Vulnerability Reportsolr:latest

solr:latestsolr:10.0.0solr:10.0solr:10
DIGESTsha256:79b08a5fabda917e6d840c384485a7c5d0dcfe3a0ebcb5bf65c30278c3b53ade

Executive Summary

DANGEROUS

This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could achieve remote code execution, bypass authentication, smuggle requests to bypass security controls, or cause a denial of service. Notably, critical vulnerabilities like `CVE-2026-42581` (request smuggling) and `CVE-2025-48734` (potential remote code execution) are present in highly relevant components. The authentication bypass vulnerability (`CVE-2026-42010`) specifically applies if GnuTLS is configured with RSA-PSK authentication, and `CVE-2025-48734` is exploitable if untrusted input is processed by vulnerable `commons-beanutils` methods. The combination of numerous high-severity flaws and severe potential consequences necessitates immediate remediation and avoiding production use.

Threat Score
100/100
DANGEROUS
Reputation
TRUSTED
Docker Official
BaseImage/
solr:latest
Hardened
Grade
A+
Vulns
0
Verified & secured for production

Vulnerabilities

Vulnerability Log

86 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-42581CRITICAL9.8
io.netty:netty-codec-http
4.2.6.Final
fixed in 4.2.13.Final, 4.1.133.Final
Directly ExposedContext importance: HIGH
CVE-2026-42013HIGH8.2
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
Directly ExposedContext importance: HIGH
CVE-2026-42010HIGH7.84
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
Directly ExposedContext importance: MEDIUM
CVE-2026-2332HIGH7.73
org.eclipse.jetty:jetty-http
12.0.27
fixed in 12.1.7, 12.0.33
<0.1%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-42587HIGH7.5
io.netty:netty-codec-http
4.2.6.Final
fixed in 4.2.13.Final, 4.1.133.Final
Directly ExposedContext importance: HIGH
CVE-2026-42585HIGH7.5
io.netty:netty-codec-http
4.2.6.Final
fixed in 4.2.13.Final, 4.1.133.Final
Directly ExposedContext importance: HIGH
CVE-2025-48734HIGH7.48
commons-beanutils:commons-beanutils
1.9.4
fixed in 1.11.0
0.3%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-42011HIGH7.4
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
Directly ExposedContext importance: HIGH
CVE-2026-42584HIGH7.28
io.netty:netty-codec-http
4.2.6.Final
fixed in 4.2.13.Final, 4.1.133.Final
Directly ExposedContext importance: MEDIUM
CVE-2026-42012HIGH7.1
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
Directly Exposed
CVE-2026-41417MEDIUM6.5
io.netty:netty-codec-http
4.2.6.Final
fixed in 4.1.133.Final, 4.2.13.Final
Directly Exposed
CVE-2026-42580MEDIUM6.5
io.netty:netty-codec-http
4.2.6.Final
fixed in 4.2.13.Final, 4.1.133.Final
Directly Exposed
CVE-2026-41989MEDIUM6.38
libgcrypt20
1.10.3-2build1
fixed in 1.10.3-2ubuntu0.1
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-33846MEDIUM6.38
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-55163MEDIUM6.38
io.grpc:grpc-netty-shaded
1.65.1
fixed in 1.75.0
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-33870MEDIUM6.38
io.netty:netty-codec-http
4.2.6.Final
fixed in 4.1.132.Final, 4.2.10.Final
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-33871MEDIUM6.38
io.netty:netty-codec-http2
4.2.6.Final
fixed in 4.1.132.Final, 4.2.11.Final
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-34479MEDIUM6.38
org.apache.logging.log4j:log4j-1.2-api
2.25.3
fixed in 2.25.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-34478MEDIUM6.38
org.apache.logging.log4j:log4j-core
2.25.3
fixed in 2.25.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-34480MEDIUM6.38
org.apache.logging.log4j:log4j-core
2.25.3
fixed in 2.25.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-34481MEDIUM6.38
org.apache.logging.log4j:log4j-layout-template-json
2.25.3
fixed in 2.25.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-40682MEDIUM6.38
org.apache.opennlp:opennlp-tools
2.5.6
fixed in 2.5.9, 3.0.0-M3
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42027MEDIUM6.38
org.apache.opennlp:opennlp-tools
2.5.6
fixed in 2.5.9, 3.0.0-M3
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42440MEDIUM6.38
org.apache.opennlp:opennlp-tools
2.5.6
fixed in 2.5.9, 3.0.0-M3
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-24308MEDIUM6.38
org.apache.zookeeper:zookeeper
3.9.4
fixed in 3.9.5, 3.8.6
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-1605MEDIUM6.38
org.eclipse.jetty:jetty-server
12.0.27
fixed in 12.1.6, 12.0.32
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-66566MEDIUM6.38
org.lz4:lz4-java
1.8.0
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3833MEDIUM6.29
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-24281MEDIUM6.29
org.apache.zookeeper:zookeeper
3.9.4
fixed in 3.8.6, 3.9.5
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42587MEDIUM6
io.netty:netty-codec-http2
4.2.6.Final
fixed in 4.2.13.Final, 4.1.133.Final
Directly ExposedContext importance: MEDIUM
CVE-2026-42578MEDIUM6
io.netty:netty-handler-proxy
4.2.6.Final
fixed in 4.1.133.Final, 4.2.13.Final
Directly ExposedContext importance: MEDIUM
CVE-2026-45292MEDIUM6
io.opentelemetry:opentelemetry-api
1.56.0
fixed in 1.62.0
Directly ExposedContext importance: MEDIUM
CVE-2026-35554MEDIUM5.78
org.apache.kafka:kafka-clients
3.9.1
fixed in 3.9.2, 4.0.2, 4.1.2
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
libc-bin
2.39-0ubuntu8.7
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
libc-bin
2.39-0ubuntu8.7
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4437MEDIUM5.52
libc6
2.39-0ubuntu8.7
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
libc6
2.39-0ubuntu8.7
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-67735MEDIUM5.52
io.netty:netty-codec-http
4.2.6.Final
fixed in 4.2.8.Final, 4.1.129.Final
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-11143MEDIUM5.52
org.eclipse.jetty:jetty-http
12.0.27
fixed in 12.0.31, 12.1.5
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-12183MEDIUM5.52
org.lz4:lz4-java
1.8.0
fixed in 1.8.1
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-40226MEDIUM5.44
libsystemd0
255.4-1ubuntu8.15
fixed in 255.4-1ubuntu8.16
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-40226MEDIUM5.44
libudev1
255.4-1ubuntu8.15
fixed in 255.4-1ubuntu8.16
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42015MEDIUM5.3
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
Directly Exposed
CVE-2026-5435MEDIUM5.02
libc-bin
2.39-0ubuntu8.7
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
libc6
2.39-0ubuntu8.7
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2024-2236MEDIUM5.02
libgcrypt20
1.10.3-2build1
No fix yet
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-34477MEDIUM5.02
org.apache.logging.log4j:log4j-core
2.25.3
fixed in 2.25.4
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5260MEDIUM4.92
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
Directly Exposed
CVE-2025-66382MEDIUM4.67
libexpat1
2.6.1-2ubuntu0.4
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-33845MEDIUM4.64
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-42009MEDIUM4.5
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
Directly Exposed
CVE-2026-4046MEDIUM4.5
libc-bin
2.39-0ubuntu8.7
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4046MEDIUM4.5
libc6
2.39-0ubuntu8.7
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-34743MEDIUM4.5
liblzma5
5.6.1+really5.4.5-1ubuntu0.2
fixed in 5.6.1+really5.4.5-1ubuntu0.3
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libblkid1
2.39.3-9ubuntu6.5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libmount1
2.39.3-9ubuntu6.5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libsmartcols1
2.39.3-9ubuntu6.5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456MEDIUM4
libuuid1
2.39.3-9ubuntu6.5
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-5419LOW3.7
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
Directly Exposed
CVE-2026-4438LOW3.4
libc-bin
2.39-0ubuntu8.7
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-4438LOW3.4
libc6
2.39-0ubuntu8.7
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3832LOW3.15
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
<0.1%
Theoretical Threat
Directly Exposed
CVE-2025-45582LOW2.86
tar
1.35+dfsg-3build1
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-5704LOW2.8
tar
1.35+dfsg-3build1
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-40228LOW2.8
libsystemd0
255.4-1ubuntu8.15
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-40228LOW2.8
libudev1
255.4-1ubuntu8.15
No fix yet
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-27456LOW2.4
bsdutils
1:2.39.3-9ubuntu6.5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
mount
2.39.3-9ubuntu6.5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2026-27456LOW2.4
util-linux
2.39.3-9ubuntu6.5
No fix yet
<0.1%
Theoretical Threat
Post-Exploit
CVE-2024-56433LOW2.16
login
1:4.13+dfsg1-4ubuntu3.2
No fix yet
4.5%
Low-Moderate Risk
Post-Exploit
CVE-2024-56433LOW2.16
passwd
1:4.13+dfsg1-4ubuntu3.2
No fix yet
4.5%
Low-Moderate Risk
Post-Exploit
CVE-2021-31879LOW1.87
wget
1.21.4-1ubuntu4.1
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-4437NONE0
locales
2.39-0ubuntu8.7
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-6238NONE0
locales
2.39-0ubuntu8.7
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-5435NONE0
locales
2.39-0ubuntu8.7
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-4046NONE0
locales
2.39-0ubuntu8.7
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-4438NONE0
locales
2.39-0ubuntu8.7
No fix yet
<0.1%
Theoretical Threat
Not Applicable
CVE-2026-42014NONE0
libgnutls30t64
3.8.3-1.1ubuntu3.5
fixed in 3.8.3-1.1ubuntu3.6
Not Applicable
GHSA-72hv-8253-57qqNONE0
com.fasterxml.jackson.core:jackson-core
2.20.0
fixed in 2.21.1, 2.18.6
Not Applicable
CVE-2026-42583NONE0
io.netty:netty-codec-compression
4.2.6.Final
fixed in 4.2.13.Final
Not Applicable
CVE-2026-47244NONE0
io.netty:netty-codec-http2
4.2.6.Final
fixed in 4.2.15.Final, 4.1.135.Final
Not Applicable
CVE-2026-44249NONE0
io.netty:netty-handler
4.2.6.Final
fixed in 4.2.15.Final, 4.1.135.Final
Not Applicable
CVE-2026-45416NONE0
io.netty:netty-handler
4.2.6.Final
fixed in 4.2.15.Final, 4.1.135.Final
Not Applicable
CVE-2026-42577NONE0
io.netty:netty-transport-native-epoll
4.2.6.Final
fixed in 4.2.13.Final
Not Applicable
CVE-2026-45536NONE0
io.netty:netty-transport-native-epoll
4.2.6.Final
fixed in 4.2.15.Final, 4.1.135.Final
Not Applicable
CVE-2026-33558NONE0
org.apache.kafka:kafka-clients
3.9.1
fixed in 3.9.2, 4.0.1
0.1%
Theoretical Threat
Not Applicable