Vulnerability Reportopensearchproject/opensearch:3.5.0

opensearchproject/opensearch:3.5.0
DIGESTsha256:dbb01641baadae5104e18acd888bf05e8fdd9af3567fd30624a76ba3e5a31dec

Executive Summary

Threat Score
85/100DANGEROUS
Reputation
TRUSTED

This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could exploit CVE-2026-42581 to perform HTTP request smuggling, leading to data exposure, cache poisoning, or unauthorized actions. Multiple Netty vulnerabilities (e.g., CVE-2026-42581 and CVE-2026-33870) affect core request parsing and decompression, with no configuration required for exploitation. Upgrading to the latest Netty versions would fix these issues, but the current image is not safe for deployment.

Vulnerabilities

Vulnerability Log

109 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-42581HIGH8.33
io.netty:netty-codec-http
4.1.130.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.4%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-42581HIGH8.33
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.4%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-39820MEDIUM6.38
libcap
2.73-1.amzn2023.0.6
fixed in 2.73-1.amzn2023.0.7
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-41989MEDIUM6.38
libgcrypt
1.10.2-1.amzn2023.0.2
fixed in 1.10.2-1.amzn2023.0.3
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27135MEDIUM6.38
libnghttp2
1.59.0-3.amzn2023.0.1
fixed in 1.59.0-3.amzn2023.0.2
0.6%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-3644MEDIUM6.38
python3-libs
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4224MEDIUM6.38
python3-libs
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-44894MEDIUM6.38
io.netty:netty-codec-classes-quic
4.2.9.Final
fixed in 4.2.15.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-33870MEDIUM6.38
io.netty:netty-codec-http
4.1.130.Final
fixed in 4.1.132.Final, 4.2.10.Final
0.4%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-42587MEDIUM6.38
io.netty:netty-codec-http
4.1.130.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42585MEDIUM6.38
io.netty:netty-codec-http
4.1.130.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-33870MEDIUM6.38
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.1.132.Final, 4.2.10.Final
0.4%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-42587MEDIUM6.38
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42585MEDIUM6.38
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-33871MEDIUM6.38
io.netty:netty-codec-http2
4.1.130.Final
fixed in 4.1.132.Final, 4.2.11.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42587MEDIUM6.38
io.netty:netty-codec-http2
4.1.130.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-48043MEDIUM6.38
io.netty:netty-codec-http2
4.1.130.Final
fixed in 4.1.135.Final, 4.2.15.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-33871MEDIUM6.38
io.netty:netty-codec-http2
4.2.9.Final
fixed in 4.1.132.Final, 4.2.11.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42587MEDIUM6.38
io.netty:netty-codec-http2
4.2.9.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-48043MEDIUM6.38
io.netty:netty-codec-http2
4.2.9.Final
fixed in 4.1.135.Final, 4.2.15.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-48748MEDIUM6.38
io.netty:netty-codec-http3
4.2.9.Final
fixed in 4.2.15.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-45416MEDIUM6.38
io.netty:netty-handler
4.1.130.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-50010MEDIUM6.38
io.netty:netty-handler
4.1.130.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45416MEDIUM6.38
io.netty:netty-handler
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-50010MEDIUM6.38
io.netty:netty-handler
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42578MEDIUM6.38
io.netty:netty-handler-proxy
4.2.9.Final
fixed in 4.1.133.Final, 4.2.13.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34478MEDIUM6.38
org.apache.logging.log4j:log4j-core
2.25.3
fixed in 2.25.4
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-34480MEDIUM6.38
org.apache.logging.log4j:log4j-core
2.25.3
fixed in 2.25.4
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-5598MEDIUM6.38
org.bouncycastle:bcprov-jdk18on
1.78.1
fixed in 1.84
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-40542MEDIUM6.21
org.apache.httpcomponents.client5:httpclient5
5.6
fixed in 5.6.1
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42584MEDIUM6.18
io.netty:netty-codec-http
4.1.130.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42584MEDIUM6.18
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-4786MEDIUM6.03
python3-libs
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-1299MEDIUM6.03
python3-libs
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-35554MEDIUM5.78
org.apache.kafka:kafka-clients
4.1.1
fixed in 3.9.2, 4.0.2, 4.1.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9149MEDIUM5.52
libsolv
0.7.22-1.amzn2023.0.2
fixed in 0.7.22-1.amzn2023.0.4
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-9150MEDIUM5.52
libsolv
0.7.22-1.amzn2023.0.2
fixed in 0.7.22-1.amzn2023.0.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-2673MEDIUM5.52
openssl-fips-provider-latest
1:3.2.2-1.amzn2023.0.5
fixed in 1:3.5.5-1.amzn2023.0.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-2673MEDIUM5.52
openssl-libs
1:3.2.2-1.amzn2023.0.5
fixed in 1:3.5.5-1.amzn2023.0.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-41417MEDIUM5.52
io.netty:netty-codec-http
4.1.130.Final
fixed in 4.1.133.Final, 4.2.13.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42580MEDIUM5.52
io.netty:netty-codec-http
4.1.130.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-41417MEDIUM5.52
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.1.133.Final, 4.2.13.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42580MEDIUM5.52
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-0636MEDIUM5.52
org.bouncycastle:bcprov-jdk18on
1.78.1
fixed in 1.84
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-28387MEDIUM5.5
openssl-fips-provider-latest
1:3.2.2-1.amzn2023.0.5
fixed in 1:3.5.5-1.amzn2023.0.4
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-28387MEDIUM5.5
openssl-libs
1:3.2.2-1.amzn2023.0.5
fixed in 1:3.5.5-1.amzn2023.0.4
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-44249MEDIUM5.5
io.netty:netty-handler
4.1.130.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-44249MEDIUM5.5
io.netty:netty-handler
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-6019MEDIUM5.18
python3-libs
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.6
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-28388MEDIUM5.1
openssl-fips-provider-latest
1:3.2.2-1.amzn2023.0.5
fixed in 1:3.5.5-1.amzn2023.0.4
0.9%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-28388MEDIUM5.1
openssl-libs
1:3.2.2-1.amzn2023.0.5
fixed in 1:3.5.5-1.amzn2023.0.4
0.9%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-40355MEDIUM5.02
krb5-libs
1.21.3-6.amzn2023.0.1
fixed in 1.21.3-7.amzn2023.0.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-40356MEDIUM5.02
krb5-libs
1.21.3-6.amzn2023.0.1
fixed in 1.21.3-7.amzn2023.0.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-31790MEDIUM5.02
openssl-fips-provider-latest
1:3.2.2-1.amzn2023.0.5
fixed in 1:3.5.5-1.amzn2023.0.4
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-31790MEDIUM5.02
openssl-libs
1:3.2.2-1.amzn2023.0.5
fixed in 1:3.5.5-1.amzn2023.0.4
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-34477MEDIUM5.02
org.apache.logging.log4j:log4j-core
2.25.3
fixed in 2.25.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-27142MEDIUM4.59
libcap
2.73-1.amzn2023.0.6
fixed in 2.73-1.amzn2023.0.7
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc
2.34-231.amzn2023.0.3
fixed in 2.34-231.amzn2023.0.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc-common
2.34-231.amzn2023.0.3
fixed in 2.34-231.amzn2023.0.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc-minimal-langpack
2.34-231.amzn2023.0.3
fixed in 2.34-231.amzn2023.0.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-50020MEDIUM4.5
io.netty:netty-codec-http
4.1.130.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-50020MEDIUM4.5
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-47244MEDIUM4.5
io.netty:netty-codec-http2
4.1.130.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-50560MEDIUM4.5
io.netty:netty-codec-http2
4.1.130.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-47244MEDIUM4.5
io.netty:netty-codec-http2
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-50560MEDIUM4.5
io.netty:netty-codec-http2
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-15282MEDIUM4.08
python3-libs
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-0672MEDIUM4.08
python3-libs
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-11468LOW3.82
python3-libs
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-0865LOW3.82
python3-libs
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-6357LOW2.96
python3-pip-wheel
21.3.1-2.amzn2023.0.16
fixed in 21.3.1-2.amzn2023.0.19
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-4519LOW2.8
python3-libs
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-2297LOW2.8
python3-libs
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-48863LOW2.7
libsolv
0.7.22-1.amzn2023.0.2
fixed in 0.7.22-1.amzn2023.0.4
Post-Exploit
CVE-2026-33557LOW2.63
org.apache.kafka:kafka-clients
4.1.1
fixed in 4.1.2
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-6100LOW2.48
python3
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.5
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-6100LOW2.48
python3-libs
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.5
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-15282LOW2.45
python3
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-0672LOW2.45
python3
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-54920LOW2.41
org.apache.spark:spark-core_2.13
3.5.4
fixed in 4.0.1, 3.5.7
5.3%
Low-Moderate Risk
Post-Exploit
CVE-2026-48864LOW2.39
libsolv
0.7.22-1.amzn2023.0.2
fixed in 0.7.22-1.amzn2023.0.4
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-33811LOW2.29
libcap
2.73-1.amzn2023.0.6
fixed in 2.73-1.amzn2023.0.7
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-33814LOW2.29
libcap
2.73-1.amzn2023.0.6
fixed in 2.73-1.amzn2023.0.7
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-28389LOW2.29
openssl-fips-provider-latest
1:3.2.2-1.amzn2023.0.5
fixed in 1:3.5.5-1.amzn2023.0.4
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-28390LOW2.29
openssl-fips-provider-latest
1:3.2.2-1.amzn2023.0.5
fixed in 1:3.5.5-1.amzn2023.0.4
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-28389LOW2.29
openssl-libs
1:3.2.2-1.amzn2023.0.5
fixed in 1:3.5.5-1.amzn2023.0.4
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-28390LOW2.29
openssl-libs
1:3.2.2-1.amzn2023.0.5
fixed in 1:3.5.5-1.amzn2023.0.4
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-3644LOW2.29
python3
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.5
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-4224LOW2.29
python3
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-11468LOW2.29
python3
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-0865LOW2.29
python3
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-4786LOW2.17
python3
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.5
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-1299LOW2.17
python3
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-1703LOW1.99
python3-pip-wheel
21.3.1-2.amzn2023.0.16
fixed in 21.3.1-2.amzn2023.0.17
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-3805LOW1.93
curl-minimal
8.17.0-1.amzn2023.0.1
fixed in 8.17.0-1.amzn2023.0.3
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-3805LOW1.93
libcurl-minimal
8.17.0-1.amzn2023.0.1
fixed in 8.17.0-1.amzn2023.0.3
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-6019LOW1.87
python3
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.6
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-4519LOW1.68
python3
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-2297LOW1.68
python3
3.9.25-1.amzn2023.0.3
fixed in 3.9.25-1.amzn2023.0.4
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-39823NONE0
libcap
2.73-1.amzn2023.0.6
fixed in 2.73-1.amzn2023.0.7
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42499NONE0
libcap
2.73-1.amzn2023.0.6
fixed in 2.73-1.amzn2023.0.7
0.6%
Theoretical Threat
Not Applicable
GHSA-72hv-8253-57qqNONE0
com.fasterxml.jackson.core:jackson-core
2.16.2
fixed in 2.21.1, 2.18.6
Not Applicable
GHSA-72hv-8253-57qqNONE0
com.fasterxml.jackson.core:jackson-core
2.20.1
fixed in 2.21.1, 2.18.6
Not Applicable
CVE-2026-42583NONE0
io.netty:netty-codec
4.1.130.Final
fixed in 4.1.133.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-50009NONE0
io.netty:netty-codec-classes-quic
4.2.9.Final
fixed in 4.2.15.Final
0.2%
Theoretical Threat
Not Applicable
CVE-2026-42583NONE0
io.netty:netty-codec-compression
4.2.9.Final
fixed in 4.2.13.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42582NONE0
io.netty:netty-codec-http3
4.2.9.Final
fixed in 4.2.13.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-44892NONE0
io.netty:netty-codec-http3
4.2.9.Final
fixed in 4.2.15.Final
0.5%
Theoretical Threat
Not Applicable
CVE-2026-8149NONE0
org.bouncycastle:bc-fips
2.1.2
No fix yet
0.2%
Theoretical Threat
Not Applicable