Last scanned:
This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could achieve remote code execution by exploiting CVE-2025-48734 or the jackson-databind bypasses, potentially compromising the SonarQube server. CVE-2025-48734 only applies if user-controlled property paths reach BeanUtils, which is not evident in the provided context, and jackson-databind requires polymorphic typing to be enabled. Upgrading to fixed versions (commons-beanutils 1.11.0, jackson-databind 2.18.8 or later) would fully eliminate these specific vulnerabilities, but the large exposed surface still demands urgent remediation before any deployment.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2025-48734 | HIGH7.04 | commons-beanutils:commons-beanutils 1.9.4 fixed in 1.11.0 | 1.5% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2026-54512 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.16.1 fixed in 2.18.8, 3.1.4, 2.21.4 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-54513 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.16.1 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-54512 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.17.2 fixed in 2.18.8, 3.1.4, 2.21.4 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-54513 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.17.2 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-54512 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.17.3 fixed in 2.18.8, 3.1.4, 2.21.4 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-54513 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.17.3 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-54512 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.19.0 fixed in 2.18.8, 3.1.4, 2.21.4 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-54513 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.19.0 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-54512 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.19.1 fixed in 2.18.8, 3.1.4, 2.21.4 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-54513 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.19.1 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-54512 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.19.2 fixed in 2.18.8, 3.1.4, 2.21.4 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-54513 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.19.2 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-69720 | MEDIUM6.63 | libncursesw6 6.4+20240113-1ubuntu2 fixed in 6.4+20240113-1ubuntu2.1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69720 | MEDIUM6.63 | libtinfo6 6.4+20240113-1ubuntu2 fixed in 6.4+20240113-1ubuntu2.1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69720 | MEDIUM6.63 | ncurses-base 6.4+20240113-1ubuntu2 fixed in 6.4+20240113-1ubuntu2.1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69720 | MEDIUM6.63 | ncurses-bin 6.4+20240113-1ubuntu2 fixed in 6.4+20240113-1ubuntu2.1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-41989 | MEDIUM6.38 | libgcrypt20 1.10.3-2build1 fixed in 1.10.3-2ubuntu0.1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-40355 | MEDIUM6.38 | libgssapi-krb5-2 1.20.1-6ubuntu2.6 fixed in 1.20.1-6ubuntu2.7 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-40356 | MEDIUM6.38 | libgssapi-krb5-2 1.20.1-6ubuntu2.6 fixed in 1.20.1-6ubuntu2.7 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-40355 | MEDIUM6.38 | libk5crypto3 1.20.1-6ubuntu2.6 fixed in 1.20.1-6ubuntu2.7 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-40356 | MEDIUM6.38 | libk5crypto3 1.20.1-6ubuntu2.6 fixed in 1.20.1-6ubuntu2.7 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-40355 | MEDIUM6.38 | libkrb5-3 1.20.1-6ubuntu2.6 fixed in 1.20.1-6ubuntu2.7 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-40356 | MEDIUM6.38 | libkrb5-3 1.20.1-6ubuntu2.6 fixed in 1.20.1-6ubuntu2.7 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-40355 | MEDIUM6.38 | libkrb5support0 1.20.1-6ubuntu2.6 fixed in 1.20.1-6ubuntu2.7 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-40356 | MEDIUM6.38 | libkrb5support0 1.20.1-6ubuntu2.6 fixed in 1.20.1-6ubuntu2.7 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2023-6378 | MEDIUM6.38 | ch.qos.logback:logback-classic 1.2.9 fixed in 1.3.12, 1.4.12, 1.2.13 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2023-6378 | MEDIUM6.38 | ch.qos.logback:logback-core 1.2.9 fixed in 1.3.12, 1.4.12, 1.2.13 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2025-7962 | MEDIUM6.38 | com.sun.mail:jakarta.mail 1.6.3 fixed in 1.6.8, 2.0.2 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-7962 | MEDIUM6.38 | com.sun.mail:jakarta.mail 2.0.1 fixed in 1.6.8, 2.0.2 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-42583 | MEDIUM6.38 | io.netty:netty-codec 4.1.115.Final fixed in 4.1.133.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59901 | MEDIUM6.38 | io.netty:netty-codec 4.1.115.Final fixed in 4.1.136.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-58057 | MEDIUM6.38 | io.netty:netty-codec 4.1.115.Final fixed in 4.1.125.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-33870 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.115.Final fixed in 4.1.132.Final, 4.2.10.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42587 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.115.Final fixed in 4.2.13.Final, 4.1.133.Final | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-55831 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.115.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-55833 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.115.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-56745 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.115.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42585 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.115.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-56746 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.115.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59899 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.115.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-58056 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.115.Final fixed in 4.1.125.Final, 4.2.5.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42587 | MEDIUM6.38 | io.netty:netty-codec-http2 4.1.115.Final fixed in 4.2.13.Final, 4.1.133.Final | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-56819 | MEDIUM6.38 | io.netty:netty-codec-http2 4.1.115.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-48043 | MEDIUM6.38 | io.netty:netty-codec-http2 4.1.115.Final fixed in 4.1.135.Final, 4.2.15.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-45416 | MEDIUM6.38 | io.netty:netty-handler 4.1.115.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-50010 | MEDIUM6.38 | io.netty:netty-handler 4.1.115.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-57699 | MEDIUM6.38 | net.minidev:json-smart 2.5.1 fixed in 2.5.2 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-34479 | MEDIUM6.38 | org.apache.logging.log4j:log4j-1.2-api 2.19.0 fixed in 2.25.4 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-34480 | MEDIUM6.38 | org.apache.logging.log4j:log4j-core 2.12.4 fixed in 2.25.4 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-34480 | MEDIUM6.38 | org.apache.logging.log4j:log4j-core 2.19.0 fixed in 2.25.4 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-5588 | MEDIUM6.38 | org.bouncycastle:bcpkix-jdk18on 1.78.1 fixed in 1.84 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-14813 | MEDIUM6.38 | org.bouncycastle:bcprov-jdk18on 1.78.1 fixed in 1.80.2, 1.81.1, 1.84 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-66566 | MEDIUM6.38 | org.lz4:lz4-java 1.8.0 No fix yet | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42198 | MEDIUM6.38 | org.postgresql:postgresql 42.7.7 fixed in 42.7.11 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-3833 | MEDIUM6.29 | libgnutls30t64 3.8.3-1.1ubuntu3.5 fixed in 3.8.3-1.1ubuntu3.6 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42011 | MEDIUM6.29 | libgnutls30t64 3.8.3-1.1ubuntu3.5 fixed in 3.8.3-1.1ubuntu3.6 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-34182 | MEDIUM6.29 | libssl3t64 3.0.13-0ubuntu3.9 fixed in 3.0.13-0ubuntu3.11 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-37731 | MEDIUM6.29 | org.elasticsearch:elasticsearch 8.16.3 fixed in 8.19.8, 9.1.8, 9.2.2 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42012 | MEDIUM6.03 | libgnutls30t64 3.8.3-1.1ubuntu3.5 fixed in 3.8.3-1.1ubuntu3.6 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-45292 | MEDIUM6 | io.opentelemetry:opentelemetry-api 1.31.0 fixed in 1.62.0 | 1.1% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2026-4878 | MEDIUM5.95 | libcap2 1:2.66-5ubuntu2.2 fixed in 1:2.66-5ubuntu2.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-2236 | MEDIUM5.9 | libgcrypt20 1.10.3-2build1 No fix yet | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-45673 | MEDIUM5.78 | io.netty:netty-resolver-dns 4.1.115.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42014 | MEDIUM5.61 | libgnutls30t64 3.8.3-1.1ubuntu3.5 fixed in 3.8.3-1.1ubuntu3.6 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-4437 | MEDIUM5.52 | libc-bin 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-6238 | MEDIUM5.52 | libc-bin 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-4437 | MEDIUM5.52 | libc6 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-6238 | MEDIUM5.52 | libc6 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59888 | MEDIUM5.52 | com.fasterxml.jackson.core:jackson-databind 2.16.1 fixed in 2.18.8, 2.21.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-59888 | MEDIUM5.52 | com.fasterxml.jackson.core:jackson-databind 2.17.2 fixed in 2.18.8, 2.21.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-59888 | MEDIUM5.52 | com.fasterxml.jackson.core:jackson-databind 2.17.3 fixed in 2.18.8, 2.21.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-59888 | MEDIUM5.52 | com.fasterxml.jackson.core:jackson-databind 2.19.0 fixed in 2.18.8, 2.21.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-59888 | MEDIUM5.52 | com.fasterxml.jackson.core:jackson-databind 2.19.1 fixed in 2.18.8, 2.21.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-59888 | MEDIUM5.52 | com.fasterxml.jackson.core:jackson-databind 2.19.2 fixed in 2.18.8, 2.21.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-67735 | MEDIUM5.52 | io.netty:netty-codec-http 4.1.115.Final fixed in 4.2.8.Final, 4.1.129.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-41417 | MEDIUM5.52 | io.netty:netty-codec-http 4.1.115.Final fixed in 4.1.133.Final, 4.2.13.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42580 | MEDIUM5.52 | io.netty:netty-codec-http 4.1.115.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59900 | MEDIUM5.52 | io.netty:netty-codec-http2 4.1.115.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-0636 | MEDIUM5.52 | org.bouncycastle:bcprov-jdk18on 1.78.1 fixed in 1.84 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-68384 | MEDIUM5.52 | org.elasticsearch.plugin:x-pack-security 8.16.3 fixed in 8.19.9, 9.1.9, 9.2.3 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-12183 | MEDIUM5.52 | org.lz4:lz4-java 1.8.0 fixed in 1.8.1 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-59250 | MEDIUM5.5 | com.microsoft.sqlserver:mssql-jdbc 12.10.2 fixed in 10.2.4.jre11, 11.2.4.jre11, 12.2.1.jre11, 12.6.5.jre11, 12.8.2.jre11, 12.10.2.jre11, 13.2.1.jre11 | 0.7% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-40226 | MEDIUM5.44 | libsystemd0 255.4-1ubuntu8.15 fixed in 255.4-1ubuntu8.16 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-40226 | MEDIUM5.44 | libudev1 255.4-1ubuntu8.15 fixed in 255.4-1ubuntu8.16 | <0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-11226 | MEDIUM5.44 | ch.qos.logback:logback-core 1.2.9 fixed in 1.5.19, 1.3.16 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-13757 | MEDIUM5.27 | libp11-kit0 0.25.3-4ubuntu2.1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-13757 | MEDIUM5.27 | p11-kit 0.25.3-4ubuntu2.1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-13757 | MEDIUM5.27 | p11-kit-modules 0.25.3-4ubuntu2.1 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-5435 | MEDIUM5.02 | libc-bin 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-5435 | MEDIUM5.02 | libc6 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42770 | MEDIUM5.02 | libssl3t64 3.0.13-0ubuntu3.9 fixed in 3.0.13-0ubuntu3.11 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-9076 | MEDIUM5.02 | libssl3t64 3.0.13-0ubuntu3.9 fixed in 3.0.13-0ubuntu3.11 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-34477 | MEDIUM5.02 | org.apache.logging.log4j:log4j-core 2.12.4 fixed in 2.25.4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-34477 | MEDIUM5.02 | org.apache.logging.log4j:log4j-core 2.19.0 fixed in 2.25.4 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-54291 | MEDIUM5.02 | org.postgresql:postgresql 42.7.7 fixed in 42.7.12 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-34180 | MEDIUM5 | libssl3t64 3.0.13-0ubuntu3.9 fixed in 3.0.13-0ubuntu3.11 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2025-53864 | MEDIUM4.93 | com.nimbusds:nimbus-jose-jwt 9.37.3 fixed in 10.0.2, 9.37.4 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-59921 | MEDIUM4.84 | io.netty:netty-codec-http 4.1.115.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-37727 | MEDIUM4.84 | org.elasticsearch:elasticsearch 8.16.3 fixed in 8.18.8, 8.19.5, 9.0.8, 9.1.5 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-66382 | MEDIUM4.67 | libexpat1 2.6.1-2ubuntu0.4 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-7383 | MEDIUM4.67 | libssl3t64 3.0.13-0ubuntu3.9 fixed in 3.0.13-0ubuntu3.11 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-27171 | MEDIUM4.67 | zlib1g 1:1.3.dfsg-3.1ubuntu2.1 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-12798 | MEDIUM4.67 | ch.qos.logback:logback-core 1.2.9 fixed in 1.5.13, 1.3.15 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-25193 | MEDIUM4.67 | io.netty:netty-common 4.1.115.Final fixed in 4.1.118.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-58055 | MEDIUM4.59 | libnghttp2-14 1.59.0-1ubuntu0.3 fixed in 1.59.0-1ubuntu0.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-4046 | MEDIUM4.5 | libc-bin 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-4046 | MEDIUM4.5 | libc6 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42015 | MEDIUM4.5 | libgnutls30t64 3.8.3-1.1ubuntu3.5 fixed in 3.8.3-1.1ubuntu3.6 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-34743 | MEDIUM4.5 | liblzma5 5.6.1+really5.4.5-1ubuntu0.2 fixed in 5.6.1+really5.4.5-1ubuntu0.3 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42766 | MEDIUM4.5 | libssl3t64 3.0.13-0ubuntu3.9 fixed in 3.0.13-0ubuntu3.11 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-42767 | MEDIUM4.5 | libssl3t64 3.0.13-0ubuntu3.9 fixed in 3.0.13-0ubuntu3.11 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-54514 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.16.1 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-54515 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.16.1 fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-54514 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.17.2 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-54515 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.17.2 fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-54514 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.17.3 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-54515 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.17.3 fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-54514 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.19.0 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-54515 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.19.0 fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-54514 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.19.1 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-54515 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.19.1 fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-54514 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.19.2 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-54515 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.19.2 fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-50020 | MEDIUM4.5 | io.netty:netty-codec-http 4.1.115.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-59898 | MEDIUM4.5 | io.netty:netty-codec-http 4.1.115.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-47244 | MEDIUM4.5 | io.netty:netty-codec-http2 4.1.115.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-50560 | MEDIUM4.5 | io.netty:netty-codec-http2 4.1.115.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-8885 | MEDIUM4.5 | org.bouncycastle:bc-fips 1.0.2.5 fixed in 1.0.2.6, 2.0.1 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-8916 | MEDIUM4.5 | org.bouncycastle:bcpkix-jdk18on 1.78.1 fixed in 1.79 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | libc-bin 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | libc-bin 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-5450 | MEDIUM4.25 | libc6 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-5928 | MEDIUM4.25 | libc6 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-11850 | MEDIUM4.25 | libgssapi-krb5-2 1.20.1-6ubuntu2.6 fixed in 1.20.1-6ubuntu2.7 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-11850 | MEDIUM4.25 | libk5crypto3 1.20.1-6ubuntu2.6 fixed in 1.20.1-6ubuntu2.7 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-11850 | MEDIUM4.25 | libkrb5-3 1.20.1-6ubuntu2.6 fixed in 1.20.1-6ubuntu2.7 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-11850 | MEDIUM4.25 | libkrb5support0 1.20.1-6ubuntu2.6 fixed in 1.20.1-6ubuntu2.7 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-1225 | MEDIUM4.25 | ch.qos.logback:logback-core 1.2.9 fixed in 1.5.25 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-68390 | MEDIUM4.17 | org.elasticsearch.plugin:x-pack-core 8.16.3 fixed in 8.19.8, 9.1.8, 9.2.2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-54411 | MEDIUM4.08 | libpam-modules 1.5.3-5ubuntu5.5 fixed in 1.5.3-5ubuntu5.6 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-54411 | MEDIUM4.08 | libpam-modules-bin 1.5.3-5ubuntu5.5 fixed in 1.5.3-5ubuntu5.6 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-54411 | MEDIUM4.08 | libpam-runtime 1.5.3-5ubuntu5.5 fixed in 1.5.3-5ubuntu5.6 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-54411 | MEDIUM4.08 | libpam0g 1.5.3-5ubuntu5.5 fixed in 1.5.3-5ubuntu5.6 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-68161 | MEDIUM4.08 | org.apache.logging.log4j:log4j-core 2.12.4 fixed in 2.25.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-68161 | MEDIUM4.08 | org.apache.logging.log4j:log4j-core 2.19.0 fixed in 2.25.3 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libblkid1 2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libmount1 2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libsmartcols1 2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-27456 | MEDIUM4 | libuuid1 2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-8927 | LOW3.82 | libcurl4t64 8.5.0-2ubuntu10.9 fixed in 8.5.0-2ubuntu10.10 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-9547 | LOW3.77 | curl 8.5.0-2ubuntu10.9 fixed in 8.5.0-2ubuntu10.10 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-9547 | LOW3.77 | libcurl4t64 8.5.0-2ubuntu10.9 fixed in 8.5.0-2ubuntu10.10 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-34182 | LOW3.77 | openssl 3.0.13-0ubuntu3.9 fixed in 3.0.13-0ubuntu3.11 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-48924 | LOW3.7 | org.apache.commons:commons-lang3 3.14.0 fixed in 3.18.0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-48924 | LOW3.7 | org.apache.commons:commons-lang3 3.16.0 fixed in 3.18.0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-48924 | LOW3.7 | org.apache.commons:commons-lang3 3.17.0 fixed in 3.18.0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2021-31879 | LOW3.66 | wget 1.21.4-1ubuntu4.1 No fix yet | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-58471 | LOW3.62 | wget 1.21.4-1ubuntu4.1 fixed in 1.21.4-1ubuntu4.3 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-58472 | LOW3.62 | wget 1.21.4-1ubuntu4.1 fixed in 1.21.4-1ubuntu4.3 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-42010 | LOW3.53 | libgnutls30t64 3.8.3-1.1ubuntu3.5 fixed in 3.8.3-1.1ubuntu3.6 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-4438 | LOW3.4 | libc-bin 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-4438 | LOW3.4 | libc6 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-8924 | LOW3.31 | curl 8.5.0-2ubuntu10.9 fixed in 8.5.0-2ubuntu10.10 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-8924 | LOW3.31 | libcurl4t64 8.5.0-2ubuntu10.9 fixed in 8.5.0-2ubuntu10.10 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-58469 | LOW3.31 | wget 1.21.4-1ubuntu4.1 fixed in 1.21.4-1ubuntu4.3 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-3832 | LOW3.15 | libgnutls30t64 3.8.3-1.1ubuntu3.5 fixed in 3.8.3-1.1ubuntu3.6 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-5419 | LOW3.15 | libgnutls30t64 3.8.3-1.1ubuntu3.5 fixed in 3.8.3-1.1ubuntu3.6 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-45446 | LOW3.15 | libssl3t64 3.0.13-0ubuntu3.9 fixed in 3.0.13-0ubuntu3.11 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-45674 | LOW3.06 | io.netty:netty-resolver-dns 4.1.115.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-47691 | LOW3.06 | io.netty:netty-resolver-dns 4.1.115.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-42770 | LOW3.01 | openssl 3.0.13-0ubuntu3.9 fixed in 3.0.13-0ubuntu3.11 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-9076 | LOW3.01 | openssl 3.0.13-0ubuntu3.9 fixed in 3.0.13-0ubuntu3.11 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-15146 | LOW3.01 | wget 1.21.4-1ubuntu4.1 fixed in 1.21.4-1ubuntu4.4 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-8376 | LOW3 | perl-base 5.38.2-3.2ubuntu0.2 fixed in 5.38.2-3.2ubuntu0.3 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-42581 | LOW3 | io.netty:netty-codec-http 4.1.115.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-34180 | LOW3 | openssl 3.0.13-0ubuntu3.9 fixed in 3.0.13-0ubuntu3.11 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-45447 | LOW2.92 | libssl3t64 3.0.13-0ubuntu3.9 fixed in 3.0.13-0ubuntu3.11 | 5.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-45447 | LOW2.92 | openssl 3.0.13-0ubuntu3.9 fixed in 3.0.13-0ubuntu3.11 | 5.2% Low-Moderate Risk | Post-Exploit |
| CVE-2025-45582 | LOW2.86 | tar 1.35+dfsg-3build1 fixed in 1.35+dfsg-3ubuntu0.2 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-7383 | LOW2.8 | openssl 3.0.13-0ubuntu3.9 fixed in 3.0.13-0ubuntu3.11 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-5704 | LOW2.8 | tar 1.35+dfsg-3build1 fixed in 1.35+dfsg-3ubuntu0.4 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-40228 | LOW2.8 | libsystemd0 255.4-1ubuntu8.15 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-40228 | LOW2.8 | libudev1 255.4-1ubuntu8.15 No fix yet | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-12801 | LOW2.8 | ch.qos.logback:logback-core 1.2.9 fixed in 1.5.13, 1.3.15 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-33845 | LOW2.78 | libgnutls30t64 3.8.3-1.1ubuntu3.5 fixed in 3.8.3-1.1ubuntu3.6 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-45445 | LOW2.78 | libssl3t64 3.0.13-0ubuntu3.9 fixed in 3.0.13-0ubuntu3.11 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-45445 | LOW2.78 | openssl 3.0.13-0ubuntu3.9 fixed in 3.0.13-0ubuntu3.11 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-42496 | LOW2.78 | perl-base 5.38.2-3.2ubuntu0.2 fixed in 5.38.2-3.2ubuntu0.3 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-42579 | LOW2.78 | io.netty:netty-codec-dns 4.1.115.Final fixed in 4.2.13.Final, 4.1.133.Final | 1.0% Theoretical Threat | Post-Exploit |
| CVE-2026-42584 | LOW2.78 | io.netty:netty-codec-http 4.1.115.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-33846 | LOW2.7 | libgnutls30t64 3.8.3-1.1ubuntu3.5 fixed in 3.8.3-1.1ubuntu3.6 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2026-42009 | LOW2.7 | libgnutls30t64 3.8.3-1.1ubuntu3.5 fixed in 3.8.3-1.1ubuntu3.6 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2025-55163 | LOW2.7 | io.netty:netty-codec-http2 4.1.115.Final fixed in 4.2.4.Final, 4.1.124.Final | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-33871 | LOW2.7 | io.netty:netty-codec-http2 4.1.115.Final fixed in 4.1.132.Final, 4.2.11.Final | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2025-24970 | LOW2.7 | io.netty:netty-handler 4.1.115.Final fixed in 4.1.118.Final | 2.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-42766 | LOW2.7 | openssl 3.0.13-0ubuntu3.9 fixed in 3.0.13-0ubuntu3.11 | 1.0% Theoretical Threat | Post-Exploit |
| CVE-2026-42767 | LOW2.7 | openssl 3.0.13-0ubuntu3.9 fixed in 3.0.13-0ubuntu3.11 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-58470 | LOW2.7 | wget 1.21.4-1ubuntu4.1 fixed in 1.21.4-1ubuntu4.3 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-42013 | LOW2.51 | libgnutls30t64 3.8.3-1.1ubuntu3.5 fixed in 3.8.3-1.1ubuntu3.6 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-5260 | LOW2.51 | libgnutls30t64 3.8.3-1.1ubuntu3.5 fixed in 3.8.3-1.1ubuntu3.6 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-8925 | LOW2.48 | curl 8.5.0-2ubuntu10.9 fixed in 8.5.0-2ubuntu10.10 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-8286 | LOW2.48 | curl 8.5.0-2ubuntu10.9 fixed in 8.5.0-2ubuntu10.10 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-8925 | LOW2.48 | libcurl4t64 8.5.0-2ubuntu10.9 fixed in 8.5.0-2ubuntu10.10 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-8286 | LOW2.48 | libcurl4t64 8.5.0-2ubuntu10.9 fixed in 8.5.0-2ubuntu10.10 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-44249 | LOW2.48 | io.netty:netty-handler 4.1.115.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | bsdutils 1:2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-10536 | LOW2.4 | curl 8.5.0-2ubuntu10.9 fixed in 8.5.0-2ubuntu10.11 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-41991 | LOW2.4 | gzip 1.12-1ubuntu3.1 fixed in 1.12-1ubuntu3.2 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-10536 | LOW2.4 | libcurl4t64 8.5.0-2ubuntu10.9 fixed in 8.5.0-2ubuntu10.11 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | mount 2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-27456 | LOW2.4 | util-linux 2.39.3-9ubuntu6.5 No fix yet | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-8927 | LOW2.29 | curl 8.5.0-2ubuntu10.9 fixed in 8.5.0-2ubuntu10.10 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-41992 | LOW2.29 | gzip 1.12-1ubuntu3.1 fixed in 1.12-1ubuntu3.2 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-45446 | LOW1.89 | openssl 3.0.13-0ubuntu3.9 fixed in 3.0.13-0ubuntu3.11 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2024-56433 | LOW1.84 | passwd 1:4.13+dfsg1-4ubuntu3.2 No fix yet | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-4437 | NONE0 | locales 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-6238 | NONE0 | locales 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-5958 | NONE0 | sed 4.9-2build1 fixed in 4.9-2ubuntu0.24.04.1 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-5435 | NONE0 | locales 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-4046 | NONE0 | locales 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-5450 | NONE0 | locales 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-5928 | NONE0 | locales 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-4438 | NONE0 | locales 2.39-0ubuntu8.7 fixed in 2.39-0ubuntu8.8 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-48924 | NONE0 | commons-lang:commons-lang 2.6 No fix yet | 2.2% Low-Moderate Risk | Not Applicable |
| CVE-2024-56433 | NONE0 | login 1:4.13+dfsg1-4ubuntu3.2 No fix yet | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-8458 | NONE0 | curl 8.5.0-2ubuntu10.9 fixed in 8.5.0-2ubuntu10.10 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-2219 | NONE0 | dpkg 1.22.6ubuntu6.5 fixed in 1.22.6ubuntu6.6 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-8458 | NONE0 | libcurl4t64 8.5.0-2ubuntu10.9 fixed in 8.5.0-2ubuntu10.10 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-11822 | NONE0 | libsqlite3-0 3.45.1-1ubuntu2.5 fixed in 3.45.1-1ubuntu2.6 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-11824 | NONE0 | libsqlite3-0 3.45.1-1ubuntu2.5 fixed in 3.45.1-1ubuntu2.6 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-50812 | NONE0 | libsqlite3-0 3.45.1-1ubuntu2.5 fixed in 3.45.1-1ubuntu2.7 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-50813 | NONE0 | libsqlite3-0 3.45.1-1ubuntu2.5 fixed in 3.45.1-1ubuntu2.7 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-10532 | NONE0 | ch.qos.logback:logback-core 1.2.9 fixed in 1.5.34 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-9828 | NONE0 | ch.qos.logback:logback-core 1.2.9 fixed in 1.5.33 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-10532 | NONE0 | ch.qos.logback:logback-core 1.5.25 fixed in 1.5.34 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-9828 | NONE0 | ch.qos.logback:logback-core 1.5.25 fixed in 1.5.33 | 0.4% Theoretical Threat | Not Applicable |
| GHSA-r7wm-3cxj-wff9 | NONE0 | com.fasterxml.jackson.core:jackson-core 2.15.0 fixed in 2.18.8, 2.21.4, 2.22.1 | — | Not Applicable |
| GHSA-72hv-8253-57qq | NONE0 | com.fasterxml.jackson.core:jackson-core 2.15.0 fixed in 2.21.1, 2.18.6 | — | Not Applicable |
| GHSA-r7wm-3cxj-wff9 | NONE0 | com.fasterxml.jackson.core:jackson-core 2.16.1 fixed in 2.18.8, 2.21.4, 2.22.1 | — | Not Applicable |
| GHSA-72hv-8253-57qq | NONE0 | com.fasterxml.jackson.core:jackson-core 2.16.1 fixed in 2.21.1, 2.18.6 | — | Not Applicable |
| GHSA-r7wm-3cxj-wff9 | NONE0 | com.fasterxml.jackson.core:jackson-core 2.17.2 fixed in 2.18.8, 2.21.4, 2.22.1 | — | Not Applicable |
| GHSA-72hv-8253-57qq | NONE0 | com.fasterxml.jackson.core:jackson-core 2.17.2 fixed in 2.21.1, 2.18.6 | — | Not Applicable |
| GHSA-r7wm-3cxj-wff9 | NONE0 | com.fasterxml.jackson.core:jackson-core 2.17.3 fixed in 2.18.8, 2.21.4, 2.22.1 | — | Not Applicable |
| GHSA-72hv-8253-57qq | NONE0 | com.fasterxml.jackson.core:jackson-core 2.17.3 fixed in 2.21.1, 2.18.6 | — | Not Applicable |
| GHSA-r7wm-3cxj-wff9 | NONE0 | com.fasterxml.jackson.core:jackson-core 2.19.0 fixed in 2.18.8, 2.21.4, 2.22.1 | — | Not Applicable |
| GHSA-72hv-8253-57qq | NONE0 | com.fasterxml.jackson.core:jackson-core 2.19.0 fixed in 2.21.1, 2.18.6 | — | Not Applicable |
| GHSA-r7wm-3cxj-wff9 | NONE0 | com.fasterxml.jackson.core:jackson-core 2.19.1 fixed in 2.18.8, 2.21.4, 2.22.1 | — | Not Applicable |
| GHSA-72hv-8253-57qq | NONE0 | com.fasterxml.jackson.core:jackson-core 2.19.1 fixed in 2.21.1, 2.18.6 | — | Not Applicable |
| GHSA-r7wm-3cxj-wff9 | NONE0 | com.fasterxml.jackson.core:jackson-core 2.19.2 fixed in 2.18.8, 2.21.4, 2.22.1 | — | Not Applicable |
| GHSA-72hv-8253-57qq | NONE0 | com.fasterxml.jackson.core:jackson-core 2.19.2 fixed in 2.21.1, 2.18.6 | — | Not Applicable |
| GHSA-mfg7-5gfp-c4w3 | NONE0 | io.netty:netty-codec-dns 4.1.115.Final fixed in 4.2.16.Final, 4.1.136.Final | — | Not Applicable |
| CVE-2026-59949 | NONE0 | org.lz4:lz4-java 1.8.0 No fix yet | — | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.