Vulnerability Reportpingcap/tidb:v7.5.7

pingcap/tidb:v7.5.7
DIGESTsha256:2c2a2bff9a588cf2d2e6b8a3c41e173aef9f1063d6af8ab9587913021c3dcd18

Executive Summary

Threat Score
50/100CAUTION
Reputation
RELIABLE

This image carries significant risk; production deployment is highly discouraged without strict compensating controls. The exposed surface contains 42 vulnerabilities of medium severity (6.0-6.9), including heap corruption in glibc (CVE-2026-0861) and TLS certificate validation bypass (CVE-2025-68121). However, exploitation of these vulnerabilities typically requires non-default configurations or specific attack conditions, reducing practical exploitability. For instance, CVE-2025-68121 only affects TLS session resumption when the config is cloned and mutated between handshakes, which is not the default TiDB behavior. Similarly, CVE-2026-42010 in gnutls requires RSA-PSK ciphers, which TiDB does not use. While the image is from a reputable source and pinned by digest, remediating these vulnerabilities is recommended to reduce the attack surface.

Vulnerabilities

Vulnerability Log

227 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-0861MEDIUM6.88
glibc
2.34-168.el9_6.23
fixed in 2.34-231.el9_7.10
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-0861MEDIUM6.88
glibc-common
2.34-168.el9_6.23
fixed in 2.34-231.el9_7.10
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-0861MEDIUM6.88
glibc-minimal-langpack
2.34-168.el9_6.23
fixed in 2.34-231.el9_7.10
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-68121MEDIUM6.8
stdlib
v1.21.13
fixed in 1.24.13, 1.25.7, 1.26.0-rc.3
0.8%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42010MEDIUM6.66
gnutls
3.8.3-6.el9
fixed in 3.8.10-4.el9_8
0.8%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2025-5914MEDIUM6.63
libarchive
3.5.3-5.el9_6
fixed in 3.5.3-6.el9_6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-29111MEDIUM6.63
systemd-libs
252-51.el9_6.1
fixed in 252-67.el9_8.2.rocky.0.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-13601MEDIUM6.54
glib2
2.68.4-16.el9_6.2
fixed in 2.68.4-18.el9_7.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2023-36054MEDIUM6.5
krb5-libs
1.21.1-8.el9_6
fixed in 1.21.1-10.el9_8
2.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-45186MEDIUM6.38
expat
2.5.0-5.el9_6
fixed in 2.5.0-6.el9_8.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-33846MEDIUM6.38
gnutls
3.8.3-6.el9
fixed in 3.8.10-4.el9_8
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-42009MEDIUM6.38
gnutls
3.8.3-6.el9
fixed in 3.8.10-4.el9_8
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-4111MEDIUM6.38
libarchive
3.5.3-5.el9_6
fixed in 3.5.3-7.el9_7
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-4424MEDIUM6.38
libarchive
3.5.3-5.el9_6
fixed in 3.5.3-9.el9_7
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-27135MEDIUM6.38
libnghttp2
1.43.0-6.el9
fixed in 1.43.0-6.el9_7.1
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-69421MEDIUM6.38
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.1-7.el9_7
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-34183MEDIUM6.38
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-28390MEDIUM6.38
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-3.el9_8
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-41602MEDIUM6.38
github.com/apache/thrift
v0.13.1-0.20201008052519-daf620915714
fixed in 0.23.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-30204MEDIUM6.38
github.com/golang-jwt/jwt
v3.2.1+incompatible
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2024-21664MEDIUM6.38
github.com/lestrrat-go/jwx/v2
v2.0.11
fixed in 2.0.19
0.9%
Theoretical Threat
Directly Exposed
CVE-2025-22869MEDIUM6.38
golang.org/x/crypto
v0.21.0
fixed in 0.35.0
0.9%
Theoretical Threat
Directly Exposed
CVE-2025-22868MEDIUM6.38
golang.org/x/oauth2
v0.16.0
fixed in 0.27.0
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-61726MEDIUM6.38
stdlib
v1.21.13
fixed in 1.24.12, 1.25.6
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-61729MEDIUM6.38
stdlib
v1.21.13
fixed in 1.24.11, 1.25.5
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-25679MEDIUM6.38
stdlib
v1.21.13
fixed in 1.25.8, 1.26.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-32280MEDIUM6.38
stdlib
v1.21.13
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-32281MEDIUM6.38
stdlib
v1.21.13
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-32283MEDIUM6.38
stdlib
v1.21.13
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-33811MEDIUM6.38
stdlib
v1.21.13
fixed in 1.25.10, 1.26.3
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-33814MEDIUM6.38
stdlib
v1.21.13
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-39820MEDIUM6.38
stdlib
v1.21.13
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39836MEDIUM6.38
stdlib
v1.21.13
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-58183MEDIUM6.38
stdlib
v1.21.13
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-61728MEDIUM6.38
stdlib
v1.21.13
fixed in 1.24.12, 1.25.6
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-3833MEDIUM6.29
gnutls
3.8.3-6.el9
fixed in 3.8.10-4.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42011MEDIUM6.29
gnutls
3.8.3-6.el9
fixed in 3.8.10-4.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-69419MEDIUM6.29
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.1-7.el9_7
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34182MEDIUM6.29
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-33186MEDIUM6.18
google.golang.org/grpc
v1.59.0
fixed in 1.79.3
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42012MEDIUM6.03
gnutls
3.8.3-6.el9
fixed in 3.8.10-4.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-45339MEDIUM6.03
github.com/golang/glog
v1.2.0
fixed in 1.2.4
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4878MEDIUM5.95
libcap
2.48-9.el9_2
fixed in 2.48-10.el9_7.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-47907MEDIUM5.95
stdlib
v1.21.13
fixed in 1.23.12, 1.24.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-34158MEDIUM5.9
stdlib
v1.21.13
fixed in 1.22.7, 1.23.1
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2024-28122MEDIUM5.78
github.com/lestrrat-go/jwx/v2
v2.0.11
fixed in 2.0.21
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-4673MEDIUM5.78
stdlib
v1.21.13
fixed in 1.23.10, 1.24.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42014MEDIUM5.61
gnutls
3.8.3-6.el9
fixed in 3.8.10-4.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-9230MEDIUM5.6
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.1-4.el9_7
1.8%
Low-Moderate Risk
Directly Exposed
CVE-2025-14512MEDIUM5.52
glib2
2.68.4-16.el9_6.2
fixed in 2.68.4-19.el9_8.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
glibc
2.34-168.el9_6.23
fixed in 2.34-270.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
glibc-common
2.34-168.el9_6.23
fixed in 2.34-270.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
glibc-minimal-langpack
2.34-168.el9_6.23
fixed in 2.34-270.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-6395MEDIUM5.52
gnutls
3.8.3-6.el9
fixed in 3.8.3-6.el9_6.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-22872MEDIUM5.52
golang.org/x/net
v0.23.0
fixed in 0.38.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-47906MEDIUM5.52
stdlib
v1.21.13
fixed in 1.23.12, 1.24.6
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-61727MEDIUM5.52
stdlib
v1.21.13
fixed in 1.24.11, 1.25.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-32282MEDIUM5.44
stdlib
v1.21.13
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-34181MEDIUM5.35
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-59375MEDIUM5.3
expat
2.5.0-5.el9_6
fixed in 2.5.0-5.el9_7.1
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-32989MEDIUM5.3
gnutls
3.8.3-6.el9
fixed in 3.8.3-6.el9_6.2
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-11187MEDIUM5.18
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.1-7.el9_7
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-32289MEDIUM5.18
stdlib
v1.21.13
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-15281MEDIUM5.02
glibc
2.34-168.el9_6.23
fixed in 2.34-231.el9_7.10
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-15281MEDIUM5.02
glibc-common
2.34-168.el9_6.23
fixed in 2.34-231.el9_7.10
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-15281MEDIUM5.02
glibc-minimal-langpack
2.34-168.el9_6.23
fixed in 2.34-231.el9_7.10
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-40355MEDIUM5.02
krb5-libs
1.21.1-8.el9_6
fixed in 1.21.1-10.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-40356MEDIUM5.02
krb5-libs
1.21.1-8.el9_6
fixed in 1.21.1-10.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-15468MEDIUM5.02
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.1-7.el9_7
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-66199MEDIUM5.02
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.1-7.el9_7
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69420MEDIUM5.02
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.1-7.el9_7
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-22796MEDIUM5.02
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.1-7.el9_7
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42764MEDIUM5.02
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-31790MEDIUM5.02
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-2.el9_8
1.0%
Theoretical Threat
Directly Exposed
CVE-2024-34155MEDIUM5.02
stdlib
v1.21.13
fixed in 1.22.7, 1.23.1
0.8%
Theoretical Threat
Directly Exposed
CVE-2024-45336MEDIUM5.02
stdlib
v1.21.13
fixed in 1.22.11, 1.23.5, 1.24.0-rc.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-9714MEDIUM4.67
libxml2
2.9.13-12.el9_6
fixed in 2.9.13-14.el9_7
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-15469MEDIUM4.67
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.1-7.el9_7
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-22795MEDIUM4.67
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.1-7.el9_7
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-35255MEDIUM4.67
github.com/Azure/azure-sdk-for-go/sdk/azidentity
v1.1.0
fixed in 1.6.0-beta.4.0.20240610221955-50774cd97099
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-32288MEDIUM4.67
stdlib
v1.21.13
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-22871MEDIUM4.59
stdlib
v1.21.13
fixed in 1.23.8, 1.24.2
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-27142MEDIUM4.59
stdlib
v1.21.13
fixed in 1.25.8, 1.26.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39826MEDIUM4.59
stdlib
v1.21.13
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-6965MEDIUM4.58
sqlite-libs
3.34.1-8.el9_6
fixed in 3.34.1-9.el9_7
64.9%
Actively Exploited
Post-Exploit
CVE-2026-0915MEDIUM4.5
glibc
2.34-168.el9_6.23
fixed in 2.34-231.el9_7.10
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc
2.34-168.el9_6.23
fixed in 2.34-270.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-0915MEDIUM4.5
glibc-common
2.34-168.el9_6.23
fixed in 2.34-231.el9_7.10
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc-common
2.34-168.el9_6.23
fixed in 2.34-270.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-0915MEDIUM4.5
glibc-minimal-langpack
2.34-168.el9_6.23
fixed in 2.34-231.el9_7.10
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc-minimal-langpack
2.34-168.el9_6.23
fixed in 2.34-270.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42015MEDIUM4.5
gnutls
3.8.3-6.el9
fixed in 3.8.10-4.el9_8
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-14831MEDIUM4.5
gnutls
3.8.3-6.el9
fixed in 3.8.3-10.el9_7
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2023-49290MEDIUM4.5
github.com/lestrrat-go/jwx/v2
v2.0.11
fixed in 2.0.18
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-47914MEDIUM4.5
golang.org/x/crypto
v0.21.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58181MEDIUM4.5
golang.org/x/crypto
v0.21.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-22866MEDIUM4.5
stdlib
v1.21.13
fixed in 1.22.12, 1.23.6, 1.24.0-rc.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-22873MEDIUM4.5
stdlib
v1.21.13
fixed in 1.23.9, 1.24.3
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-47912MEDIUM4.5
stdlib
v1.21.13
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58185MEDIUM4.5
stdlib
v1.21.13
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58187MEDIUM4.5
stdlib
v1.21.13
fixed in 1.24.9, 1.25.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58188MEDIUM4.5
stdlib
v1.21.13
fixed in 1.24.8, 1.25.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-58189MEDIUM4.5
stdlib
v1.21.13
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-61723MEDIUM4.5
stdlib
v1.21.13
fixed in 1.24.8, 1.25.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61724MEDIUM4.5
stdlib
v1.21.13
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-61725MEDIUM4.5
stdlib
v1.21.13
fixed in 1.24.8, 1.25.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61730MEDIUM4.5
stdlib
v1.21.13
fixed in 1.24.12, 1.25.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42507MEDIUM4.5
stdlib
v1.21.13
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-58186MEDIUM4.5
stdlib
v1.21.13
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM4.25
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-15467MEDIUM4.06
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.1-7.el9_7
48.7%
High Exploitation Risk
Post-Exploit
CVE-2025-15467MEDIUM4.06
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.1-7.el9_7
48.7%
High Exploitation Risk
Post-Exploit
CVE-2025-68160MEDIUM4
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.1-7.el9_7
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-4598MEDIUM4
systemd-libs
252-51.el9_6.1
fixed in 252-55.el9_7.7.rocky.0.1
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-11083LOW3.98
binutils
2.35.2-63.el9
fixed in 2.35.2-67.el9_7.1
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-11083LOW3.98
binutils-gold
2.35.2-63.el9
fixed in 2.35.2-67.el9_7.1
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-28421LOW3.98
vim-minimal
2:8.2.2637-22.el9_6
fixed in 2:8.2.2637-23.el9_7.2
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-34183LOW3.82
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-28390LOW3.82
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-3.el9_8
0.8%
Theoretical Threat
Post-Exploit
CVE-2025-69419LOW3.77
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.1-7.el9_7
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-34182LOW3.77
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-22870LOW3.74
golang.org/x/net
v0.23.0
fixed in 0.36.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-22870LOW3.74
stdlib
v1.21.13
fixed in 1.23.7, 1.24.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-33412LOW3.72
vim-minimal
2:8.2.2637-22.el9_6
fixed in 2:8.2.2637-23.el9_7.2
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-25749LOW3.72
vim-minimal
2:8.2.2637-22.el9_6
fixed in 2:8.2.2637-23.el9_7.1
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-4786LOW3.62
python3
3.9.21-2.el9_6.1
fixed in 3.9.25-7.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-15366LOW3.62
python3
3.9.21-2.el9_6.1
fixed in 3.9.25-3.el9_7.1
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-15367LOW3.62
python3
3.9.21-2.el9_6.1
fixed in 3.9.25-3.el9_7.1
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-1299LOW3.62
python3
3.9.21-2.el9_6.1
fixed in 3.9.25-3.el9_7.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-4786LOW3.62
python3-libs
3.9.21-2.el9_6.1
fixed in 3.9.25-7.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-15366LOW3.62
python3-libs
3.9.21-2.el9_6.1
fixed in 3.9.25-3.el9_7.1
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-15367LOW3.62
python3-libs
3.9.21-2.el9_6.1
fixed in 3.9.25-3.el9_7.1
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-1299LOW3.62
python3-libs
3.9.21-2.el9_6.1
fixed in 3.9.25-3.el9_7.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-35177LOW3.62
vim-minimal
2:8.2.2637-22.el9_6
fixed in 2:8.2.2637-26.el9_8.5
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-68973LOW3.57
gnupg2
2.3.3-4.el9
fixed in 2.3.3-5.el9_7
0.1%
Theoretical Threat
Post-Exploit
CVE-2024-45341LOW3.57
stdlib
v1.21.13
fixed in 1.22.11, 1.23.5, 1.24.0-rc.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
glibc
2.34-168.el9_6.23
fixed in 2.34-270.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
glibc-common
2.34-168.el9_6.23
fixed in 2.34-270.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
glibc-minimal-langpack
2.34-168.el9_6.23
fixed in 2.34-270.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-9820LOW3.4
gnutls
3.8.3-6.el9
fixed in 3.8.3-10.el9_7
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69418LOW3.4
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.1-7.el9_7
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-9230LOW3.36
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.1-4.el9_7
1.8%
Low-Moderate Risk
Post-Exploit
CVE-2026-34181LOW3.21
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-42768LOW3.21
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-9086LOW3.18
curl
7.76.1-31.el9_6.1
fixed in 7.76.1-35.el9_7.3
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-9086LOW3.18
libcurl-minimal
7.76.1-31.el9_6.1
fixed in 7.76.1-35.el9_7.3
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2023-39975LOW3.17
krb5-libs
1.21.1-8.el9_6
fixed in 1.21.1-10.el9_8
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-3832LOW3.15
gnutls
3.8.3-6.el9
fixed in 3.8.10-4.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-5419LOW3.15
gnutls
3.8.3-6.el9
fixed in 3.8.10-4.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-11187LOW3.11
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.1-7.el9_7
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-15468LOW3.01
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.1-7.el9_7
0.7%
Theoretical Threat
Post-Exploit
CVE-2025-66199LOW3.01
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.1-7.el9_7
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-69420LOW3.01
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.1-7.el9_7
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-22796LOW3.01
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.1-7.el9_7
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-42764LOW3.01
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-42769LOW3.01
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-42770LOW3.01
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-9076LOW3.01
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-31790LOW3.01
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-2.el9_8
1.0%
Theoretical Threat
Post-Exploit
CVE-2025-14087LOW3
glib2
2.68.4-16.el9_6.2
fixed in 2.68.4-19.el9_8.1
0.8%
Theoretical Threat
Post-Exploit
CVE-2025-32988LOW2.95
gnutls
3.8.3-6.el9
fixed in 3.8.3-6.el9_6.2
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2024-45337LOW2.95
golang.org/x/crypto
v0.21.0
fixed in 0.31.0
3.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2025-45582LOW2.86
tar
2:1.34-7.el9
fixed in 2:1.34-9.el9_7
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-28417LOW2.81
vim-minimal
2:8.2.2637-22.el9_6
fixed in 2:8.2.2637-23.el9_7.2
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2025-15469LOW2.8
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.1-7.el9_7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-22795LOW2.8
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.1-7.el9_7
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-7383LOW2.8
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-6075LOW2.8
python3
3.9.21-2.el9_6.1
fixed in 3.9.25-2.el9_7
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-6075LOW2.8
python3-libs
3.9.21-2.el9_6.1
fixed in 3.9.25-2.el9_7
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-33845LOW2.78
gnutls
3.8.3-6.el9
fixed in 3.8.10-4.el9_8
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl-libs
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-5121LOW2.7
libarchive
3.5.3-5.el9_6
fixed in 3.5.3-9.el9_7
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-2100LOW2.7
p11-kit
0.25.3-3.el9_5
fixed in 0.26.2-1.el9
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-2100LOW2.7
p11-kit-trust
0.25.3-3.el9_5
fixed in 0.26.2-1.el9
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-32952LOW2.7
github.com/Azure/go-ntlmssp
v0.0.0-20221128193559-754e69321358
fixed in 0.1.1
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2024-34156LOW2.7
stdlib
v1.21.13
fixed in 1.22.7, 1.23.1
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2025-48964LOW2.7
iputils
20210202-11.el9_6.1
fixed in 20210202-11.el9_6.3
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-42766LOW2.7
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-42767LOW2.7
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-12084LOW2.7
python3
3.9.21-2.el9_6.1
fixed in 3.9.25-3.el9_7
0.7%
Theoretical Threat
Post-Exploit
CVE-2025-12084LOW2.7
python3-libs
3.9.21-2.el9_6.1
fixed in 3.9.25-3.el9_7
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-34180LOW2.55
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-42013LOW2.51
gnutls
3.8.3-6.el9
fixed in 3.8.10-4.el9_8
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-5260LOW2.51
gnutls
3.8.3-6.el9
fixed in 3.8.10-4.el9_8
0.7%
Theoretical Threat
Post-Exploit
CVE-2025-32990LOW2.51
gnutls
3.8.3-6.el9
fixed in 3.8.3-6.el9_6.2
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-34982LOW2.51
vim-minimal
2:8.2.2637-22.el9_6
fixed in 2:8.2.2637-26.el9_8.4
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6100LOW2.48
python3
3.9.21-2.el9_6.1
fixed in 3.9.25-7.el9_8
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-6100LOW2.48
python3-libs
3.9.21-2.el9_6.1
fixed in 3.9.25-7.el9_8
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-68160LOW2.4
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.1-7.el9_7
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-69421LOW2.29
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.1-7.el9_7
0.8%
Theoretical Threat
Post-Exploit
CVE-2025-8194LOW2.29
python3
3.9.21-2.el9_6.1
fixed in 3.9.21-2.el9_6.2
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-8194LOW2.29
python3-libs
3.9.21-2.el9_6.1
fixed in 3.9.21-2.el9_6.2
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-0865LOW2.29
python3
3.9.21-2.el9_6.1
fixed in 3.9.25-3.el9_7.1
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-0865LOW2.29
python3-libs
3.9.21-2.el9_6.1
fixed in 3.9.25-3.el9_7.1
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-6069LOW2.19
python3
3.9.21-2.el9_6.1
fixed in 3.9.25-2.el9_7
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-8291LOW2.19
python3
3.9.21-2.el9_6.1
fixed in 3.9.25-2.el9_7
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-6069LOW2.19
python3-libs
3.9.21-2.el9_6.1
fixed in 3.9.25-2.el9_7
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-8291LOW2.19
python3-libs
3.9.21-2.el9_6.1
fixed in 3.9.25-2.el9_7
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-27139LOW2.12
stdlib
v1.21.13
fixed in 1.25.8, 1.26.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-53905LOW2.09
vim-minimal
2:8.2.2637-22.el9_6
fixed in 2:8.2.2637-23.el9_7
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-53906LOW2.09
vim-minimal
2:8.2.2637-22.el9_6
fixed in 2:8.2.2637-23.el9_7
0.7%
Theoretical Threat
Post-Exploit
CVE-2025-69418LOW2.04
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.1-7.el9_7
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-45446LOW1.89
openssl
1:3.2.2-6.el9_5.1
fixed in 1:3.5.5-4.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2024-56433LOW1.84
shadow-utils
2:4.9-12.el9
fixed in 2:4.9-15.el9
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-4519LOW1.68
python3
3.9.21-2.el9_6.1
fixed in 3.9.25-7.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-4519LOW1.68
python3-libs
3.9.21-2.el9_6.1
fixed in 3.9.25-7.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2024-5642LOW1.38
python3
3.9.21-2.el9_6.1
fixed in 3.9.25-2.el9_7
0.7%
Theoretical Threat
Post-Exploit
CVE-2024-5642LOW1.38
python3-libs
3.9.21-2.el9_6.1
fixed in 3.9.25-2.el9_7
0.7%
Theoretical Threat
Post-Exploit
CVE-2025-6020NONE0
pam
1.5.1-25.el9_6
fixed in 1.5.1-26.el9_6
0.4%
Theoretical Threat
Not Applicable
CVE-2025-8941NONE0
pam
1.5.1-25.el9_6
fixed in 1.5.1-26.el9_6
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39823NONE0
stdlib
v1.21.13
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39825NONE0
stdlib
v1.21.13
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42499NONE0
stdlib
v1.21.13
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42504NONE0
stdlib
v1.21.13
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Not Applicable
CVE-2025-0913NONE0
stdlib
v1.21.13
fixed in 1.23.10, 1.24.4
0.2%
Theoretical Threat
Not Applicable
CVE-2026-27145NONE0
stdlib
v1.21.13
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable