212.amzn2.1.6
0.5%
Theoretical Threat
Not Applicable
CVE-2019-17594NONE0
ncurses-libs
6.0-8.20170212.amzn2.1.5
fixed in 6.0-8.20170212.amzn2.1.6
0.5%
Theoretical Threat
Not Applicable
CVE-2025-48924NONE0
commons-lang:commons-lang
2.4
No fix yet
2.2%
Low-Moderate Risk
Not Applicable
CVE-2025-48924NONE0
commons-lang:commons-lang
2.6
No fix yet
2.2%
Low-Moderate Risk
Not Applicable
CVE-2026-53615NONE0
libblkid
2.30.2-2.amzn2.0.11
fixed in 2.30.2-2.amzn2.0.14
Not Applicable
CVE-2026-53615NONE0
libmount
2.30.2-2.amzn2.0.11
fixed in 2.30.2-2.amzn2.0.14
Not Applicable
CVE-2026-53615NONE0
libuuid
2.30.2-2.amzn2.0.11
fixed in 2.30.2-2.amzn2.0.14
Not Applicable
CVE-2024-37902NONE0
ai.djl:api
0.19.0
fixed in 0.28.0
0.7%
Theoretical Threat
Not Applicable
CVE-2025-0851NONE0
ai.djl:api
0.19.0
fixed in 0.31.1
23.3%
High Exploitation Risk
Not Applicable
GHSA-r7wm-3cxj-wff9NONE0
com.fasterxml.jackson.core:jackson-core
2.15.1
fixed in 2.18.8, 2.21.4, 2.22.1
Not Applicable
GHSA-72hv-8253-57qqNONE0
com.fasterxml.jackson.core:jackson-core
2.15.1
fixed in 2.21.1, 2.18.6
Not Applicable
GHSA-xpw8-rcwv-8f8pNONE0
io.netty:netty-codec-http2
4.1.91.Final
fixed in 4.1.100.Final
Not Applicable
CVE-2026-33558NONE0
org.apache.kafka:kafka-clients
3.4.0
fixed in 3.9.2, 4.0.1
0.6%
Theoretical Threat
Not Applicable
CVE-2026-59949NONE0
org.lz4:lz4-java
1.8.0
No fix yet
Not Applicable
GHSA-6g3j-p5g6-992fNONE0
org.opensearch:opensearch
2.8.0
fixed in 1.3.14, 2.11.1
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.