Vulnerability Reportpingcap/tidb:v8.5.4

pingcap/tidb:v8.5.4
DIGESTsha256:e986dadd59937fbfcbdfe7fd084421cc65988da8b795f75194b05a0292635ead

Executive Summary

Threat Score
50/100CAUTION
Reputation
RELIABLE

This image carries significant risk; production deployment is highly discouraged without strict compensating controls. It contains 25 exposed vulnerabilities of medium-high severity (none critical), primarily leading to denial of service or information disclosure. CVE-2025-68121 could permit authentication bypass if TLS configuration is mutated, while CVE-2026-45186 enables remote DoS via crafted XML. Network segmentation and disabling unused modules (e.g., DTLS) can mitigate most risks, but the overall exposure warrants caution.

Vulnerabilities

Vulnerability Log

125 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2025-68121MEDIUM6.8
stdlib
v1.23.12
fixed in 1.24.13, 1.25.7, 1.26.0-rc.3
0.8%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-45186MEDIUM6.38
expat
2.5.0-5.el9_7.1
fixed in 2.5.0-6.el9_8.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-33846MEDIUM6.38
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-42009MEDIUM6.38
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-4424MEDIUM6.38
libarchive
3.5.3-7.el9_7
fixed in 3.5.3-9.el9_7
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-27135MEDIUM6.38
libnghttp2
1.43.0-6.el9
fixed in 1.43.0-6.el9_7.1
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-34183MEDIUM6.38
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-28390MEDIUM6.38
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-3.el9_8
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-41602MEDIUM6.38
github.com/apache/thrift
v0.16.0
fixed in 0.23.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61726MEDIUM6.38
stdlib
v1.23.12
fixed in 1.24.12, 1.25.6
0.8%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2025-61729MEDIUM6.38
stdlib
v1.23.12
fixed in 1.24.11, 1.25.5
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-25679MEDIUM6.38
stdlib
v1.23.12
fixed in 1.25.8, 1.26.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-32280MEDIUM6.38
stdlib
v1.23.12
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-32281MEDIUM6.38
stdlib
v1.23.12
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-32283MEDIUM6.38
stdlib
v1.23.12
fixed in 1.25.9, 1.26.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-33811MEDIUM6.38
stdlib
v1.23.12
fixed in 1.25.10, 1.26.3
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-33814MEDIUM6.38
stdlib
v1.23.12
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-39820MEDIUM6.38
stdlib
v1.23.12
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39836MEDIUM6.38
stdlib
v1.23.12
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61728MEDIUM6.38
stdlib
v1.23.12
fixed in 1.24.12, 1.25.6
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-3833MEDIUM6.29
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42011MEDIUM6.29
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-34182MEDIUM6.29
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-33186MEDIUM6.18
google.golang.org/grpc
v1.63.2
fixed in 1.79.3
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42012MEDIUM6.03
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4878MEDIUM5.95
libcap
2.48-10.el9
fixed in 2.48-10.el9_7.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42014MEDIUM5.61
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-14512MEDIUM5.52
glib2
2.68.4-18.el9_7.1
fixed in 2.68.4-19.el9_8.1
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
glibc
2.34-231.el9_7.10
fixed in 2.34-270.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
glibc-common
2.34-231.el9_7.10
fixed in 2.34-270.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
glibc-minimal-langpack
2.34-231.el9_7.10
fixed in 2.34-270.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-61727MEDIUM5.52
stdlib
v1.23.12
fixed in 1.24.11, 1.25.5
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-32282MEDIUM5.44
stdlib
v1.23.12
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-34181MEDIUM5.35
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-32289MEDIUM5.18
stdlib
v1.23.12
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-40355MEDIUM5.02
krb5-libs
1.21.1-8.el9_6
fixed in 1.21.1-10.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-40356MEDIUM5.02
krb5-libs
1.21.1-8.el9_6
fixed in 1.21.1-10.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42764MEDIUM5.02
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-31790MEDIUM5.02
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-2.el9_8
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-32288MEDIUM4.67
stdlib
v1.23.12
fixed in 1.25.9, 1.26.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-27142MEDIUM4.59
stdlib
v1.23.12
fixed in 1.25.8, 1.26.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39826MEDIUM4.59
stdlib
v1.23.12
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc
2.34-231.el9_7.10
fixed in 2.34-270.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc-common
2.34-231.el9_7.10
fixed in 2.34-270.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
glibc-minimal-langpack
2.34-231.el9_7.10
fixed in 2.34-270.el9_8
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42015MEDIUM4.5
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-47914MEDIUM4.5
golang.org/x/crypto
v0.36.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58181MEDIUM4.5
golang.org/x/crypto
v0.36.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-47912MEDIUM4.5
stdlib
v1.23.12
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58185MEDIUM4.5
stdlib
v1.23.12
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58187MEDIUM4.5
stdlib
v1.23.12
fixed in 1.24.9, 1.25.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-58188MEDIUM4.5
stdlib
v1.23.12
fixed in 1.24.8, 1.25.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-58189MEDIUM4.5
stdlib
v1.23.12
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-61723MEDIUM4.5
stdlib
v1.23.12
fixed in 1.24.8, 1.25.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61724MEDIUM4.5
stdlib
v1.23.12
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-61725MEDIUM4.5
stdlib
v1.23.12
fixed in 1.24.8, 1.25.2
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-61730MEDIUM4.5
stdlib
v1.23.12
fixed in 1.24.12, 1.25.6
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42507MEDIUM4.5
stdlib
v1.23.12
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-58186MEDIUM4.5
stdlib
v1.23.12
fixed in 1.24.8, 1.25.2
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM4.25
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-28421LOW3.98
vim-minimal
2:8.2.2637-23.el9_7
fixed in 2:8.2.2637-23.el9_7.2
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-33412LOW3.72
vim-minimal
2:8.2.2637-23.el9_7
fixed in 2:8.2.2637-23.el9_7.2
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-25749LOW3.72
vim-minimal
2:8.2.2637-23.el9_7
fixed in 2:8.2.2637-23.el9_7.1
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-4786LOW3.62
python3-libs
3.9.25-3.el9_7.1
fixed in 3.9.25-7.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-35177LOW3.62
vim-minimal
2:8.2.2637-23.el9_7
fixed in 2:8.2.2637-26.el9_8.5
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-4438LOW3.4
glibc
2.34-231.el9_7.10
fixed in 2.34-270.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
glibc-common
2.34-231.el9_7.10
fixed in 2.34-270.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
glibc-minimal-langpack
2.34-231.el9_7.10
fixed in 2.34-270.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-34181LOW3.21
openssl
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-42768LOW3.21
openssl
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-39975LOW3.17
krb5-libs
1.21.1-8.el9_6
fixed in 1.21.1-10.el9_8
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-3832LOW3.15
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-5419LOW3.15
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42764LOW3.01
openssl
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-42769LOW3.01
openssl
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-42770LOW3.01
openssl
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-9076LOW3.01
openssl
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-31790LOW3.01
openssl
1:3.5.1-7.el9_7
fixed in 1:3.5.5-2.el9_8
1.0%
Theoretical Threat
Post-Exploit
CVE-2025-14087LOW3
glib2
2.68.4-18.el9_7.1
fixed in 2.68.4-19.el9_8.1
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-42010LOW3
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-45447LOW2.92
openssl
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2026-28417LOW2.81
vim-minimal
2:8.2.2637-23.el9_7
fixed in 2:8.2.2637-23.el9_7.2
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-7383LOW2.8
openssl
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-33845LOW2.78
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl-libs
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-5121LOW2.7
libarchive
3.5.3-7.el9_7
fixed in 3.5.3-9.el9_7
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-2100LOW2.7
p11-kit
0.25.3-3.el9_5
fixed in 0.26.2-1.el9
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-2100LOW2.7
p11-kit-trust
0.25.3-3.el9_5
fixed in 0.26.2-1.el9
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-32952LOW2.7
github.com/Azure/go-ntlmssp
v0.0.0-20221128193559-754e69321358
fixed in 0.1.1
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-42766LOW2.7
openssl
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-42767LOW2.7
openssl
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-34180LOW2.55
openssl
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-42013LOW2.51
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-5260LOW2.51
gnutls
3.8.3-10.el9_7
fixed in 3.8.10-4.el9_8
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-34982LOW2.51
vim-minimal
2:8.2.2637-23.el9_7
fixed in 2:8.2.2637-26.el9_8.4
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6100LOW2.48
python3
3.9.25-3.el9_7.1
fixed in 3.9.25-7.el9_8
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-6100LOW2.48
python3-libs
3.9.25-3.el9_7.1
fixed in 3.9.25-7.el9_8
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-29111LOW2.39
systemd-libs
252-55.el9_7.7.rocky.0.1
fixed in 252-67.el9_8.2.rocky.0.1
0.1%
Theoretical Threat
Post-Exploit
CVE-2023-36054LOW2.34
krb5-libs
1.21.1-8.el9_6
fixed in 1.21.1-10.el9_8
2.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-34183LOW2.29
openssl
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-28390LOW2.29
openssl
1:3.5.1-7.el9_7
fixed in 1:3.5.5-3.el9_8
0.8%
Theoretical Threat
Post-Exploit
CVE-2025-30204LOW2.29
github.com/golang-jwt/jwt/v5
v5.2.1
fixed in 5.2.2
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-22868LOW2.29
golang.org/x/oauth2
v0.23.0
fixed in 0.27.0
0.8%
Theoretical Threat
Post-Exploit
CVE-2025-58183LOW2.29
stdlib
v1.23.12
fixed in 1.24.8, 1.25.2
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-34182LOW2.26
openssl
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-4786LOW2.17
python3
3.9.25-3.el9_7.1
fixed in 3.9.25-7.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-27139LOW2.12
stdlib
v1.23.12
fixed in 1.25.8, 1.26.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW1.89
openssl
1:3.5.1-7.el9_7
fixed in 1:3.5.5-4.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-4519LOW1.68
python3
3.9.25-3.el9_7.1
fixed in 3.9.25-7.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-4519LOW1.68
python3-libs
3.9.25-3.el9_7.1
fixed in 3.9.25-7.el9_8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-39823NONE0
stdlib
v1.23.12
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39825NONE0
stdlib
v1.23.12
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42499NONE0
stdlib
v1.23.12
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42504NONE0
stdlib
v1.23.12
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Not Applicable
CVE-2026-27145NONE0
stdlib
v1.23.12
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable