Vulnerability Reportopensearchproject/opensearch:3.4.0

opensearchproject/opensearch:3.4.0
DIGESTsha256:1647ce2e07371f1ac8bbad28890a64ef77c5a694a61f656120f0ace09e66bf48

Executive Summary

Threat Score
74/100CAUTION
Reputation
TRUSTED

This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker could exploit the Netty request smuggling flaw (CVE-2026-42581) to perform cache poisoning or bypass security controls, or trigger denial of service via HTTP/2 frames (CVE-2026-27135). Post-exploit vulnerabilities are low severity and not relevant to this container's operation.

Vulnerabilities

Vulnerability Log

154 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-42581HIGH8.33
io.netty:netty-codec-http
4.1.125.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.4%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-42581HIGH8.33
io.netty:netty-codec-http
4.2.7.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.4%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-33811MEDIUM6.38
libcap
2.73-1.amzn2023.0.5
fixed in 2.73-1.amzn2023.0.7
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-33814MEDIUM6.38
libcap
2.73-1.amzn2023.0.5
fixed in 2.73-1.amzn2023.0.7
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-39820MEDIUM6.38
libcap
2.73-1.amzn2023.0.5
fixed in 2.73-1.amzn2023.0.7
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-41989MEDIUM6.38
libgcrypt
1.10.2-1.amzn2023.0.2
fixed in 1.10.2-1.amzn2023.0.3
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27135MEDIUM6.38
libnghttp2
1.59.0-3.amzn2023.0.1
fixed in 1.59.0-3.amzn2023.0.2
0.6%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-28389MEDIUM6.38
openssl-fips-provider-latest
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.5.5-1.amzn2023.0.4
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-28390MEDIUM6.38
openssl-fips-provider-latest
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.5.5-1.amzn2023.0.4
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-28389MEDIUM6.38
openssl-libs
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.5.5-1.amzn2023.0.4
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-28390MEDIUM6.38
openssl-libs
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.5.5-1.amzn2023.0.4
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-33870MEDIUM6.38
io.netty:netty-codec-http
4.1.125.Final
fixed in 4.1.132.Final, 4.2.10.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42587MEDIUM6.38
io.netty:netty-codec-http
4.1.125.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42585MEDIUM6.38
io.netty:netty-codec-http
4.1.125.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-33870MEDIUM6.38
io.netty:netty-codec-http
4.2.7.Final
fixed in 4.1.132.Final, 4.2.10.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42587MEDIUM6.38
io.netty:netty-codec-http
4.2.7.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42585MEDIUM6.38
io.netty:netty-codec-http
4.2.7.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-33871MEDIUM6.38
io.netty:netty-codec-http2
4.1.125.Final
fixed in 4.1.132.Final, 4.2.11.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42587MEDIUM6.38
io.netty:netty-codec-http2
4.1.125.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-48043MEDIUM6.38
io.netty:netty-codec-http2
4.1.125.Final
fixed in 4.1.135.Final, 4.2.15.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-33871MEDIUM6.38
io.netty:netty-codec-http2
4.2.7.Final
fixed in 4.1.132.Final, 4.2.11.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42587MEDIUM6.38
io.netty:netty-codec-http2
4.2.7.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-48043MEDIUM6.38
io.netty:netty-codec-http2
4.2.7.Final
fixed in 4.1.135.Final, 4.2.15.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-45416MEDIUM6.38
io.netty:netty-handler
4.1.125.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-50010MEDIUM6.38
io.netty:netty-handler
4.1.125.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45416MEDIUM6.38
io.netty:netty-handler
4.2.7.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-50010MEDIUM6.38
io.netty:netty-handler
4.2.7.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42578MEDIUM6.38
io.netty:netty-handler-proxy
4.2.7.Final
fixed in 4.1.133.Final, 4.2.13.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34478MEDIUM6.38
org.apache.logging.log4j:log4j-core
2.21.0
fixed in 2.25.4
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-34480MEDIUM6.38
org.apache.logging.log4j:log4j-core
2.21.0
fixed in 2.25.4
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-5598MEDIUM6.38
org.bouncycastle:bcprov-jdk18on
1.78.1
fixed in 1.84
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-69419MEDIUM6.29
openssl-fips-provider-latest
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.2.2-1.amzn2023.0.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69419MEDIUM6.29
openssl-libs
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.2.2-1.amzn2023.0.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-13151MEDIUM5.9
libtasn1
4.19.0-1.amzn2023.0.5
fixed in 4.19.0-1.amzn2023.0.6
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-35554MEDIUM5.78
org.apache.kafka:kafka-clients
4.1.1
fixed in 3.9.2, 4.0.2, 4.1.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9149MEDIUM5.52
libsolv
0.7.22-1.amzn2023.0.2
fixed in 0.7.22-1.amzn2023.0.4
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9150MEDIUM5.52
libsolv
0.7.22-1.amzn2023.0.2
fixed in 0.7.22-1.amzn2023.0.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-2673MEDIUM5.52
openssl-fips-provider-latest
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.5.5-1.amzn2023.0.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-2673MEDIUM5.52
openssl-libs
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.5.5-1.amzn2023.0.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-67735MEDIUM5.52
io.netty:netty-codec-http
4.1.125.Final
fixed in 4.2.8.Final, 4.1.129.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-41417MEDIUM5.52
io.netty:netty-codec-http
4.1.125.Final
fixed in 4.1.133.Final, 4.2.13.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42580MEDIUM5.52
io.netty:netty-codec-http
4.1.125.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-67735MEDIUM5.52
io.netty:netty-codec-http
4.2.7.Final
fixed in 4.2.8.Final, 4.1.129.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-41417MEDIUM5.52
io.netty:netty-codec-http
4.2.7.Final
fixed in 4.1.133.Final, 4.2.13.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42580MEDIUM5.52
io.netty:netty-codec-http
4.2.7.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-0636MEDIUM5.52
org.bouncycastle:bcprov-jdk18on
1.78.1
fixed in 1.84
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-44249MEDIUM5.5
io.netty:netty-handler
4.1.125.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-44249MEDIUM5.5
io.netty:netty-handler
4.2.7.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-1757MEDIUM5.27
libxml2
2.10.4-1.amzn2023.0.13
fixed in 2.10.4-1.amzn2023.0.18
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-40355MEDIUM5.02
krb5-libs
1.21.3-6.amzn2023.0.1
fixed in 1.21.3-7.amzn2023.0.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-40356MEDIUM5.02
krb5-libs
1.21.3-6.amzn2023.0.1
fixed in 1.21.3-7.amzn2023.0.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-0990MEDIUM5.02
libxml2
2.10.4-1.amzn2023.0.13
fixed in 2.10.4-1.amzn2023.0.16
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-15468MEDIUM5.02
openssl-fips-provider-latest
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.2.2-1.amzn2023.0.5
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-66199MEDIUM5.02
openssl-fips-provider-latest
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.2.2-1.amzn2023.0.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69420MEDIUM5.02
openssl-fips-provider-latest
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.2.2-1.amzn2023.0.5
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-22796MEDIUM5.02
openssl-fips-provider-latest
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.2.2-1.amzn2023.0.5
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-31790MEDIUM5.02
openssl-fips-provider-latest
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.5.5-1.amzn2023.0.4
1.0%
Theoretical Threat
Directly Exposed
CVE-2025-15468MEDIUM5.02
openssl-libs
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.2.2-1.amzn2023.0.5
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-66199MEDIUM5.02
openssl-libs
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.2.2-1.amzn2023.0.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69420MEDIUM5.02
openssl-libs
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.2.2-1.amzn2023.0.5
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-22796MEDIUM5.02
openssl-libs
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.2.2-1.amzn2023.0.5
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-31790MEDIUM5.02
openssl-libs
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.5.5-1.amzn2023.0.4
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-34477MEDIUM5.02
org.apache.logging.log4j:log4j-core
2.21.0
fixed in 2.25.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-22795MEDIUM4.67
openssl-fips-provider-latest
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.2.2-1.amzn2023.0.5
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-22795MEDIUM4.67
openssl-libs
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.2.2-1.amzn2023.0.5
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27142MEDIUM4.59
libcap
2.73-1.amzn2023.0.5
fixed in 2.73-1.amzn2023.0.7
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc
2.34-231.amzn2023.0.1
fixed in 2.34-231.amzn2023.0.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc-common
2.34-231.amzn2023.0.1
fixed in 2.34-231.amzn2023.0.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc-minimal-langpack
2.34-231.amzn2023.0.1
fixed in 2.34-231.amzn2023.0.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-61730MEDIUM4.5
libcap
2.73-1.amzn2023.0.5
fixed in 2.73-1.amzn2023.0.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-50020MEDIUM4.5
io.netty:netty-codec-http
4.1.125.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-50020MEDIUM4.5
io.netty:netty-codec-http
4.2.7.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-47244MEDIUM4.5
io.netty:netty-codec-http2
4.1.125.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-50560MEDIUM4.5
io.netty:netty-codec-http2
4.1.125.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-47244MEDIUM4.5
io.netty:netty-codec-http2
4.2.7.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-50560MEDIUM4.5
io.netty:netty-codec-http2
4.2.7.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-68161MEDIUM4.08
org.apache.logging.log4j:log4j-core
2.21.0
fixed in 2.25.3
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-15467MEDIUM4.06
openssl-fips-provider-latest
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.2.2-1.amzn2023.0.4
48.7%
High Exploitation Risk
Post-Exploit
CVE-2025-15467MEDIUM4.06
openssl-libs
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.2.2-1.amzn2023.0.4
48.7%
High Exploitation Risk
Post-Exploit
CVE-2025-68160MEDIUM4
openssl-fips-provider-latest
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.2.2-1.amzn2023.0.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-68160MEDIUM4
openssl-libs
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.2.2-1.amzn2023.0.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-24882LOW3.98
gnupg2-minimal
2.3.7-1.amzn2023.0.5
fixed in 2.3.7-1.amzn2023.0.7
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-4224LOW3.82
python3-libs
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-4786LOW3.62
python3
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.5
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-1299LOW3.62
python3
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-4786LOW3.62
python3-libs
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.5
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-1299LOW3.62
python3-libs
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-68973LOW3.57
gnupg2-minimal
2.3.7-1.amzn2023.0.5
fixed in 2.3.7-1.amzn2023.0.6
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-13034LOW3.47
curl-minimal
8.15.0-4.amzn2023.0.1
fixed in 8.17.0-1.amzn2023.0.1
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-14819LOW3.47
curl-minimal
8.15.0-4.amzn2023.0.1
fixed in 8.17.0-1.amzn2023.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-13034LOW3.47
libcurl-minimal
8.15.0-4.amzn2023.0.1
fixed in 8.17.0-1.amzn2023.0.1
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-14819LOW3.47
libcurl-minimal
8.15.0-4.amzn2023.0.1
fixed in 8.17.0-1.amzn2023.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-69418LOW3.4
openssl-fips-provider-latest
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.2.2-1.amzn2023.0.5
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-69418LOW3.4
openssl-libs
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.2.2-1.amzn2023.0.5
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-14524LOW3.31
curl-minimal
8.15.0-4.amzn2023.0.1
fixed in 8.17.0-1.amzn2023.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-14524LOW3.31
libcurl-minimal
8.15.0-4.amzn2023.0.1
fixed in 8.17.0-1.amzn2023.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-3805LOW3.21
curl-minimal
8.15.0-4.amzn2023.0.1
fixed in 8.17.0-1.amzn2023.0.3
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-3805LOW3.21
libcurl-minimal
8.15.0-4.amzn2023.0.1
fixed in 8.17.0-1.amzn2023.0.3
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-0989LOW3.15
libxml2
2.10.4-1.amzn2023.0.13
fixed in 2.10.4-1.amzn2023.0.17
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-6019LOW3.11
python3
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.6
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-6019LOW3.11
python3-libs
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.6
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-68121LOW3.06
libcap
2.73-1.amzn2023.0.5
fixed in 2.73-1.amzn2023.0.6
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-6357LOW2.96
python3-pip-wheel
21.3.1-2.amzn2023.0.14
fixed in 21.3.1-2.amzn2023.0.19
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-8732LOW2.8
libxml2
2.10.4-1.amzn2023.0.13
fixed in 2.10.4-1.amzn2023.0.15
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42584LOW2.78
io.netty:netty-codec-http
4.1.125.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-42584LOW2.78
io.netty:netty-codec-http
4.2.7.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-48863LOW2.7
libsolv
0.7.22-1.amzn2023.0.2
fixed in 0.7.22-1.amzn2023.0.4
Post-Exploit
CVE-2026-33557LOW2.63
org.apache.kafka:kafka-clients
4.1.1
fixed in 4.1.2
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-15079LOW2.48
curl-minimal
8.15.0-4.amzn2023.0.1
fixed in 8.17.0-1.amzn2023.0.1
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-15079LOW2.48
libcurl-minimal
8.15.0-4.amzn2023.0.1
fixed in 8.17.0-1.amzn2023.0.1
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-28387LOW2.48
openssl-fips-provider-latest
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.5.5-1.amzn2023.0.4
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-28387LOW2.48
openssl-libs
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.5.5-1.amzn2023.0.4
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-6100LOW2.48
python3
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.5
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-6100LOW2.48
python3-libs
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.5
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-0992LOW2.46
libxml2
2.10.4-1.amzn2023.0.13
fixed in 2.10.4-1.amzn2023.0.16
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-14017LOW2.45
curl-minimal
8.15.0-4.amzn2023.0.1
fixed in 8.17.0-1.amzn2023.0.1
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-14017LOW2.45
libcurl-minimal
8.15.0-4.amzn2023.0.1
fixed in 8.17.0-1.amzn2023.0.1
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-15282LOW2.45
python3
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-0672LOW2.45
python3
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-15282LOW2.45
python3-libs
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-0672LOW2.45
python3-libs
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-54920LOW2.41
org.apache.spark:spark-core_2.13
3.5.4
fixed in 4.0.1, 3.5.7
5.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-15224LOW2.4
curl-minimal
8.15.0-4.amzn2023.0.1
fixed in 8.17.0-1.amzn2023.0.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-15224LOW2.4
libcurl-minimal
8.15.0-4.amzn2023.0.1
fixed in 8.17.0-1.amzn2023.0.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-25210LOW2.39
expat
2.6.3-1.amzn2023.0.3
fixed in 2.6.3-1.amzn2023.0.4
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-48864LOW2.39
libsolv
0.7.22-1.amzn2023.0.2
fixed in 0.7.22-1.amzn2023.0.4
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-61726LOW2.29
libcap
2.73-1.amzn2023.0.5
fixed in 2.73-1.amzn2023.0.6
0.8%
Theoretical Threat
Post-Exploit
CVE-2025-61728LOW2.29
libcap
2.73-1.amzn2023.0.5
fixed in 2.73-1.amzn2023.0.6
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-69421LOW2.29
openssl-fips-provider-latest
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.2.2-1.amzn2023.0.5
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-28388LOW2.29
openssl-fips-provider-latest
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.5.5-1.amzn2023.0.4
0.9%
Theoretical Threat
Post-Exploit
CVE-2025-69421LOW2.29
openssl-libs
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.2.2-1.amzn2023.0.5
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-28388LOW2.29
openssl-libs
1:3.2.2-1.amzn2023.0.3
fixed in 1:3.5.5-1.amzn2023.0.4
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-3644LOW2.29
python3
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-4224LOW2.29
python3
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-3644LOW2.29
python3-libs
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-21441LOW2.29
python3-pip-wheel
21.3.1-2.amzn2023.0.14
fixed in 21.3.1-2.amzn2023.0.16
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-66418LOW2.29
python3-pip-wheel
21.3.1-2.amzn2023.0.14
fixed in 21.3.1-2.amzn2023.0.15
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-66471LOW2.29
python3-pip-wheel
21.3.1-2.amzn2023.0.14
fixed in 21.3.1-2.amzn2023.0.15
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-11468LOW2.29
python3
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-0865LOW2.29
python3
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-11468LOW2.29
python3-libs
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-0865LOW2.29
python3-libs
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-1703LOW1.99
python3-pip-wheel
21.3.1-2.amzn2023.0.14
fixed in 21.3.1-2.amzn2023.0.17
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-4519LOW1.68
python3
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-2297LOW1.68
python3
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-4519LOW1.68
python3-libs
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-2297LOW1.68
python3-libs
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-39823NONE0
libcap
2.73-1.amzn2023.0.5
fixed in 2.73-1.amzn2023.0.7
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42499NONE0
libcap
2.73-1.amzn2023.0.5
fixed in 2.73-1.amzn2023.0.7
0.6%
Theoretical Threat
Not Applicable
GHSA-72hv-8253-57qqNONE0
com.fasterxml.jackson.core:jackson-core
2.16.2
fixed in 2.21.1, 2.18.6
Not Applicable
GHSA-72hv-8253-57qqNONE0
com.fasterxml.jackson.core:jackson-core
2.18.2
fixed in 2.21.1, 2.18.6
Not Applicable
CVE-2026-42583NONE0
io.netty:netty-codec
4.1.125.Final
fixed in 4.1.133.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42583NONE0
io.netty:netty-codec-compression
4.2.7.Final
fixed in 4.2.13.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-8149NONE0
org.bouncycastle:bc-fips
2.1.2
No fix yet
0.2%
Theoretical Threat
Not Applicable