Last scanned:
This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could trigger XML External Entity injection via a crafted PDF upload, conduct HTTP request smuggling to reach administrative APIs, or cause denial of service via DNS/OpenSSL flaws. The top exposed-surface vulnerabilities require no special configuration and are directly reachable by network clients. Despite being published by a verified vendor, the image's attack surface is far too broad for production use without immediate remediation or replacement.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2025-66516 | CRITICAL10 | org.apache.tika:tika-core 1.28.4 fixed in 3.2.2 | 78.8% Actively Exploited | Directly ExposedContext importance: HIGH |
| CVE-2026-2332 | CRITICAL9.1 | org.eclipse.jetty:jetty-http 9.4.56.v20240826 fixed in 12.1.7, 12.0.33 | 1.1% Low-Moderate Risk | Directly ExposedContext importance: HIGH |
| CVE-2026-33630 | HIGH7.5 | c-ares 1.34.3-r0 fixed in 1.34.8-r0 | — | Directly Exposed |
| CVE-2026-28390 | HIGH7.5 | libcrypto3 3.3.2-r4 fixed in 3.3.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-33416 | HIGH7.5 | libpng 1.6.44-r0 fixed in 1.6.56-r0 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28390 | HIGH7.5 | libssl3 3.3.2-r4 fixed in 3.3.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2025-67030 | HIGH7.48 | org.codehaus.plexus:plexus-utils 3.0.24 fixed in 4.0.3, 3.6.1 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-67030 | HIGH7.48 | org.codehaus.plexus:plexus-utils 3.5.1 fixed in 4.0.3, 3.6.1 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2024-12797 | HIGH7.4 | libcrypto3 3.3.2-r4 fixed in 3.3.3-r0 | 2.4% Low-Moderate Risk | Directly Exposed |
| CVE-2024-12797 | HIGH7.4 | libssl3 3.3.2-r4 fixed in 3.3.3-r0 | 2.4% Low-Moderate Risk | Directly Exposed |
| CVE-2025-50059 | HIGH7.31 | openjdk17 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-50059 | HIGH7.31 | openjdk17-jdk 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-50059 | HIGH7.31 | openjdk17-jre 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-50059 | HIGH7.31 | openjdk17-jre-headless 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-48734 | HIGH7.04 | commons-beanutils:commons-beanutils 1.9.4 fixed in 1.11.0 | 1.5% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2025-48976 | MEDIUM6.89 | commons-fileupload:commons-fileupload 1.5 fixed in 1.6.0 | 67.3% Actively Exploited | Directly Exposed |
| CVE-2026-28387 | MEDIUM6.88 | libcrypto3 3.3.2-r4 fixed in 3.3.7-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-25646 | MEDIUM6.88 | libpng 1.6.44-r0 fixed in 1.6.55-r0 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-28387 | MEDIUM6.88 | libssl3 3.3.2-r4 fixed in 3.3.7-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-50106 | MEDIUM6.88 | openjdk17 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-50106 | MEDIUM6.88 | openjdk17-jdk 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-50106 | MEDIUM6.88 | openjdk17-jre 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-50106 | MEDIUM6.88 | openjdk17-jre-headless 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-54512 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.17.0 fixed in 2.18.8, 3.1.4, 2.21.4 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-54513 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.17.0 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-22801 | MEDIUM6.63 | libpng 1.6.44-r0 fixed in 1.6.54-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-40200 | MEDIUM6.63 | musl 1.2.5-r8 fixed in 1.2.5-r11 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-22184 | MEDIUM6.63 | zlib 1.3.1-r2 fixed in 1.3.2-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-23083 | MEDIUM6.54 | openjdk17 17.0.13_p11-r0 fixed in 17.0.15_p6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-23083 | MEDIUM6.54 | openjdk17-jdk 17.0.13_p11-r0 fixed in 17.0.15_p6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-23083 | MEDIUM6.54 | openjdk17-jre 17.0.13_p11-r0 fixed in 17.0.15_p6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-23083 | MEDIUM6.54 | openjdk17-jre-headless 17.0.13_p11-r0 fixed in 17.0.15_p6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2020-7019 | MEDIUM6.5 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.9.0, 6.8.12 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2021-22144 | MEDIUM6.5 | org.elasticsearch:elasticsearch 2.4.3 fixed in 6.8.17, 7.13.3 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-33636 | MEDIUM6.46 | libpng 1.6.44-r0 fixed in 1.6.56-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-41254 | MEDIUM6.38 | lcms2 2.16-r0 fixed in 2.19-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69421 | MEDIUM6.38 | libcrypto3 3.3.2-r4 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-69421 | MEDIUM6.38 | libssl3 3.3.2-r4 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-27135 | MEDIUM6.38 | nghttp2-libs 1.64.0-r0 fixed in 1.68.1 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-21945 | MEDIUM6.38 | openjdk17 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-21945 | MEDIUM6.38 | openjdk17-jdk 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-21945 | MEDIUM6.38 | openjdk17-jre 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-21945 | MEDIUM6.38 | openjdk17-jre-headless 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2025-7962 | MEDIUM6.38 | com.sun.mail:jakarta.mail 1.6.5 fixed in 1.6.8, 2.0.2 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-3505 | MEDIUM6.38 | org.bouncycastle:bcpg-jdk15to18 1.78.1 fixed in 1.84 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-5588 | MEDIUM6.38 | org.bouncycastle:bcpkix-jdk15to18 1.78.1 fixed in 1.84 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-14813 | MEDIUM6.38 | org.bouncycastle:bcprov-jdk15to18 1.78.1 fixed in 1.84 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-5598 | MEDIUM6.38 | org.bouncycastle:bcprov-jdk15to18 1.78.1 fixed in 1.80.2 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2024-38374 | MEDIUM6.38 | org.cyclonedx:cyclonedx-core-java 7.3.2 fixed in 9.0.4 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-64518 | MEDIUM6.38 | org.cyclonedx:cyclonedx-core-java 7.3.2 fixed in 11.0.1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-23444 | MEDIUM6.38 | org.elasticsearch:elasticsearch 2.4.3 fixed in 8.13.0, 7.17.23 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-43709 | MEDIUM6.38 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.17.21, 8.13.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2024-52979 | MEDIUM6.38 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.17.25, 8.16.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-7307 | MEDIUM6.38 | org.keycloak:keycloak-saml-core 18.0.2 fixed in 26.6.2 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-42198 | MEDIUM6.38 | org.postgresql:postgresql 42.7.2 fixed in 42.7.11 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-69419 | MEDIUM6.29 | libcrypto3 3.3.2-r4 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69419 | MEDIUM6.29 | libssl3 3.3.2-r4 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-21932 | MEDIUM6.29 | openjdk17 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-21587 | MEDIUM6.29 | openjdk17 17.0.13_p11-r0 fixed in 17.0.15_p6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-21932 | MEDIUM6.29 | openjdk17-jdk 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-21587 | MEDIUM6.29 | openjdk17-jdk 17.0.13_p11-r0 fixed in 17.0.15_p6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-21932 | MEDIUM6.29 | openjdk17-jre 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-21587 | MEDIUM6.29 | openjdk17-jre 17.0.13_p11-r0 fixed in 17.0.15_p6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-21932 | MEDIUM6.29 | openjdk17-jre-headless 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-21587 | MEDIUM6.29 | openjdk17-jre-headless 17.0.13_p11-r0 fixed in 17.0.15_p6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-49268 | MEDIUM6.18 | org.apache.shiro:shiro-core 1.13.0 fixed in 2.2.1, 3.0.0-alpha-2 | 0.5% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2024-8698 | MEDIUM6.16 | org.keycloak:keycloak-saml-core 18.0.2 fixed in 22.0.13, 24.0.8, 25.0.6 | 2.0% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2024-13009 | MEDIUM6.12 | org.eclipse.jetty:jetty-server 9.4.56.v20240826 fixed in 9.4.57.v20241219 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-64720 | MEDIUM6.03 | libpng 1.6.44-r0 fixed in 1.6.53-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-65018 | MEDIUM6.03 | libpng 1.6.44-r0 fixed in 1.6.53-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-66293 | MEDIUM6.03 | libpng 1.6.44-r0 fixed in 1.6.53-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-22695 | MEDIUM6.03 | libpng 1.6.44-r0 fixed in 1.6.54-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-31498 | MEDIUM5.95 | c-ares 1.34.3-r0 fixed in 1.34.5-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-26519 | MEDIUM5.95 | musl 1.2.5-r8 fixed in 1.2.5-r9 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-9231 | MEDIUM5.9 | libcrypto3 3.3.2-r4 fixed in 3.3.5-r0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-31790 | MEDIUM5.9 | libcrypto3 3.3.2-r4 fixed in 3.3.7-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-9231 | MEDIUM5.9 | libssl3 3.3.2-r4 fixed in 3.3.5-r0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-31790 | MEDIUM5.9 | libssl3 3.3.2-r4 fixed in 3.3.7-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-13151 | MEDIUM5.9 | libtasn1 4.19.0-r2 fixed in 4.21.0-r0 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2019-7614 | MEDIUM5.9 | org.elasticsearch:elasticsearch 2.4.3 fixed in 6.8.2, 7.2.1 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2025-9230 | MEDIUM5.6 | libcrypto3 3.3.2-r4 fixed in 3.3.5-r0 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2025-9230 | MEDIUM5.6 | libssl3 3.3.2-r4 fixed in 3.3.5-r0 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2026-59888 | MEDIUM5.52 | com.fasterxml.jackson.core:jackson-databind 2.17.0 fixed in 2.18.8, 2.21.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-43827 | MEDIUM5.52 | org.apache.shiro:shiro-core 1.13.0 fixed in 2.2.0, 3.0.0-alpha-2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-43828 | MEDIUM5.52 | org.apache.shiro:shiro-web 1.13.0 fixed in 2.2.0, 3.0.0-alpha-2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-0636 | MEDIUM5.52 | org.bouncycastle:bcprov-jdk15to18 1.78.1 fixed in 1.84 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-11143 | MEDIUM5.52 | org.eclipse.jetty:jetty-http 9.4.56.v20240826 fixed in 12.0.31, 12.1.5 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2023-49921 | MEDIUM5.52 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.17.16, 8.11.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-12133 | MEDIUM5.3 | libtasn1 4.19.0-r2 fixed in 4.20.0-r0 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2021-22135 | MEDIUM5.3 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.11.2, 6.8.15 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2021-22137 | MEDIUM5.3 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.11.2, 6.8.15 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2025-64506 | MEDIUM5.18 | libpng 1.6.44-r0 fixed in 1.6.53-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-21933 | MEDIUM5.18 | openjdk17 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-21933 | MEDIUM5.18 | openjdk17-jdk 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-21933 | MEDIUM5.18 | openjdk17-jre 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-21933 | MEDIUM5.18 | openjdk17-jre-headless 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2018-3824 | MEDIUM5.18 | org.elasticsearch:elasticsearch 2.4.3 fixed in 5.6.9, 6.2.4 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2025-62408 | MEDIUM5.02 | c-ares 1.34.3-r0 fixed in 1.34.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-31344 | MEDIUM5.02 | giflib 5.2.2-r0 fixed in 5.2.2-r1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-15468 | MEDIUM5.02 | libcrypto3 3.3.2-r4 fixed in 3.3.6-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-66199 | MEDIUM5.02 | libcrypto3 3.3.2-r4 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69420 | MEDIUM5.02 | libcrypto3 3.3.2-r4 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-22796 | MEDIUM5.02 | libcrypto3 3.3.2-r4 fixed in 3.3.6-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-15468 | MEDIUM5.02 | libssl3 3.3.2-r4 fixed in 3.3.6-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-66199 | MEDIUM5.02 | libssl3 3.3.2-r4 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69420 | MEDIUM5.02 | libssl3 3.3.2-r4 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-22796 | MEDIUM5.02 | libssl3 3.3.2-r4 fixed in 3.3.6-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-53057 | MEDIUM5.02 | openjdk17 17.0.13_p11-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-53057 | MEDIUM5.02 | openjdk17-jdk 17.0.13_p11-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-53057 | MEDIUM5.02 | openjdk17-jre 17.0.13_p11-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-53057 | MEDIUM5.02 | openjdk17-jre-headless 17.0.13_p11-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2020-7021 | MEDIUM4.9 | org.elasticsearch:elasticsearch 2.4.3 fixed in 6.8.14, 7.10.0 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2025-30698 | MEDIUM4.76 | openjdk17 17.0.13_p11-r0 fixed in 17.0.15_p6-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-30698 | MEDIUM4.76 | openjdk17-jdk 17.0.13_p11-r0 fixed in 17.0.15_p6-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-30698 | MEDIUM4.76 | openjdk17-jre 17.0.13_p11-r0 fixed in 17.0.15_p6-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-30698 | MEDIUM4.76 | openjdk17-jre-headless 17.0.13_p11-r0 fixed in 17.0.15_p6-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-22795 | MEDIUM4.67 | libcrypto3 3.3.2-r4 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-22795 | MEDIUM4.67 | libssl3 3.3.2-r4 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-6042 | MEDIUM4.67 | musl 1.2.5-r8 fixed in 1.2.5-r10 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-27171 | MEDIUM4.67 | zlib 1.3.1-r2 fixed in 1.3.2-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-54514 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.17.0 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-54515 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.17.0 fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-8916 | MEDIUM4.5 | org.bouncycastle:bcpkix-jdk15to18 1.78.1 fixed in 1.79 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2024-6763 | MEDIUM4.5 | org.eclipse.jetty:jetty-http 9.4.56.v20240826 fixed in 12.0.12 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-2575 | MEDIUM4.5 | org.keycloak:keycloak-saml-adapter-core 18.0.2 fixed in 26.5.4 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-2575 | MEDIUM4.5 | org.keycloak:keycloak-saml-core 18.0.2 fixed in 26.5.4 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2024-47554 | MEDIUM4.3 | commons-io:commons-io 2.11.0 fixed in 2.14.0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2024-47554 | MEDIUM4.3 | commons-io:commons-io 2.8.0 fixed in 2.14.0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-21502 | MEDIUM4.08 | openjdk17 17.0.13_p11-r0 fixed in 17.0.14_p7-r0 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2025-30754 | MEDIUM4.08 | openjdk17 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-53066 | MEDIUM4.08 | openjdk17 17.0.13_p11-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-21925 | MEDIUM4.08 | openjdk17 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-21502 | MEDIUM4.08 | openjdk17-jdk 17.0.13_p11-r0 fixed in 17.0.14_p7-r0 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2025-30754 | MEDIUM4.08 | openjdk17-jdk 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-53066 | MEDIUM4.08 | openjdk17-jdk 17.0.13_p11-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-21925 | MEDIUM4.08 | openjdk17-jdk 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-21502 | MEDIUM4.08 | openjdk17-jre 17.0.13_p11-r0 fixed in 17.0.14_p7-r0 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2025-30754 | MEDIUM4.08 | openjdk17-jre 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-53066 | MEDIUM4.08 | openjdk17-jre 17.0.13_p11-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-21925 | MEDIUM4.08 | openjdk17-jre 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-21502 | MEDIUM4.08 | openjdk17-jre-headless 17.0.13_p11-r0 fixed in 17.0.14_p7-r0 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2025-30754 | MEDIUM4.08 | openjdk17-jre-headless 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-53066 | MEDIUM4.08 | openjdk17-jre-headless 17.0.13_p11-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-21925 | MEDIUM4.08 | openjdk17-jre-headless 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-15467 | MEDIUM4.06 | libcrypto3 3.3.2-r4 fixed in 3.3.6-r0 | 47.6% High Exploitation Risk | Post-Exploit |
| CVE-2025-15467 | MEDIUM4.06 | libssl3 3.3.2-r4 fixed in 3.3.6-r0 | 47.6% High Exploitation Risk | Post-Exploit |
| CVE-2025-15467 | MEDIUM4.06 | openssl 3.3.2-r4 fixed in 3.3.6-r0 | 47.6% High Exploitation Risk | Post-Exploit |
| CVE-2024-13176 | MEDIUM4 | libcrypto3 3.3.2-r4 fixed in 3.3.2-r5 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-68160 | MEDIUM4 | libcrypto3 3.3.2-r4 fixed in 3.3.6-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-13176 | MEDIUM4 | libssl3 3.3.2-r4 fixed in 3.3.2-r5 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-68160 | MEDIUM4 | libssl3 3.3.2-r4 fixed in 3.3.6-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-64505 | LOW3.74 | libpng 1.6.44-r0 fixed in 1.6.53-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-34757 | LOW3.74 | libpng 1.6.44-r0 fixed in 1.6.57-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-48924 | LOW3.7 | org.apache.commons:commons-lang3 3.12.0 fixed in 3.18.0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-48924 | LOW3.7 | org.apache.commons:commons-lang3 3.13.0 fixed in 3.18.0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-31790 | LOW3.54 | openssl 3.3.2-r4 fixed in 3.3.7-r0 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2025-69418 | LOW3.4 | libcrypto3 3.3.2-r4 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-69418 | LOW3.4 | libssl3 3.3.2-r4 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-9230 | LOW3.36 | openssl 3.3.2-r4 fixed in 3.3.5-r0 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2025-4947 | LOW3.31 | curl 8.12.0-r0 fixed in 8.14.0-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-4947 | LOW3.31 | libcurl 8.12.0-r0 fixed in 8.14.0-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-9086 | LOW3.18 | curl 8.12.0-r0 fixed in 8.14.1-r2 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2025-9086 | LOW3.18 | libcurl 8.12.0-r0 fixed in 8.14.1-r2 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2025-9232 | LOW3.1 | libcrypto3 3.3.2-r4 fixed in 3.3.5-r0 | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2025-9232 | LOW3.1 | libssl3 3.3.2-r4 fixed in 3.3.5-r0 | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2020-7020 | LOW3.1 | org.elasticsearch:elasticsearch 2.4.3 fixed in 6.8.13, 7.9.2 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2025-15468 | LOW3.01 | openssl 3.3.2-r4 fixed in 3.3.6-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2025-66199 | LOW3.01 | openssl 3.3.2-r4 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-69420 | LOW3.01 | openssl 3.3.2-r4 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-22796 | LOW3.01 | openssl 3.3.2-r4 fixed in 3.3.6-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-31789 | LOW3 | libcrypto3 3.3.2-r4 fixed in 3.3.7-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-31789 | LOW3 | libssl3 3.3.2-r4 fixed in 3.3.7-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-31789 | LOW3 | openssl 3.3.2-r4 fixed in 3.3.7-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-30749 | LOW2.92 | openjdk17 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2025-30749 | LOW2.92 | openjdk17-jdk 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2025-30749 | LOW2.92 | openjdk17-jre 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2025-30749 | LOW2.92 | openjdk17-jre-headless 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2019-7611 | LOW2.92 | org.elasticsearch:elasticsearch 2.4.3 fixed in 5.6.15, 6.6.1 | 2.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-22795 | LOW2.8 | openssl 3.3.2-r4 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-28388 | LOW2.7 | libcrypto3 3.3.2-r4 fixed in 3.3.7-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28389 | LOW2.7 | libcrypto3 3.3.2-r4 fixed in 3.3.7-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28388 | LOW2.7 | libssl3 3.3.2-r4 fixed in 3.3.7-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28389 | LOW2.7 | libssl3 3.3.2-r4 fixed in 3.3.7-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28388 | LOW2.7 | openssl 3.3.2-r4 fixed in 3.3.7-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28389 | LOW2.7 | openssl 3.3.2-r4 fixed in 3.3.7-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28390 | LOW2.7 | openssl 3.3.2-r4 fixed in 3.3.7-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-2100 | LOW2.7 | p11-kit 0.25.5-r2 fixed in 0.26.2-r0 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-2100 | LOW2.7 | p11-kit-trust 0.25.5-r2 fixed in 0.26.2-r0 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2023-31418 | LOW2.7 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.17.13, 8.9.0 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2024-12797 | LOW2.66 | openssl 3.3.2-r4 fixed in 3.3.3-r0 | 2.4% Low-Moderate Risk | Post-Exploit |
| CVE-2025-5399 | LOW2.58 | curl 8.12.0-r0 fixed in 8.14.1-r0 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2025-5399 | LOW2.58 | libcurl 8.12.0-r0 fixed in 8.14.1-r0 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28387 | LOW2.48 | openssl 3.3.2-r4 fixed in 3.3.7-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2025-5025 | LOW2.45 | curl 8.12.0-r0 fixed in 8.14.0-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-10148 | LOW2.45 | curl 8.12.0-r0 fixed in 8.14.1-r2 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-5025 | LOW2.45 | libcurl 8.12.0-r0 fixed in 8.14.0-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-10148 | LOW2.45 | libcurl 8.12.0-r0 fixed in 8.14.1-r2 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2024-13176 | LOW2.4 | openssl 3.3.2-r4 fixed in 3.3.2-r5 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-68160 | LOW2.4 | openssl 3.3.2-r4 fixed in 3.3.6-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-69421 | LOW2.29 | openssl 3.3.2-r4 fixed in 3.3.6-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2025-69419 | LOW2.26 | openssl 3.3.2-r4 fixed in 3.3.6-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-9231 | LOW2.12 | openssl 3.3.2-r4 fixed in 3.3.5-r0 | 2.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-23901 | LOW2.12 | org.apache.shiro:shiro-core 1.13.0 fixed in 2.1.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69418 | LOW2.04 | openssl 3.3.2-r4 fixed in 3.3.6-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-9232 | LOW1.86 | openssl 3.3.2-r4 fixed in 3.3.5-r0 | 2.3% Low-Moderate Risk | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | busybox 1.37.0-r9 fixed in 1.37.0-r14 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | busybox-binsh 1.37.0-r9 fixed in 1.37.0-r14 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | ssl_client 1.37.0-r9 fixed in 1.37.0-r14 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-50059 | NONE0 | openjdk17-demos 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-50059 | NONE0 | openjdk17-doc 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-50059 | NONE0 | openjdk17-jmods 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-30749 | NONE0 | openjdk17-demos 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2025-50106 | NONE0 | openjdk17-demos 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-30749 | NONE0 | openjdk17-doc 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2025-50106 | NONE0 | openjdk17-doc 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-30749 | NONE0 | openjdk17-jmods 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2025-50106 | NONE0 | openjdk17-jmods 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-40200 | NONE0 | musl-utils 1.2.5-r8 fixed in 1.2.5-r11 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-23083 | NONE0 | openjdk17-demos 17.0.13_p11-r0 fixed in 17.0.15_p6-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-23083 | NONE0 | openjdk17-doc 17.0.13_p11-r0 fixed in 17.0.15_p6-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-23083 | NONE0 | openjdk17-jmods 17.0.13_p11-r0 fixed in 17.0.15_p6-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-21945 | NONE0 | openjdk17-demos 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2026-21945 | NONE0 | openjdk17-doc 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2026-21945 | NONE0 | openjdk17-jmods 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2026-21932 | NONE0 | openjdk17-demos 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-21587 | NONE0 | openjdk17-demos 17.0.13_p11-r0 fixed in 17.0.15_p6-r0 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-21932 | NONE0 | openjdk17-doc 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-21587 | NONE0 | openjdk17-doc 17.0.13_p11-r0 fixed in 17.0.15_p6-r0 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2026-21932 | NONE0 | openjdk17-jmods 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-21587 | NONE0 | openjdk17-jmods 17.0.13_p11-r0 fixed in 17.0.15_p6-r0 | 0.8% Theoretical Threat | Not Applicable |
| CVE-2025-26519 | NONE0 | musl-utils 1.2.5-r8 fixed in 1.2.5-r9 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-21933 | NONE0 | openjdk17-demos 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-21933 | NONE0 | openjdk17-doc 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-21933 | NONE0 | openjdk17-jmods 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-53057 | NONE0 | openjdk17-demos 17.0.13_p11-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-53057 | NONE0 | openjdk17-doc 17.0.13_p11-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-53057 | NONE0 | openjdk17-jmods 17.0.13_p11-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-30698 | NONE0 | openjdk17-demos 17.0.13_p11-r0 fixed in 17.0.15_p6-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-30698 | NONE0 | openjdk17-doc 17.0.13_p11-r0 fixed in 17.0.15_p6-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-30698 | NONE0 | openjdk17-jmods 17.0.13_p11-r0 fixed in 17.0.15_p6-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-6042 | NONE0 | musl-utils 1.2.5-r8 fixed in 1.2.5-r10 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-21502 | NONE0 | openjdk17-demos 17.0.13_p11-r0 fixed in 17.0.14_p7-r0 | 1.0% Theoretical Threat | Not Applicable |
| CVE-2025-30754 | NONE0 | openjdk17-demos 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-53066 | NONE0 | openjdk17-demos 17.0.13_p11-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-21925 | NONE0 | openjdk17-demos 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-21502 | NONE0 | openjdk17-doc 17.0.13_p11-r0 fixed in 17.0.14_p7-r0 | 1.0% Theoretical Threat | Not Applicable |
| CVE-2025-30754 | NONE0 | openjdk17-doc 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-53066 | NONE0 | openjdk17-doc 17.0.13_p11-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-21925 | NONE0 | openjdk17-doc 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-21502 | NONE0 | openjdk17-jmods 17.0.13_p11-r0 fixed in 17.0.14_p7-r0 | 1.0% Theoretical Threat | Not Applicable |
| CVE-2025-30754 | NONE0 | openjdk17-jmods 17.0.13_p11-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-53066 | NONE0 | openjdk17-jmods 17.0.13_p11-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-21925 | NONE0 | openjdk17-jmods 17.0.13_p11-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-48924 | NONE0 | commons-lang:commons-lang 2.6 No fix yet | 2.2% Low-Moderate Risk | Not Applicable |
| CVE-2024-58251 | NONE0 | busybox 1.37.0-r9 fixed in 1.37.0-r14 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | busybox-binsh 1.37.0-r9 fixed in 1.37.0-r14 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | ssl_client 1.37.0-r9 fixed in 1.37.0-r14 | 0.2% Theoretical Threat | Not Applicable |
| GHSA-r7wm-3cxj-wff9 | NONE0 | com.fasterxml.jackson.core:jackson-core 2.17.0 fixed in 2.18.8, 2.21.4, 2.22.1 | — | Not Applicable |
| GHSA-72hv-8253-57qq | NONE0 | com.fasterxml.jackson.core:jackson-core 2.17.0 fixed in 2.21.1, 2.18.6 | — | Not Applicable |
| CVE-2026-10050 | NONE0 | org.eclipse.jetty:jetty-security 9.4.56.v20240826 fixed in 9.4.63, 10.0.31, 11.0.31, 12.0.36, 12.1.10 | — | Not Applicable |
| CVE-2026-6790 | NONE0 | org.eclipse.jetty:jetty-server 9.4.56.v20240826 fixed in 12.0.35, 12.1.9 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-56740 | NONE0 | org.jline:jline-remote-telnet 3.21.0 fixed in 4.2.1 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-56741 | NONE0 | org.jline:jline-remote-telnet 3.21.0 fixed in 4.2.1 | 0.5% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.