Vulnerability Reportredhat/ubi9-minimal:latest

redhat/ubi9-minimal:latestredhat/ubi9-minimal:9.8-1788939036redhat/ubi9-minimal:9.8redhat/ubi9-minimal:1788939088
digestsha256:d235f607e1d6d833f031db107dc42206e4dd4d5aa9142c43d3771fb7f9bea76a

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
TRUSTED

This image is safe for production use. Although the vulnerability stats show 45 exposed and 75 post-exploit findings, none reach severity 6.0, with maximum severities of 5.95 exposed and 3.82 post-exploit. The image comes from a verified Red Hat publisher and is pinned by digest, which supports supply-chain trust. No CVE IDs were provided in the top exposed or post-exploit findings, so there is no specific high-impact vulnerability to remediate from the supplied data.

Vulnerabilities

Vulnerability Log

122 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-44604MEDIUM5.95
rpm-libs
4.16.1.3-40.el9
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-22185MEDIUM5.78
openldap
2.6.8-4.el9
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4105MEDIUM5.7
systemd-libs
252-67.el9_8.4
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-5915MEDIUM5.61
libarchive
3.5.3-11.el9_8
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-5918MEDIUM5.61
libarchive
3.5.3-11.el9_8
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-1757MEDIUM5.27
libxml2
2.9.13-14.el9_8.4
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-0990MEDIUM5.02
libxml2
2.9.13-14.el9_8.4
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-5916MEDIUM4.76
libarchive
3.5.3-11.el9_8
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-60753MEDIUM4.67
libarchive
3.5.3-11.el9_8
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5745MEDIUM4.67
libarchive
3.5.3-11.el9_8
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-1632MEDIUM4.67
libarchive
3.5.3-11.el9_8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2021-46195MEDIUM4.67
libgcc
11.5.0-14.el9
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2022-27943MEDIUM4.67
libgcc
11.5.0-14.el9
No fix yet
0.9%
Theoretical Threat
Directly Exposed
CVE-2021-46195MEDIUM4.67
libstdc++
11.5.0-14.el9
No fix yet
0.8%
Theoretical Threat
Directly Exposed
CVE-2022-27943MEDIUM4.67
libstdc++
11.5.0-14.el9
No fix yet
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-44605MEDIUM4.67
rpm-libs
4.16.1.3-40.el9
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2024-0232MEDIUM4.67
sqlite-libs
3.34.1-11.el9_8
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib
1.2.11-40.el9
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-1489MEDIUM4.59
glib2
2.68.4-19.el9_8.10
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2023-30571MEDIUM4.5
libarchive
3.5.3-11.el9_8
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-13595MEDIUM4.5
libblkid
2.37.4-25.el9
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-13595MEDIUM4.5
libmount
2.37.4-25.el9
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-13595MEDIUM4.5
libsmartcols
2.37.4-25.el9
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-13595MEDIUM4.5
libuuid
2.37.4-25.el9
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-34743MEDIUM4.5
xz-libs
5.2.5-8.el9_0
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42250MEDIUM4.25
bzip2-libs
1.0.8-11.el9
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-11850MEDIUM4.25
krb5-libs
1.21.1-10.el9_8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-5917MEDIUM4.25
libarchive
3.5.3-11.el9_8
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libblkid
2.37.4-25.el9
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libmount
2.37.4-25.el9
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libsmartcols
2.37.4-25.el9
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libuuid
2.37.4-25.el9
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2024-13176MEDIUM4
openssl-libs
1:3.5.5-6.el9_8
No fix yet
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-11586LOW3.82
curl-minimal
7.76.1-40.el9_8.5
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-5773LOW3.82
curl-minimal
7.76.1-40.el9_8.5
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-6276LOW3.82
curl-minimal
7.76.1-40.el9_8.5
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-11586LOW3.82
libcurl-minimal
7.76.1-40.el9_8.5
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-5773LOW3.82
libcurl-minimal
7.76.1-40.el9_8.5
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-6276LOW3.82
libcurl-minimal
7.76.1-40.el9_8.5
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2023-4156LOW3.62
gawk
5.1.0-6.el9
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-44604LOW3.57
rpm
4.16.1.3-40.el9
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-1484LOW3.57
glib2
2.68.4-19.el9_8.10
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2024-11053LOW3.54
curl-minimal
7.76.1-40.el9_8.5
No fix yet
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2024-11053LOW3.54
libcurl-minimal
7.76.1-40.el9_8.5
No fix yet
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2025-13034LOW3.47
curl-minimal
7.76.1-40.el9_8.5
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-13034LOW3.47
libcurl-minimal
7.76.1-40.el9_8.5
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-11856LOW3.31
curl-minimal
7.76.1-40.el9_8.5
No fix yet
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-3784LOW3.31
curl-minimal
7.76.1-40.el9_8.5
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-5545LOW3.31
curl-minimal
7.76.1-40.el9_8.5
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6429LOW3.31
curl-minimal
7.76.1-40.el9_8.5
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-8924LOW3.31
curl-minimal
7.76.1-40.el9_8.5
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-14524LOW3.31
curl-minimal
7.76.1-40.el9_8.5
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-11856LOW3.31
libcurl-minimal
7.76.1-40.el9_8.5
No fix yet
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-3784LOW3.31
libcurl-minimal
7.76.1-40.el9_8.5
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-5545LOW3.31
libcurl-minimal
7.76.1-40.el9_8.5
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6429LOW3.31
libcurl-minimal
7.76.1-40.el9_8.5
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-8924LOW3.31
libcurl-minimal
7.76.1-40.el9_8.5
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-14524LOW3.31
libcurl-minimal
7.76.1-40.el9_8.5
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-15028LOW3.31
libarchive
3.5.3-11.el9_8
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5958LOW3.21
sed
4.8-10.el9
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-3360LOW3.15
glib2
2.68.4-19.el9_8.10
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-7039LOW3.15
glib2
2.68.4-19.el9_8.10
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-0988LOW3.15
glib2
2.68.4-19.el9_8.10
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-0989LOW3.15
libxml2
2.9.13-14.el9_8.4
No fix yet
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-56391LOW3.11
coreutils-single
8.32-41.el9_8
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-56392LOW3.11
coreutils-single
8.32-41.el9_8
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-9232LOW3.1
openssl-libs
1:3.5.5-6.el9_8
No fix yet
2.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-6653LOW3
libxml2
2.9.13-14.el9_8.4
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-31789LOW3
openssl-libs
1:3.5.5-6.el9_8
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-24883LOW2.8
gnupg2
2.3.3-5.el9_7
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-44605LOW2.8
rpm
4.16.1.3-40.el9
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-41990LOW2.8
libgcrypt
1.10.0-13.el9_8
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-70873LOW2.8
sqlite-libs
3.34.1-11.el9_8
No fix yet
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-27113LOW2.7
libxml2
2.9.13-14.el9_8.4
No fix yet
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2022-41409LOW2.7
pcre2
10.40-6.el9
No fix yet
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2022-41409LOW2.7
pcre2-syntax
10.40-6.el9
No fix yet
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-4873LOW2.7
curl-minimal
7.76.1-40.el9_8.5
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6253LOW2.7
curl-minimal
7.76.1-40.el9_8.5
No fix yet
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-7168LOW2.7
curl-minimal
7.76.1-40.el9_8.5
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-4873LOW2.7
libcurl-minimal
7.76.1-40.el9_8.5
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6253LOW2.7
libcurl-minimal
7.76.1-40.el9_8.5
No fix yet
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-7168LOW2.7
libcurl-minimal
7.76.1-40.el9_8.5
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2024-7264LOW2.69
curl-minimal
7.76.1-40.el9_8.5
No fix yet
17.3%
High Exploitation Risk
Post-Exploit
CVE-2024-7264LOW2.69
libcurl-minimal
7.76.1-40.el9_8.5
No fix yet
17.3%
High Exploitation Risk
Post-Exploit
CVE-2026-8925LOW2.48
curl-minimal
7.76.1-40.el9_8.5
No fix yet
0.7%
Theoretical Threat
Post-Exploit
CVE-2025-15079LOW2.48
curl-minimal
7.76.1-40.el9_8.5
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-8925LOW2.48
libcurl-minimal
7.76.1-40.el9_8.5
No fix yet
0.7%
Theoretical Threat
Post-Exploit
CVE-2025-15079LOW2.48
libcurl-minimal
7.76.1-40.el9_8.5
No fix yet
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-28387LOW2.48
openssl-libs
1:3.5.5-6.el9_8
No fix yet
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-16517LOW2.46
libarchive
3.5.3-11.el9_8
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-0992LOW2.46
libxml2
2.9.13-14.el9_8.4
No fix yet
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-14017LOW2.45
curl-minimal
7.76.1-40.el9_8.5
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-8926LOW2.45
curl-minimal
7.76.1-40.el9_8.5
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-14017LOW2.45
libcurl-minimal
7.76.1-40.el9_8.5
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-8926LOW2.45
libcurl-minimal
7.76.1-40.el9_8.5
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-15224LOW2.4
curl-minimal
7.76.1-40.el9_8.5
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-68972LOW2.4
gnupg2
2.3.3-5.el9_7
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-30258LOW2.4
gnupg2
2.3.3-5.el9_7
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-15224LOW2.4
libcurl-minimal
7.76.1-40.el9_8.5
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-11979LOW2.39
libxml2
2.9.13-14.el9_8.4
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-1485LOW2.38
glib2
2.68.4-19.el9_8.10
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2024-9681LOW2.34
curl-minimal
7.76.1-40.el9_8.5
No fix yet
2.0%
Low-Moderate Risk
Post-Exploit
CVE-2024-9681LOW2.34
libcurl-minimal
7.76.1-40.el9_8.5
No fix yet
2.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-11352LOW2.29
curl-minimal
7.76.1-40.el9_8.5
No fix yet
0.7%
Theoretical Threat
Post-Exploit
CVE-2023-32636LOW2.29
glib2
2.68.4-19.el9_8.10
No fix yet
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-11352LOW2.29
libcurl-minimal
7.76.1-40.el9_8.5
No fix yet
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-6732LOW2.29
libxml2
2.9.13-14.el9_8.4
No fix yet
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-28388LOW2.29
openssl-libs
1:3.5.5-6.el9_8
No fix yet
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-28389LOW2.29
openssl-libs
1:3.5.5-6.el9_8
No fix yet
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-16118LOW2.17
glib2
2.68.4-19.el9_8.10
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2024-41996LOW2.12
openssl-libs
1:3.5.5-6.el9_8
No fix yet
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-4426LOW1.99
libarchive
3.5.3-11.el9_8
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-9149LOW1.99
libsolv
0.7.24-6.el9_8
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-9150LOW1.99
libsolv
0.7.24-6.el9_8
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2023-45322LOW1.99
libxml2
2.9.13-14.el9_8.4
No fix yet
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-2673LOW1.99
openssl-fips-provider
3.0.7-11.el9_8
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-2673LOW1.99
openssl-fips-provider-so
3.0.7-11.el9_8
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-2673LOW1.99
openssl-libs
1:3.5.5-6.el9_8
No fix yet
0.4%
Theoretical Threat
Post-Exploit
CVE-2022-3219LOW1.68
gnupg2
2.3.3-5.el9_7
No fix yet
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-57062LOW1.48
gnupg2
2.3.3-5.el9_7
No fix yet
0.1%
Theoretical Threat
Post-Exploit
CVE-2023-50495NONE0
ncurses-base
6.2-12.20210508.el9
No fix yet
1.0%
Theoretical Threat
Not Applicable
CVE-2023-50495NONE0
ncurses-libs
6.2-12.20210508.el9
No fix yet
1.0%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.