Last scanned:
This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could exploit request smuggling via Jetty to bypass security controls and gain unauthorized access to sensitive data, and exploit the Commons BeanUtils vulnerability to achieve remote code execution if the application passes untrusted property paths. Note: CVE-2025-48734 only applies if the application passes attacker-controlled property paths to BeanUtils, which may not be the case in typical Solr deployments; similarly, Netty-related vulnerabilities require Netty to be used as an HTTP server, which is not the primary role. The high number of vulnerabilities (70), including two critical/high-severity CVEs, underscores the need to avoid deployment until remediated.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-2332 | CRITICAL9.1 | org.eclipse.jetty:jetty-http 12.0.27 fixed in 12.1.7, 12.0.33 | 1.1% Low-Moderate Risk | Directly ExposedContext importance: HIGH |
| CVE-2025-48734 | HIGH7.04 | commons-beanutils:commons-beanutils 1.9.4 fixed in 1.11.0 | 1.5% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2026-42581 | MEDIUM6.66 | io.netty:netty-codec-http 4.2.6.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.6% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-44825 | MEDIUM6.66 | org.apache.solr:solr-core 10.0.0 No fix yet | 0.5% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-42583 | MEDIUM6.38 | io.netty:netty-codec-compression 4.2.6.Final fixed in 4.2.13.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42587 | MEDIUM6.38 | io.netty:netty-codec-http 4.2.6.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-42585 | MEDIUM6.38 | io.netty:netty-codec-http 4.2.6.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42587 | MEDIUM6.38 | io.netty:netty-codec-http2 4.2.6.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-48043 | MEDIUM6.38 | io.netty:netty-codec-http2 4.2.6.Final fixed in 4.1.135.Final, 4.2.15.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-45416 | MEDIUM6.38 | io.netty:netty-handler 4.2.6.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-50010 | MEDIUM6.38 | io.netty:netty-handler 4.2.6.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42578 | MEDIUM6.38 | io.netty:netty-handler-proxy 4.2.6.Final fixed in 4.1.133.Final, 4.2.13.Final | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-45292 | MEDIUM6.38 | io.opentelemetry:opentelemetry-api 1.56.0 fixed in 1.62.0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-40682 | MEDIUM6.38 | org.apache.opennlp:opennlp-tools 2.5.6 fixed in 2.5.9, 3.0.0-M3 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-42027 | MEDIUM6.38 | org.apache.opennlp:opennlp-tools 2.5.6 fixed in 2.5.9, 3.0.0-M3 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-42440 | MEDIUM6.38 | org.apache.opennlp:opennlp-tools 2.5.6 fixed in 2.5.9, 3.0.0-M3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-1605 | MEDIUM6.38 | org.eclipse.jetty:jetty-server 12.0.27 fixed in 12.1.6, 12.0.32 | 0.6% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-24281 | MEDIUM6.29 | org.apache.zookeeper:zookeeper 3.9.4 fixed in 3.8.6, 3.9.5 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-33871 | MEDIUM6 | io.netty:netty-codec-http2 4.2.6.Final fixed in 4.1.132.Final, 4.2.11.Final | 1.1% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2026-24308 | MEDIUM6 | org.apache.zookeeper:zookeeper 3.9.4 fixed in 3.9.5, 3.8.6 | 1.2% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2024-2236 | MEDIUM5.9 | libgcrypt20 1.10.3-2ubuntu0.1 No fix yet | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-35554 | MEDIUM5.78 | org.apache.kafka:kafka-clients 3.9.1 fixed in 3.9.2, 4.0.2, 4.1.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-4437 | MEDIUM5.52 | libc-bin 2.39-0ubuntu8.7 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-6238 | MEDIUM5.52 | libc-bin 2.39-0ubuntu8.7 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-4437 | MEDIUM5.52 | libc6 2.39-0ubuntu8.7 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-6238 | MEDIUM5.52 | libc6 2.39-0ubuntu8.7 No fix yet | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-67735 | MEDIUM5.52 | io.netty:netty-codec-http 4.2.6.Final fixed in 4.2.8.Final, 4.1.129.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-41417 | MEDIUM5.52 | io.netty:netty-codec-http 4.2.6.Final fixed in 4.1.133.Final, 4.2.13.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42580 | MEDIUM5.52 | io.netty:netty-codec-http 4.2.6.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-11143 | MEDIUM5.52 | org.eclipse.jetty:jetty-http 12.0.27 fixed in 12.0.31, 12.1.5 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-12183 | MEDIUM5.52 | org.lz4:lz4-java 1.8.0 fixed in 1.8.1 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-54512 | MEDIUM5.5 | com.fasterxml.jackson.core:jackson-databind 2.20.0 fixed in 2.18.8, 3.1.4, 2.21.4 | 0.6% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-54513 | MEDIUM5.5 | com.fasterxml.jackson.core:jackson-databind 2.20.0 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.7% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-44249 | MEDIUM5.5 | io.netty:netty-handler 4.2.6.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.6% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-13757 | MEDIUM5.27 | libp11-kit0 0.25.3-4ubuntu2.1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-13757 | MEDIUM5.27 | p11-kit 0.25.3-4ubuntu2.1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-13757 | MEDIUM5.27 | p11-kit-modules 0.25.3-4ubuntu2.1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-55163 | MEDIUM5.1 | io.grpc:grpc-netty-shaded 1.65.1 fixed in 1.75.0 | 1.0% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-33870 | MEDIUM5.1 | io.netty:netty-codec-http 4.2.6.Final fixed in 4.1.132.Final, 4.2.10.Final | 0.6% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-34479 | MEDIUM5.1 | org.apache.logging.log4j:log4j-1.2-api 2.25.3 fixed in 2.25.4 | 0.5% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-34478 | MEDIUM5.1 | org.apache.logging.log4j:log4j-core 2.25.3 fixed in 2.25.4 | 0.8% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-34480 | MEDIUM5.1 | org.apache.logging.log4j:log4j-core 2.25.3 fixed in 2.25.4 | 0.9% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-34481 | MEDIUM5.1 | org.apache.logging.log4j:log4j-layout-template-json 2.25.3 fixed in 2.25.4 | 0.6% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2025-66566 | MEDIUM5.1 | org.lz4:lz4-java 1.8.0 No fix yet | 0.6% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-5435 | MEDIUM5.02 | libc-bin 2.39-0ubuntu8.7 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-5435 | MEDIUM5.02 | libc6 2.39-0ubuntu8.7 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-34477 | MEDIUM5.02 | org.apache.logging.log4j:log4j-core 2.25.3 fixed in 2.25.4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-66382 | MEDIUM4.67 | libexpat1 2.6.1-2ubuntu0.4 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-27171 | MEDIUM4.67 | zlib1g 1:1.3.dfsg-3.1ubuntu2.1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-46718 | MEDIUM4.59 | org.apache.calcite:calcite-core 1.37.0 fixed in 1.42.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-4046 | MEDIUM4.5 | libc-bin 2.39-0ubuntu8.7 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-4046 | MEDIUM4.5 | libc6 2.39-0ubuntu8.7 No fix yet | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-54514 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.20.0 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-54515 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.20.0 fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-50020 | MEDIUM4.5 | io.netty:netty-codec-http 4.2.6.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-47244 | MEDIUM4.5 | io.netty:netty-codec-http2 4.2.6.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-50560 | MEDIUM4.5 | io.netty:netty-codec-http2 4.2.6.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libblkid1 2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libmount1 2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libsmartcols1 2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libuuid1 2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-69720 | LOW3.98 | ncurses-base 6.4+20240113-1ubuntu2 fixed in 6.4+20240113-1ubuntu2.1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-69720 | LOW3.98 | ncurses-bin 6.4+20240113-1ubuntu2 fixed in 6.4+20240113-1ubuntu2.1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-15146 | LOW3.54 | wget 1.21.4-1ubuntu4.1 No fix yet | — | Post-Exploit |
| CVE-2026-4438 | LOW3.4 | libc-bin 2.39-0ubuntu8.7 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-4438 | LOW3.4 | libc6 2.39-0ubuntu8.7 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-45536 | LOW3.4 | io.netty:netty-transport-native-epoll 4.2.6.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-8376 | LOW3 | perl-base 5.38.2-3.2ubuntu0.2 fixed in 5.38.2-3.2ubuntu0.3 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-45582 | LOW2.86 | tar 1.35+dfsg-3build1 fixed in 1.35+dfsg-3ubuntu0.2 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-5704 | LOW2.8 | tar 1.35+dfsg-3build1 fixed in 1.35+dfsg-3ubuntu0.3 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-40228 | LOW2.8 | libsystemd0 255.4-1ubuntu8.16 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-40228 | LOW2.8 | libudev1 255.4-1ubuntu8.16 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42496 | LOW2.78 | perl-base 5.38.2-3.2ubuntu0.2 fixed in 5.38.2-3.2ubuntu0.3 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-42584 | LOW2.78 | io.netty:netty-codec-http 4.2.6.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-58470 | LOW2.7 | wget 1.21.4-1ubuntu4.1 fixed in 1.21.4-1ubuntu4.3 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | bsdutils 1:2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-10536 | LOW2.4 | curl 8.5.0-2ubuntu10.10 fixed in 8.5.0-2ubuntu10.11 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2026-41991 | LOW2.4 | gzip 1.12-1ubuntu3.1 fixed in 1.12-1ubuntu3.2 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-10536 | LOW2.4 | libcurl4t64 8.5.0-2ubuntu10.10 fixed in 8.5.0-2ubuntu10.11 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | mount 2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | util-linux 2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-69720 | LOW2.39 | libncursesw6 6.4+20240113-1ubuntu2 fixed in 6.4+20240113-1ubuntu2.1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-69720 | LOW2.39 | libtinfo6 6.4+20240113-1ubuntu2 fixed in 6.4+20240113-1ubuntu2.1 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-41992 | LOW2.29 | gzip 1.12-1ubuntu3.1 fixed in 1.12-1ubuntu3.2 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2021-31879 | LOW2.2 | wget 1.21.4-1ubuntu4.1 No fix yet | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-58471 | LOW2.17 | wget 1.21.4-1ubuntu4.1 fixed in 1.21.4-1ubuntu4.3 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-58472 | LOW2.17 | wget 1.21.4-1ubuntu4.1 fixed in 1.21.4-1ubuntu4.3 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2024-56433 | LOW1.84 | login 1:4.13+dfsg1-4ubuntu3.2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2024-56433 | LOW1.84 | passwd 1:4.13+dfsg1-4ubuntu3.2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-4437 | NONE0 | locales 2.39-0ubuntu8.7 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-6238 | NONE0 | locales 2.39-0ubuntu8.7 No fix yet | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-5435 | NONE0 | locales 2.39-0ubuntu8.7 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-4046 | NONE0 | locales 2.39-0ubuntu8.7 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-4438 | NONE0 | locales 2.39-0ubuntu8.7 No fix yet | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-58055 | NONE0 | libnghttp2-14 1.59.0-1ubuntu0.3 fixed in 1.59.0-1ubuntu0.4 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-58469 | NONE0 | wget 1.21.4-1ubuntu4.1 fixed in 1.21.4-1ubuntu4.3 | 0.4% Theoretical Threat | Not Applicable |
| GHSA-72hv-8253-57qq | NONE0 | com.fasterxml.jackson.core:jackson-core 2.20.0 fixed in 2.21.1, 2.18.6 | — | Not Applicable |
| CVE-2026-42577 | NONE0 | io.netty:netty-transport-native-epoll 4.2.6.Final fixed in 4.2.13.Final | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-33558 | NONE0 | org.apache.kafka:kafka-clients 3.9.1 fixed in 3.9.2, 4.0.1 | 0.5% Theoretical Threat | Not Applicable |
Want to check another image? Run a full scan with the Docker Security Scanner.