Vulnerability Reportsonatype/nexus3:3.81.0-alpine

sonatype/nexus3:3.81.0-alpine
digestsha256:b4188e591207a20effa3642041b798e1d5c8163213a06812608cafb92f491c18

Executive Summary

Last scanned:

Threat Score
0/100NEEDS ATTENTION
Reputation
TRUSTED

AI verdict failed due to an error.

Vulnerabilities

Vulnerability Log

390 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2025-15467MEDIUM6.76
openssl
3.5.0-r0
fixed in 3.5.5-r0
47.6%
High Exploitation Risk
Post-Exploit
CVE-2026-31789MEDIUM5
openssl
3.5.0-r0
fixed in 3.5.6-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-45447MEDIUM4.86
openssl
3.5.0-r0
fixed in 3.5.7-r0
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-45445MEDIUM4.64
openssl
3.5.0-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-28388MEDIUM4.5
openssl
3.5.0-r0
fixed in 3.5.6-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-28389MEDIUM4.5
openssl
3.5.0-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-28390MEDIUM4.5
openssl
3.5.0-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-34183MEDIUM4.5
openssl
3.5.0-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-28387MEDIUM4.13
openssl
3.5.0-r0
fixed in 3.5.6-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2025-69421LOW3.82
openssl
3.5.0-r0
fixed in 3.5.5-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2025-69419LOW3.77
openssl
3.5.0-r0
fixed in 3.5.5-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-34182LOW3.77
openssl
3.5.0-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-11187LOW3.66
openssl
3.5.0-r0
fixed in 3.5.5-r0
4.5%
Low-Moderate Risk
Post-Exploit
CVE-2025-9231LOW3.54
openssl
3.5.0-r0
fixed in 3.5.4-r0
2.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-31790LOW3.54
openssl
3.5.0-r0
fixed in 3.5.6-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-42764LOW3.54
openssl
3.5.0-r0
fixed in 3.5.7-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2025-9230LOW3.36
openssl
3.5.0-r0
fixed in 3.5.4-r0
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2026-5545LOW3.31
curl
8.14.1-r0
fixed in 8.14.1-r3
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-2673LOW3.31
openssl
3.5.0-r0
fixed in 3.5.6-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-34181LOW3.21
openssl
3.5.0-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-42768LOW3.21
openssl
3.5.0-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-9086LOW3.18
curl
8.14.1-r0
fixed in 8.14.1-r2
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-15468LOW3.01
openssl
3.5.0-r0
fixed in 3.5.5-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2025-66199LOW3.01
openssl
3.5.0-r0
fixed in 3.5.5-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-69420LOW3.01
openssl
3.5.0-r0
fixed in 3.5.5-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-22796LOW3.01
openssl
3.5.0-r0
fixed in 3.5.5-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-42769LOW3.01
openssl
3.5.0-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-42770LOW3.01
openssl
3.5.0-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-9076LOW3.01
openssl
3.5.0-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-34180LOW3
openssl
3.5.0-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2025-15469LOW2.8
openssl
3.5.0-r0
fixed in 3.5.5-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-22795LOW2.8
openssl
3.5.0-r0
fixed in 3.5.5-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-7383LOW2.8
openssl
3.5.0-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-42766LOW2.7
openssl
3.5.0-r0
fixed in 3.5.7-r0
1.0%
Theoretical Threat
Post-Exploit
CVE-2026-42767LOW2.7
openssl
3.5.0-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-10148LOW2.45
curl
8.14.1-r0
fixed in 8.14.1-r2
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-68160LOW2.4
openssl
3.5.0-r0
fixed in 3.5.5-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-69418LOW2.04
openssl
3.5.0-r0
fixed in 3.5.5-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-45446LOW1.89
openssl
3.5.0-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-9232LOW1.86
openssl
3.5.0-r0
fixed in 3.5.4-r0
2.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-46394LOW1.68
busybox
1.37.0-r18
fixed in 1.37.0-r20
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-46394LOW1.68
busybox-binsh
1.37.0-r18
fixed in 1.37.0-r20
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-45674NONE0
io.netty:netty-resolver-dns
4.1.119.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Not Applicable
CVE-2026-47691NONE0
io.netty:netty-resolver-dns
4.1.119.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-31789NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.6-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2025-15467NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.5-r0
47.6%
High Exploitation Risk
Not Applicable
CVE-2026-31789NONE0
libssl3
3.5.0-r0
fixed in 3.5.6-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2025-15467NONE0
libssl3
3.5.0-r0
fixed in 3.5.5-r0
47.6%
High Exploitation Risk
Not Applicable
CVE-2026-42581NONE0
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2025-66516NONE0
org.apache.tika:tika-core
1.28.4
fixed in 3.2.2
79.8%
Actively Exploited
Not Applicable
CVE-2026-45445NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-45445NONE0
libssl3
3.5.0-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42579NONE0
io.netty:netty-codec-dns
4.1.119.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Not Applicable
CVE-2026-42584NONE0
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.8%
Theoretical Threat
Not Applicable
CVE-2026-49268NONE0
org.apache.shiro:shiro-core
1.13.0
fixed in 2.2.1, 3.0.0-alpha-2
0.5%
Theoretical Threat
Not Applicable
CVE-2026-2332NONE0
org.eclipse.jetty:jetty-http
12.0.17
fixed in 12.1.7, 12.0.33
1.1%
Low-Moderate Risk
Not Applicable
CVE-2025-48734NONE0
commons-beanutils:commons-beanutils
1.9.4
fixed in 1.11.0
1.5%
Low-Moderate Risk
Not Applicable
CVE-2025-67030NONE0
org.codehaus.plexus:plexus-utils
3.5.1
fixed in 4.0.3, 3.6.1
0.7%
Theoretical Threat
Not Applicable
CVE-2025-50059NONE0
openjdk17
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2025-50059NONE0
openjdk17-demos
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2025-50059NONE0
openjdk17-doc
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2025-50059NONE0
openjdk17-jdk
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2025-50059NONE0
openjdk17-jmods
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2025-50059NONE0
openjdk17-jre
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2025-50059NONE0
openjdk17-jre-headless
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-28387NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.6-r0
0.8%
Theoretical Threat
Not Applicable
CVE-2026-45447NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
5.2%
Low-Moderate Risk
Not Applicable
CVE-2026-25646NONE0
libpng
1.6.47-r0
fixed in 1.6.55-r0
1.0%
Theoretical Threat
Not Applicable
CVE-2026-28387NONE0
libssl3
3.5.0-r0
fixed in 3.5.6-r0
0.8%
Theoretical Threat
Not Applicable
CVE-2026-45447NONE0
libssl3
3.5.0-r0
fixed in 3.5.7-r0
5.2%
Low-Moderate Risk
Not Applicable
CVE-2025-30749NONE0
openjdk17
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
1.1%
Low-Moderate Risk
Not Applicable
CVE-2025-50106NONE0
openjdk17
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2025-30749NONE0
openjdk17-demos
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
1.1%
Low-Moderate Risk
Not Applicable
CVE-2025-50106NONE0
openjdk17-demos
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2025-30749NONE0
openjdk17-doc
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
1.1%
Low-Moderate Risk
Not Applicable
CVE-2025-50106NONE0
openjdk17-doc
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2025-30749NONE0
openjdk17-jdk
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
1.1%
Low-Moderate Risk
Not Applicable
CVE-2025-50106NONE0
openjdk17-jdk
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2025-30749NONE0
openjdk17-jmods
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
1.1%
Low-Moderate Risk
Not Applicable
CVE-2025-50106NONE0
openjdk17-jmods
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2025-30749NONE0
openjdk17-jre
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
1.1%
Low-Moderate Risk
Not Applicable
CVE-2025-50106NONE0
openjdk17-jre
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2025-30749NONE0
openjdk17-jre-headless
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
1.1%
Low-Moderate Risk
Not Applicable
CVE-2025-50106NONE0
openjdk17-jre-headless
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-54512NONE0
com.fasterxml.jackson.core:jackson-databind
2.17.0
fixed in 2.18.8, 3.1.4, 2.21.4
0.8%
Theoretical Threat
Not Applicable
CVE-2026-54513NONE0
com.fasterxml.jackson.core:jackson-databind
2.17.0
fixed in 2.18.8, 2.21.4, 3.1.4
0.7%
Theoretical Threat
Not Applicable
CVE-2026-44249NONE0
io.netty:netty-handler
4.1.119.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2019-7611NONE0
org.elasticsearch:elasticsearch
2.4.3
fixed in 5.6.15, 6.6.1
2.1%
Low-Moderate Risk
Not Applicable
CVE-2026-22801NONE0
libpng
1.6.47-r0
fixed in 1.6.54-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-40200NONE0
musl
1.2.5-r10
fixed in 1.2.5-r12
0.2%
Theoretical Threat
Not Applicable
CVE-2026-40200NONE0
musl-utils
1.2.5-r10
fixed in 1.2.5-r12
0.2%
Theoretical Threat
Not Applicable
CVE-2026-22184NONE0
zlib
1.3.1-r2
fixed in 1.3.2-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2024-8698NONE0
org.keycloak:keycloak-saml-core
18.0.2
fixed in 22.0.13, 24.0.8, 25.0.6
2.0%
Low-Moderate Risk
Not Applicable
CVE-2026-33636NONE0
libpng
1.6.47-r0
fixed in 1.6.56-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-33630NONE0
c-ares
1.34.5-r0
fixed in 1.34.8-r0
Not Applicable
CVE-2026-41254NONE0
lcms2
2.16-r0
fixed in 2.19-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2025-69421NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.5-r0
0.8%
Theoretical Threat
Not Applicable
CVE-2026-28388NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.6-r0
1.1%
Low-Moderate Risk
Not Applicable
CVE-2026-28389NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-28390NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-34183NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-33416NONE0
libpng
1.6.47-r0
fixed in 1.6.56-r0
1.1%
Low-Moderate Risk
Not Applicable
CVE-2025-69421NONE0
libssl3
3.5.0-r0
fixed in 3.5.5-r0
0.8%
Theoretical Threat
Not Applicable
CVE-2026-28388NONE0
libssl3
3.5.0-r0
fixed in 3.5.6-r0
1.1%
Low-Moderate Risk
Not Applicable
CVE-2026-28389NONE0
libssl3
3.5.0-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-28390NONE0
libssl3
3.5.0-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-34183NONE0
libssl3
3.5.0-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-27135NONE0
nghttp2-libs
1.65.0-r0
fixed in 1.68.1
0.8%
Theoretical Threat
Not Applicable
CVE-2026-21945NONE0
openjdk17
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.9%
Theoretical Threat
Not Applicable
CVE-2026-22016NONE0
openjdk17
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-34282NONE0
openjdk17
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-21945NONE0
openjdk17-demos
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.9%
Theoretical Threat
Not Applicable
CVE-2026-22016NONE0
openjdk17-demos
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-34282NONE0
openjdk17-demos
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-21945NONE0
openjdk17-doc
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.9%
Theoretical Threat
Not Applicable
CVE-2026-22016NONE0
openjdk17-doc
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-34282NONE0
openjdk17-doc
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-21945NONE0
openjdk17-jdk
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.9%
Theoretical Threat
Not Applicable
CVE-2026-22016NONE0
openjdk17-jdk
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-34282NONE0
openjdk17-jdk
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-21945NONE0
openjdk17-jmods
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.9%
Theoretical Threat
Not Applicable
CVE-2026-22016NONE0
openjdk17-jmods
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-34282NONE0
openjdk17-jmods
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-21945NONE0
openjdk17-jre
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.9%
Theoretical Threat
Not Applicable
CVE-2026-22016NONE0
openjdk17-jre
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-34282NONE0
openjdk17-jre
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-21945NONE0
openjdk17-jre-headless
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.9%
Theoretical Threat
Not Applicable
CVE-2026-22016NONE0
openjdk17-jre-headless
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-34282NONE0
openjdk17-jre-headless
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-2100NONE0
p11-kit
0.25.5-r2
fixed in 0.26.2-r0
1.2%
Low-Moderate Risk
Not Applicable
CVE-2026-2100NONE0
p11-kit-trust
0.25.5-r2
fixed in 0.26.2-r0
1.2%
Low-Moderate Risk
Not Applicable
CVE-2025-7962NONE0
com.sun.mail:jakarta.mail
1.6.7
fixed in 1.6.8, 2.0.2
0.8%
Theoretical Threat
Not Applicable
CVE-2026-42583NONE0
io.netty:netty-codec
4.1.119.Final
fixed in 4.1.133.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-59901NONE0
io.netty:netty-codec
4.1.119.Final
fixed in 4.1.136.Final
0.2%
Theoretical Threat
Not Applicable
CVE-2025-58057NONE0
io.netty:netty-codec
4.1.119.Final
fixed in 4.1.125.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2026-33870NONE0
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.1.132.Final, 4.2.10.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42587NONE0
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Not Applicable
CVE-2026-55831NONE0
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-55833NONE0
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-56745NONE0
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.5%
Theoretical Threat
Not Applicable
CVE-2026-42585NONE0
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.2%
Theoretical Threat
Not Applicable
CVE-2026-56746NONE0
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-59899NONE0
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2025-58056NONE0
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.1.125.Final, 4.2.5.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2025-55163NONE0
io.netty:netty-codec-http2
4.1.119.Final
fixed in 4.2.4.Final, 4.1.124.Final
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-33871NONE0
io.netty:netty-codec-http2
4.1.119.Final
fixed in 4.1.132.Final, 4.2.11.Final
1.1%
Low-Moderate Risk
Not Applicable
CVE-2026-42587NONE0
io.netty:netty-codec-http2
4.1.119.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Not Applicable
CVE-2026-56819NONE0
io.netty:netty-codec-http2
4.1.119.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-48043NONE0
io.netty:netty-codec-http2
4.1.119.Final
fixed in 4.1.135.Final, 4.2.15.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2026-45416NONE0
io.netty:netty-handler
4.1.119.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.5%
Theoretical Threat
Not Applicable
CVE-2026-50010NONE0
io.netty:netty-handler
4.1.119.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42578NONE0
io.netty:netty-handler-proxy
4.1.119.Final
fixed in 4.1.133.Final, 4.2.13.Final
1.0%
Theoretical Threat
Not Applicable
CVE-2024-57699NONE0
net.minidev:json-smart
2.5.0
fixed in 2.5.2
0.6%
Theoretical Threat
Not Applicable
CVE-2026-3505NONE0
org.bouncycastle:bcpg-jdk15to18
1.78.1
fixed in 1.84
0.8%
Theoretical Threat
Not Applicable
CVE-2026-5588NONE0
org.bouncycastle:bcpkix-jdk15to18
1.78.1
fixed in 1.84
0.4%
Theoretical Threat
Not Applicable
CVE-2026-5588NONE0
org.bouncycastle:bcpkix-jdk18on
1.78.1
fixed in 1.84
0.4%
Theoretical Threat
Not Applicable
CVE-2025-14813NONE0
org.bouncycastle:bcprov-jdk15to18
1.78.1
fixed in 1.84
0.3%
Theoretical Threat
Not Applicable
CVE-2026-5598NONE0
org.bouncycastle:bcprov-jdk15to18
1.78.1
fixed in 1.80.2
0.7%
Theoretical Threat
Not Applicable
CVE-2025-14813NONE0
org.bouncycastle:bcprov-jdk18on
1.78.1
fixed in 1.80.2, 1.81.1, 1.84
0.3%
Theoretical Threat
Not Applicable
CVE-2025-64518NONE0
org.cyclonedx:cyclonedx-core-java
9.1.0
fixed in 11.0.1
0.4%
Theoretical Threat
Not Applicable
CVE-2026-1605NONE0
org.eclipse.jetty:jetty-server
12.0.17
fixed in 12.1.6, 12.0.32
0.6%
Theoretical Threat
Not Applicable
CVE-2026-10051NONE0
org.eclipse.jetty:jetty-server
12.0.17
fixed in 12.0.36, 12.1.10
0.3%
Theoretical Threat
Not Applicable
CVE-2023-31418NONE0
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.17.13, 8.9.0
1.2%
Low-Moderate Risk
Not Applicable
CVE-2024-23444NONE0
org.elasticsearch:elasticsearch
2.4.3
fixed in 8.13.0, 7.17.23
0.2%
Theoretical Threat
Not Applicable
CVE-2024-43709NONE0
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.17.21, 8.13.3
0.6%
Theoretical Threat
Not Applicable
CVE-2024-52979NONE0
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.17.25, 8.16.0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-7307NONE0
org.keycloak:keycloak-saml-core
18.0.2
fixed in 26.6.2
0.7%
Theoretical Threat
Not Applicable
CVE-2026-42198NONE0
org.postgresql:postgresql
42.7.2
fixed in 42.7.11
0.8%
Theoretical Threat
Not Applicable
CVE-2025-41249NONE0
org.springframework:spring-core
6.1.15
fixed in 6.2.11
0.5%
Theoretical Threat
Not Applicable
CVE-2026-41848NONE0
org.springframework:spring-core
6.1.15
fixed in 7.0.8, 6.2.19
0.3%
Theoretical Threat
Not Applicable
CVE-2026-41851NONE0
org.springframework:spring-expression
6.1.15
fixed in 7.0.8, 6.2.19
0.4%
Theoretical Threat
Not Applicable
CVE-2025-69419NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.5-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-34182NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2025-69419NONE0
libssl3
3.5.0-r0
fixed in 3.5.5-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-34182NONE0
libssl3
3.5.0-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-21932NONE0
openjdk17
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-21932NONE0
openjdk17-demos
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-21932NONE0
openjdk17-doc
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-21932NONE0
openjdk17-jdk
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-21932NONE0
openjdk17-jmods
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-21932NONE0
openjdk17-jre
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-21932NONE0
openjdk17-jre-headless
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2025-22235NONE0
org.springframework.boot:spring-boot
3.3.6
fixed in 3.3.11, 3.4.5
0.4%
Theoretical Threat
Not Applicable
CVE-2025-64720NONE0
libpng
1.6.47-r0
fixed in 1.6.51-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2025-65018NONE0
libpng
1.6.47-r0
fixed in 1.6.51-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2025-66293NONE0
libpng
1.6.47-r0
fixed in 1.6.53-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22695NONE0
libpng
1.6.47-r0
fixed in 1.6.54-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-40973NONE0
org.springframework.boot:spring-boot
3.3.6
fixed in 4.0.6, 3.5.14
0.1%
Theoretical Threat
Not Applicable
CVE-2026-45673NONE0
io.netty:netty-resolver-dns
4.1.119.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-2673NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.6-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-5545NONE0
libcurl
8.14.1-r0
fixed in 8.14.1-r3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-2673NONE0
libssl3
3.5.0-r0
fixed in 3.5.6-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-59888NONE0
com.fasterxml.jackson.core:jackson-databind
2.17.0
fixed in 2.18.8, 2.21.4
0.2%
Theoretical Threat
Not Applicable
CVE-2025-67735NONE0
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.8.Final, 4.1.129.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-41417NONE0
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.1.133.Final, 4.2.13.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42580NONE0
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-59900NONE0
io.netty:netty-codec-http2
4.1.119.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-43827NONE0
org.apache.shiro:shiro-core
1.13.0
fixed in 2.2.0, 3.0.0-alpha-2
0.4%
Theoretical Threat
Not Applicable
CVE-2026-43828NONE0
org.apache.shiro:shiro-web
1.13.0
fixed in 2.2.0, 3.0.0-alpha-2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-0636NONE0
org.bouncycastle:bcprov-jdk15to18
1.78.1
fixed in 1.84
0.5%
Theoretical Threat
Not Applicable
CVE-2026-0636NONE0
org.bouncycastle:bcprov-jdk18on
1.78.1
fixed in 1.84
0.5%
Theoretical Threat
Not Applicable
CVE-2025-11143NONE0
org.eclipse.jetty:jetty-http
12.0.17
fixed in 12.0.31, 12.1.5
0.2%
Theoretical Threat
Not Applicable
CVE-2020-7019NONE0
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.9.0, 6.8.12
1.2%
Low-Moderate Risk
Not Applicable
CVE-2021-22144NONE0
org.elasticsearch:elasticsearch
2.4.3
fixed in 6.8.17, 7.13.3
2.2%
Low-Moderate Risk
Not Applicable
CVE-2023-49921NONE0
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.17.16, 8.11.2
0.4%
Theoretical Threat
Not Applicable
CVE-2025-11226NONE0
ch.qos.logback:logback-core
1.5.16
fixed in 1.5.19, 1.3.16
0.2%
Theoretical Threat
Not Applicable
CVE-2026-34181NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-42768NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-34181NONE0
libssl3
3.5.0-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-42768NONE0
libssl3
3.5.0-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2025-9341NONE0
org.bouncycastle:bc-fips
2.1.0
fixed in 2.1.1
0.2%
Theoretical Threat
Not Applicable
CVE-2025-11187NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.5-r0
4.5%
Low-Moderate Risk
Not Applicable
CVE-2025-64506NONE0
libpng
1.6.47-r0
fixed in 1.6.51-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2025-11187NONE0
libssl3
3.5.0-r0
fixed in 3.5.5-r0
4.5%
Low-Moderate Risk
Not Applicable
CVE-2026-21933NONE0
openjdk17
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-21933NONE0
openjdk17-demos
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-21933NONE0
openjdk17-doc
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-21933NONE0
openjdk17-jdk
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-21933NONE0
openjdk17-jmods
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-21933NONE0
openjdk17-jre
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-21933NONE0
openjdk17-jre-headless
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2025-22227NONE0
io.projectreactor.netty:reactor-netty-http
1.0.39
fixed in 1.3.0-M5, 1.2.8
0.3%
Theoretical Threat
Not Applicable
CVE-2018-3824NONE0
org.elasticsearch:elasticsearch
2.4.3
fixed in 5.6.9, 6.2.4
0.9%
Theoretical Threat
Not Applicable
CVE-2025-62408NONE0
c-ares
1.34.5-r0
fixed in 1.34.6-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2025-9231NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.4-r0
2.2%
Low-Moderate Risk
Not Applicable
CVE-2026-31790NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.6-r0
1.2%
Low-Moderate Risk
Not Applicable
CVE-2026-42764NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
1.2%
Low-Moderate Risk
Not Applicable
CVE-2025-15468NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.5-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2025-66199NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.5-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2025-69420NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.5-r0
0.8%
Theoretical Threat
Not Applicable
CVE-2026-22796NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.5-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-42769NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42770NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-9076NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2025-9231NONE0
libssl3
3.5.0-r0
fixed in 3.5.4-r0
2.2%
Low-Moderate Risk
Not Applicable
CVE-2026-31790NONE0
libssl3
3.5.0-r0
fixed in 3.5.6-r0
1.2%
Low-Moderate Risk
Not Applicable
CVE-2026-42764NONE0
libssl3
3.5.0-r0
fixed in 3.5.7-r0
1.2%
Low-Moderate Risk
Not Applicable
CVE-2025-15468NONE0
libssl3
3.5.0-r0
fixed in 3.5.5-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2025-66199NONE0
libssl3
3.5.0-r0
fixed in 3.5.5-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2025-69420NONE0
libssl3
3.5.0-r0
fixed in 3.5.5-r0
0.8%
Theoretical Threat
Not Applicable
CVE-2026-22796NONE0
libssl3
3.5.0-r0
fixed in 3.5.5-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-42769NONE0
libssl3
3.5.0-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42770NONE0
libssl3
3.5.0-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-9076NONE0
libssl3
3.5.0-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2025-13151NONE0
libtasn1
4.20.0-r0
fixed in 4.21.0-r0
1.1%
Low-Moderate Risk
Not Applicable
CVE-2025-53057NONE0
openjdk17
17.0.15_p6-r0
fixed in 17.0.17_p10-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2025-53057NONE0
openjdk17-demos
17.0.15_p6-r0
fixed in 17.0.17_p10-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2025-53057NONE0
openjdk17-doc
17.0.15_p6-r0
fixed in 17.0.17_p10-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2025-53057NONE0
openjdk17-jdk
17.0.15_p6-r0
fixed in 17.0.17_p10-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2025-53057NONE0
openjdk17-jmods
17.0.15_p6-r0
fixed in 17.0.17_p10-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2025-53057NONE0
openjdk17-jre
17.0.15_p6-r0
fixed in 17.0.17_p10-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2025-53057NONE0
openjdk17-jre-headless
17.0.15_p6-r0
fixed in 17.0.17_p10-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2025-9340NONE0
org.bouncycastle:bc-fips
2.1.0
fixed in 2.1.1
0.2%
Theoretical Threat
Not Applicable
CVE-2019-7614NONE0
org.elasticsearch:elasticsearch
2.4.3
fixed in 6.8.2, 7.2.1
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-41850NONE0
org.springframework:spring-expression
6.1.15
fixed in 7.0.8, 6.2.19
0.4%
Theoretical Threat
Not Applicable
CVE-2026-59921NONE0
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2025-9230NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.4-r0
1.7%
Low-Moderate Risk
Not Applicable
CVE-2025-9230NONE0
libssl3
3.5.0-r0
fixed in 3.5.4-r0
1.7%
Low-Moderate Risk
Not Applicable
CVE-2025-15469NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.5-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-22795NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.5-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-7383NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2025-15469NONE0
libssl3
3.5.0-r0
fixed in 3.5.5-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-22795NONE0
libssl3
3.5.0-r0
fixed in 3.5.5-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-7383NONE0
libssl3
3.5.0-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-6042NONE0
musl
1.2.5-r10
fixed in 1.2.5-r11
0.2%
Theoretical Threat
Not Applicable
CVE-2026-6042NONE0
musl-utils
1.2.5-r10
fixed in 1.2.5-r11
0.2%
Theoretical Threat
Not Applicable
CVE-2026-27171NONE0
zlib
1.3.1-r2
fixed in 1.3.2-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-42766NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
1.0%
Theoretical Threat
Not Applicable
CVE-2026-42767NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2025-9086NONE0
libcurl
8.14.1-r0
fixed in 8.14.1-r2
1.3%
Low-Moderate Risk
Not Applicable
CVE-2026-42766NONE0
libssl3
3.5.0-r0
fixed in 3.5.7-r0
1.0%
Theoretical Threat
Not Applicable
CVE-2026-42767NONE0
libssl3
3.5.0-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-22013NONE0
openjdk17
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22021NONE0
openjdk17
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-23865NONE0
openjdk17
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22013NONE0
openjdk17-demos
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22021NONE0
openjdk17-demos
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-23865NONE0
openjdk17-demos
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22013NONE0
openjdk17-doc
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22021NONE0
openjdk17-doc
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-23865NONE0
openjdk17-doc
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22013NONE0
openjdk17-jdk
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22021NONE0
openjdk17-jdk
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-23865NONE0
openjdk17-jdk
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22013NONE0
openjdk17-jmods
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22021NONE0
openjdk17-jmods
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-23865NONE0
openjdk17-jmods
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22013NONE0
openjdk17-jre
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22021NONE0
openjdk17-jre
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-23865NONE0
openjdk17-jre
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22013NONE0
openjdk17-jre-headless
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22021NONE0
openjdk17-jre-headless
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-23865NONE0
openjdk17-jre-headless
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-54514NONE0
com.fasterxml.jackson.core:jackson-databind
2.17.0
fixed in 2.18.8, 2.21.4, 3.1.4
0.2%
Theoretical Threat
Not Applicable
CVE-2026-54515NONE0
com.fasterxml.jackson.core:jackson-databind
2.17.0
fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1
0.3%
Theoretical Threat
Not Applicable
CVE-2025-48976NONE0
commons-fileupload:commons-fileupload
1.5
fixed in 1.6.0
67.3%
Actively Exploited
Not Applicable
CVE-2026-50020NONE0
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Not Applicable
CVE-2026-59898NONE0
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-47244NONE0
io.netty:netty-codec-http2
4.1.119.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-50560NONE0
io.netty:netty-codec-http2
4.1.119.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2025-8916NONE0
org.bouncycastle:bcpkix-jdk15to18
1.78.1
fixed in 1.79
0.5%
Theoretical Threat
Not Applicable
CVE-2025-8916NONE0
org.bouncycastle:bcpkix-jdk18on
1.78.1
fixed in 1.79
0.5%
Theoretical Threat
Not Applicable
CVE-2021-22135NONE0
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.11.2, 6.8.15
1.2%
Low-Moderate Risk
Not Applicable
CVE-2021-22137NONE0
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.11.2, 6.8.15
1.1%
Low-Moderate Risk
Not Applicable
CVE-2026-2575NONE0
org.keycloak:keycloak-saml-adapter-core
18.0.2
fixed in 26.5.4
0.5%
Theoretical Threat
Not Applicable
CVE-2026-2575NONE0
org.keycloak:keycloak-saml-core
18.0.2
fixed in 26.5.4
0.5%
Theoretical Threat
Not Applicable
CVE-2026-41852NONE0
org.springframework:spring-expression
6.1.15
fixed in 7.0.8, 6.2.19
0.2%
Theoretical Threat
Not Applicable
CVE-2026-34180NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-34180NONE0
libssl3
3.5.0-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-1225NONE0
ch.qos.logback:logback-core
1.5.16
fixed in 1.5.25
0.2%
Theoretical Threat
Not Applicable
CVE-2020-7021NONE0
org.elasticsearch:elasticsearch
2.4.3
fixed in 6.8.14, 7.10.0
1.3%
Low-Moderate Risk
Not Applicable
CVE-2025-10148NONE0
libcurl
8.14.1-r0
fixed in 8.14.1-r2
0.5%
Theoretical Threat
Not Applicable
CVE-2025-30754NONE0
openjdk17
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2025-53066NONE0
openjdk17
17.0.15_p6-r0
fixed in 17.0.17_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-21925NONE0
openjdk17
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2025-30754NONE0
openjdk17-demos
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2025-53066NONE0
openjdk17-demos
17.0.15_p6-r0
fixed in 17.0.17_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-21925NONE0
openjdk17-demos
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2025-30754NONE0
openjdk17-doc
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2025-53066NONE0
openjdk17-doc
17.0.15_p6-r0
fixed in 17.0.17_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-21925NONE0
openjdk17-doc
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2025-30754NONE0
openjdk17-jdk
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2025-53066NONE0
openjdk17-jdk
17.0.15_p6-r0
fixed in 17.0.17_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-21925NONE0
openjdk17-jdk
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2025-30754NONE0
openjdk17-jmods
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2025-53066NONE0
openjdk17-jmods
17.0.15_p6-r0
fixed in 17.0.17_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-21925NONE0
openjdk17-jmods
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2025-30754NONE0
openjdk17-jre
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2025-53066NONE0
openjdk17-jre
17.0.15_p6-r0
fixed in 17.0.17_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-21925NONE0
openjdk17-jre
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2025-30754NONE0
openjdk17-jre-headless
17.0.15_p6-r0
fixed in 17.0.16_p8-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2025-53066NONE0
openjdk17-jre-headless
17.0.15_p6-r0
fixed in 17.0.17_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-21925NONE0
openjdk17-jre-headless
17.0.15_p6-r0
fixed in 17.0.18_p8-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2025-68160NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.5-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2025-68160NONE0
libssl3
3.5.0-r0
fixed in 3.5.5-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2025-64505NONE0
libpng
1.6.47-r0
fixed in 1.6.51-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-34757NONE0
libpng
1.6.47-r0
fixed in 1.6.57-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2024-47554NONE0
commons-io:commons-io
2.8.0
fixed in 2.14.0
1.2%
Low-Moderate Risk
Not Applicable
CVE-2025-69418NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.5-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2025-69418NONE0
libssl3
3.5.0-r0
fixed in 3.5.5-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-45536NONE0
io.netty:netty-transport-native-epoll
4.1.119.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.1%
Theoretical Threat
Not Applicable
CVE-2026-45536NONE0
io.netty:netty-transport-native-kqueue
4.1.119.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.1%
Theoretical Threat
Not Applicable
CVE-2025-12194NONE0
org.bouncycastle:bc-fips
2.1.0
fixed in 2.1.2
0.1%
Theoretical Threat
Not Applicable
CVE-2026-45446NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-45446NONE0
libssl3
3.5.0-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-22018NONE0
openjdk17
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22018NONE0
openjdk17-demos
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22018NONE0
openjdk17-doc
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22018NONE0
openjdk17-jdk
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22018NONE0
openjdk17-jmods
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22018NONE0
openjdk17-jre
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22018NONE0
openjdk17-jre-headless
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2025-48924NONE0
commons-lang:commons-lang
2.6
No fix yet
2.2%
Low-Moderate Risk
Not Applicable
CVE-2025-48924NONE0
org.apache.commons:commons-lang3
3.13.0
fixed in 3.18.0
2.2%
Low-Moderate Risk
Not Applicable
CVE-2025-46394NONE0
ssl_client
1.37.0-r18
fixed in 1.37.0-r20
0.2%
Theoretical Threat
Not Applicable
CVE-2025-9232NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.4-r0
2.3%
Low-Moderate Risk
Not Applicable
CVE-2025-9232NONE0
libssl3
3.5.0-r0
fixed in 3.5.4-r0
2.3%
Low-Moderate Risk
Not Applicable
CVE-2020-7020NONE0
org.elasticsearch:elasticsearch
2.4.3
fixed in 6.8.13, 7.9.2
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-22007NONE0
openjdk17
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-34268NONE0
openjdk17
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22007NONE0
openjdk17-demos
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-34268NONE0
openjdk17-demos
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22007NONE0
openjdk17-doc
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-34268NONE0
openjdk17-doc
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22007NONE0
openjdk17-jdk
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-34268NONE0
openjdk17-jdk
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22007NONE0
openjdk17-jmods
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-34268NONE0
openjdk17-jmods
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22007NONE0
openjdk17-jre
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-34268NONE0
openjdk17-jre
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22007NONE0
openjdk17-jre-headless
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-34268NONE0
openjdk17-jre-headless
17.0.15_p6-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-23901NONE0
org.apache.shiro:shiro-core
1.13.0
fixed in 2.1.0
0.2%
Theoretical Threat
Not Applicable
CVE-2025-9092NONE0
org.bouncycastle:bc-fips
2.1.0
fixed in 2.1.1
0.1%
Theoretical Threat
Not Applicable
CVE-2024-58251NONE0
busybox
1.37.0-r18
fixed in 1.37.0-r20
0.2%
Theoretical Threat
Not Applicable
CVE-2024-58251NONE0
busybox-binsh
1.37.0-r18
fixed in 1.37.0-r20
0.2%
Theoretical Threat
Not Applicable
CVE-2025-4575NONE0
libcrypto3
3.5.0-r0
fixed in 3.5.1-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2025-4575NONE0
libssl3
3.5.0-r0
fixed in 3.5.1-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2025-4575NONE0
openssl
3.5.0-r0
fixed in 3.5.1-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2024-58251NONE0
ssl_client
1.37.0-r18
fixed in 1.37.0-r20
0.2%
Theoretical Threat
Not Applicable
CVE-2026-10532NONE0
ch.qos.logback:logback-core
1.5.16
fixed in 1.5.34
0.4%
Theoretical Threat
Not Applicable
CVE-2026-9828NONE0
ch.qos.logback:logback-core
1.5.16
fixed in 1.5.33
0.4%
Theoretical Threat
Not Applicable
GHSA-r7wm-3cxj-wff9NONE0
com.fasterxml.jackson.core:jackson-core
2.17.0
fixed in 2.18.8, 2.21.4, 2.22.1
Not Applicable
GHSA-72hv-8253-57qqNONE0
com.fasterxml.jackson.core:jackson-core
2.17.0
fixed in 2.21.1, 2.18.6
Not Applicable
GHSA-mfg7-5gfp-c4w3NONE0
io.netty:netty-codec-dns
4.1.119.Final
fixed in 4.2.16.Final, 4.1.136.Final
Not Applicable
CVE-2026-10050NONE0
org.eclipse.jetty.ee8:jetty-ee8-security
12.0.17
fixed in 12.0.36, 12.1.10
Not Applicable
CVE-2026-10050NONE0
org.eclipse.jetty:jetty-security
12.0.17
fixed in 9.4.63, 10.0.31, 11.0.31, 12.0.36, 12.1.10
Not Applicable
CVE-2026-6790NONE0
org.eclipse.jetty:jetty-server
12.0.17
fixed in 12.0.35, 12.1.9
0.2%
Theoretical Threat
Not Applicable
CVE-2026-8384NONE0
org.eclipse.jetty:jetty-util
12.0.17
fixed in 12.0.35, 12.1.9
0.2%
Theoretical Threat
Not Applicable
CVE-2025-22233NONE0
org.springframework:spring-context
6.1.15
fixed in 6.2.7, 6.1.20
0.4%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.