Last scanned:
This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could exploit CVE-2025-66516 (XXE in Tika) via a crafted PDF upload to read arbitrary files, or leverage CVE-2026-2332 (Jetty request smuggling) to desynchronize HTTP requests and bypass access controls. A separate Shiro LDAP injection issue only applies when LDAP authentication is enabled, but the other critical flaws require no special configuration; the sheer number and severity of exposed vulnerabilities make remediation urgent.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2025-66516 | CRITICAL10 | org.apache.tika:tika-core 1.28.4 fixed in 3.2.2 | 78.8% Actively Exploited | Directly ExposedContext importance: HIGH |
| CVE-2026-2332 | CRITICAL9.1 | org.eclipse.jetty:jetty-http 12.0.17 fixed in 12.1.7, 12.0.33 | 1.1% Low-Moderate Risk | Directly ExposedContext importance: HIGH |
| CVE-2026-49268 | HIGH7.73 | org.apache.shiro:shiro-core 1.13.0 fixed in 2.2.1, 3.0.0-alpha-2 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2024-8698 | HIGH7.7 | org.keycloak:keycloak-saml-core 18.0.2 fixed in 22.0.13, 24.0.8, 25.0.6 | 2.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-33630 | HIGH7.5 | c-ares 1.34.5-r0 fixed in 1.34.8-r0 | — | Directly Exposed |
| CVE-2026-28388 | HIGH7.5 | libcrypto3 3.5.0-r0 fixed in 3.5.6-r0 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28389 | HIGH7.5 | libcrypto3 3.5.0-r0 fixed in 3.5.6-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28390 | HIGH7.5 | libcrypto3 3.5.0-r0 fixed in 3.5.6-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-34183 | HIGH7.5 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-33416 | HIGH7.5 | libpng 1.6.47-r0 fixed in 1.6.56-r0 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28388 | HIGH7.5 | libssl3 3.5.0-r0 fixed in 3.5.6-r0 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28389 | HIGH7.5 | libssl3 3.5.0-r0 fixed in 3.5.6-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28390 | HIGH7.5 | libssl3 3.5.0-r0 fixed in 3.5.6-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-34183 | HIGH7.5 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-2100 | HIGH7.5 | p11-kit 0.25.5-r2 fixed in 0.26.2-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-2100 | HIGH7.5 | p11-kit-trust 0.25.5-r2 fixed in 0.26.2-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-55163 | HIGH7.5 | io.netty:netty-codec-http2 4.1.119.Final fixed in 4.2.4.Final, 4.1.124.Final | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-33871 | HIGH7.5 | io.netty:netty-codec-http2 4.1.119.Final fixed in 4.1.132.Final, 4.2.11.Final | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-31418 | HIGH7.5 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.17.13, 8.9.0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-67030 | HIGH7.48 | org.codehaus.plexus:plexus-utils 3.5.1 fixed in 4.0.3, 3.6.1 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-50059 | HIGH7.31 | openjdk17 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-50059 | HIGH7.31 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-50059 | HIGH7.31 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-48734 | HIGH7.04 | commons-beanutils:commons-beanutils 1.9.4 fixed in 1.11.0 | 1.5% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2025-48976 | MEDIUM6.89 | commons-fileupload:commons-fileupload 1.5 fixed in 1.6.0 | 67.3% Actively Exploited | Directly Exposed |
| CVE-2026-28387 | MEDIUM6.88 | libcrypto3 3.5.0-r0 fixed in 3.5.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-25646 | MEDIUM6.88 | libpng 1.6.47-r0 fixed in 1.6.55-r0 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-28387 | MEDIUM6.88 | libssl3 3.5.0-r0 fixed in 3.5.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-50106 | MEDIUM6.88 | openjdk17 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-50106 | MEDIUM6.88 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-50106 | MEDIUM6.88 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-54512 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.17.0 fixed in 2.18.8, 3.1.4, 2.21.4 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-54513 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.17.0 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-44249 | MEDIUM6.88 | io.netty:netty-handler 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-45674 | MEDIUM6.8 | io.netty:netty-resolver-dns 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.2% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-47691 | MEDIUM6.8 | io.netty:netty-resolver-dns 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-42581 | MEDIUM6.66 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.6% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-22801 | MEDIUM6.63 | libpng 1.6.47-r0 fixed in 1.6.54-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-40200 | MEDIUM6.63 | musl 1.2.5-r10 fixed in 1.2.5-r12 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-22184 | MEDIUM6.63 | zlib 1.3.1-r2 fixed in 1.3.2-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2020-7019 | MEDIUM6.5 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.9.0, 6.8.12 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2021-22144 | MEDIUM6.5 | org.elasticsearch:elasticsearch 2.4.3 fixed in 6.8.17, 7.13.3 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-33636 | MEDIUM6.46 | libpng 1.6.47-r0 fixed in 1.6.56-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-41254 | MEDIUM6.38 | lcms2 2.16-r0 fixed in 2.19-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69421 | MEDIUM6.38 | libcrypto3 3.5.0-r0 fixed in 3.5.5-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-69421 | MEDIUM6.38 | libssl3 3.5.0-r0 fixed in 3.5.5-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-27135 | MEDIUM6.38 | nghttp2-libs 1.65.0-r0 fixed in 1.68.1 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-21945 | MEDIUM6.38 | openjdk17 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-22016 | MEDIUM6.38 | openjdk17 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-34282 | MEDIUM6.38 | openjdk17 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-21945 | MEDIUM6.38 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-22016 | MEDIUM6.38 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-34282 | MEDIUM6.38 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-21945 | MEDIUM6.38 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-22016 | MEDIUM6.38 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-34282 | MEDIUM6.38 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-7962 | MEDIUM6.38 | com.sun.mail:jakarta.mail 1.6.7 fixed in 1.6.8, 2.0.2 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-42583 | MEDIUM6.38 | io.netty:netty-codec 4.1.119.Final fixed in 4.1.133.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59901 | MEDIUM6.38 | io.netty:netty-codec 4.1.119.Final fixed in 4.1.136.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-58057 | MEDIUM6.38 | io.netty:netty-codec 4.1.119.Final fixed in 4.1.125.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-33870 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.1.132.Final, 4.2.10.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42587 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.13.Final, 4.1.133.Final | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-55831 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-55833 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-56745 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42585 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-56746 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59899 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-58056 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.1.125.Final, 4.2.5.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42587 | MEDIUM6.38 | io.netty:netty-codec-http2 4.1.119.Final fixed in 4.2.13.Final, 4.1.133.Final | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-56819 | MEDIUM6.38 | io.netty:netty-codec-http2 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-48043 | MEDIUM6.38 | io.netty:netty-codec-http2 4.1.119.Final fixed in 4.1.135.Final, 4.2.15.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-45416 | MEDIUM6.38 | io.netty:netty-handler 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-50010 | MEDIUM6.38 | io.netty:netty-handler 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42578 | MEDIUM6.38 | io.netty:netty-handler-proxy 4.1.119.Final fixed in 4.1.133.Final, 4.2.13.Final | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2024-57699 | MEDIUM6.38 | net.minidev:json-smart 2.5.0 fixed in 2.5.2 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-3505 | MEDIUM6.38 | org.bouncycastle:bcpg-jdk15to18 1.78.1 fixed in 1.84 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-5588 | MEDIUM6.38 | org.bouncycastle:bcpkix-jdk15to18 1.78.1 fixed in 1.84 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-5588 | MEDIUM6.38 | org.bouncycastle:bcpkix-jdk18on 1.78.1 fixed in 1.84 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-14813 | MEDIUM6.38 | org.bouncycastle:bcprov-jdk15to18 1.78.1 fixed in 1.84 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-5598 | MEDIUM6.38 | org.bouncycastle:bcprov-jdk15to18 1.78.1 fixed in 1.80.2 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-14813 | MEDIUM6.38 | org.bouncycastle:bcprov-jdk18on 1.78.1 fixed in 1.80.2, 1.81.1, 1.84 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-64518 | MEDIUM6.38 | org.cyclonedx:cyclonedx-core-java 9.1.0 fixed in 11.0.1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-1605 | MEDIUM6.38 | org.eclipse.jetty:jetty-server 12.0.17 fixed in 12.1.6, 12.0.32 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-10051 | MEDIUM6.38 | org.eclipse.jetty:jetty-server 12.0.17 fixed in 12.0.36, 12.1.10 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2024-23444 | MEDIUM6.38 | org.elasticsearch:elasticsearch 2.4.3 fixed in 8.13.0, 7.17.23 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-43709 | MEDIUM6.38 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.17.21, 8.13.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2024-52979 | MEDIUM6.38 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.17.25, 8.16.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-7307 | MEDIUM6.38 | org.keycloak:keycloak-saml-core 18.0.2 fixed in 26.6.2 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-42198 | MEDIUM6.38 | org.postgresql:postgresql 42.7.2 fixed in 42.7.11 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-41249 | MEDIUM6.38 | org.springframework:spring-core 6.1.15 fixed in 6.2.11 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-41848 | MEDIUM6.38 | org.springframework:spring-core 6.1.15 fixed in 7.0.8, 6.2.19 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-41851 | MEDIUM6.38 | org.springframework:spring-expression 6.1.15 fixed in 7.0.8, 6.2.19 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69419 | MEDIUM6.29 | libcrypto3 3.5.0-r0 fixed in 3.5.5-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-34182 | MEDIUM6.29 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69419 | MEDIUM6.29 | libssl3 3.5.0-r0 fixed in 3.5.5-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-34182 | MEDIUM6.29 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-21932 | MEDIUM6.29 | openjdk17 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-21932 | MEDIUM6.29 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-21932 | MEDIUM6.29 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-22235 | MEDIUM6.21 | org.springframework.boot:spring-boot 3.3.6 fixed in 3.3.11, 3.4.5 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42579 | MEDIUM6.18 | io.netty:netty-codec-dns 4.1.119.Final fixed in 4.2.13.Final, 4.1.133.Final | 1.0% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-42584 | MEDIUM6.18 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.8% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2025-11187 | MEDIUM6.1 | libcrypto3 3.5.0-r0 fixed in 3.5.5-r0 | 4.5% Low-Moderate Risk | Directly Exposed |
| CVE-2025-11187 | MEDIUM6.1 | libssl3 3.5.0-r0 fixed in 3.5.5-r0 | 4.5% Low-Moderate Risk | Directly Exposed |
| CVE-2025-64720 | MEDIUM6.03 | libpng 1.6.47-r0 fixed in 1.6.51-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-65018 | MEDIUM6.03 | libpng 1.6.47-r0 fixed in 1.6.51-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-66293 | MEDIUM6.03 | libpng 1.6.47-r0 fixed in 1.6.53-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-22695 | MEDIUM6.03 | libpng 1.6.47-r0 fixed in 1.6.54-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-40973 | MEDIUM5.95 | org.springframework.boot:spring-boot 3.3.6 fixed in 4.0.6, 3.5.14 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-9231 | MEDIUM5.9 | libcrypto3 3.5.0-r0 fixed in 3.5.4-r0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-31790 | MEDIUM5.9 | libcrypto3 3.5.0-r0 fixed in 3.5.6-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-42764 | MEDIUM5.9 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-9231 | MEDIUM5.9 | libssl3 3.5.0-r0 fixed in 3.5.4-r0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-31790 | MEDIUM5.9 | libssl3 3.5.0-r0 fixed in 3.5.6-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-42764 | MEDIUM5.9 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-13151 | MEDIUM5.9 | libtasn1 4.20.0-r0 fixed in 4.21.0-r0 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2019-7614 | MEDIUM5.9 | org.elasticsearch:elasticsearch 2.4.3 fixed in 6.8.2, 7.2.1 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-45673 | MEDIUM5.78 | io.netty:netty-resolver-dns 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-9230 | MEDIUM5.6 | libcrypto3 3.5.0-r0 fixed in 3.5.4-r0 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2025-9230 | MEDIUM5.6 | libssl3 3.5.0-r0 fixed in 3.5.4-r0 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2026-2673 | MEDIUM5.52 | libcrypto3 3.5.0-r0 fixed in 3.5.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-2673 | MEDIUM5.52 | libssl3 3.5.0-r0 fixed in 3.5.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59888 | MEDIUM5.52 | com.fasterxml.jackson.core:jackson-databind 2.17.0 fixed in 2.18.8, 2.21.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-67735 | MEDIUM5.52 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.8.Final, 4.1.129.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-41417 | MEDIUM5.52 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.1.133.Final, 4.2.13.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42580 | MEDIUM5.52 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59900 | MEDIUM5.52 | io.netty:netty-codec-http2 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-43827 | MEDIUM5.52 | org.apache.shiro:shiro-core 1.13.0 fixed in 2.2.0, 3.0.0-alpha-2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-43828 | MEDIUM5.52 | org.apache.shiro:shiro-web 1.13.0 fixed in 2.2.0, 3.0.0-alpha-2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-0636 | MEDIUM5.52 | org.bouncycastle:bcprov-jdk15to18 1.78.1 fixed in 1.84 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-0636 | MEDIUM5.52 | org.bouncycastle:bcprov-jdk18on 1.78.1 fixed in 1.84 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-11143 | MEDIUM5.52 | org.eclipse.jetty:jetty-http 12.0.17 fixed in 12.0.31, 12.1.5 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2023-49921 | MEDIUM5.52 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.17.16, 8.11.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-11226 | MEDIUM5.44 | ch.qos.logback:logback-core 1.5.16 fixed in 1.5.19, 1.3.16 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-34181 | MEDIUM5.35 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42768 | MEDIUM5.35 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-34181 | MEDIUM5.35 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42768 | MEDIUM5.35 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2021-22135 | MEDIUM5.3 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.11.2, 6.8.15 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2021-22137 | MEDIUM5.3 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.11.2, 6.8.15 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2025-9341 | MEDIUM5.27 | org.bouncycastle:bc-fips 2.1.0 fixed in 2.1.1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-64506 | MEDIUM5.18 | libpng 1.6.47-r0 fixed in 1.6.51-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-21933 | MEDIUM5.18 | openjdk17 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-21933 | MEDIUM5.18 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-21933 | MEDIUM5.18 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-22227 | MEDIUM5.18 | io.projectreactor.netty:reactor-netty-http 1.0.39 fixed in 1.3.0-M5, 1.2.8 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2018-3824 | MEDIUM5.18 | org.elasticsearch:elasticsearch 2.4.3 fixed in 5.6.9, 6.2.4 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2025-62408 | MEDIUM5.02 | c-ares 1.34.5-r0 fixed in 1.34.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-15468 | MEDIUM5.02 | libcrypto3 3.5.0-r0 fixed in 3.5.5-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-66199 | MEDIUM5.02 | libcrypto3 3.5.0-r0 fixed in 3.5.5-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69420 | MEDIUM5.02 | libcrypto3 3.5.0-r0 fixed in 3.5.5-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-22796 | MEDIUM5.02 | libcrypto3 3.5.0-r0 fixed in 3.5.5-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-42769 | MEDIUM5.02 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42770 | MEDIUM5.02 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-9076 | MEDIUM5.02 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-15468 | MEDIUM5.02 | libssl3 3.5.0-r0 fixed in 3.5.5-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-66199 | MEDIUM5.02 | libssl3 3.5.0-r0 fixed in 3.5.5-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69420 | MEDIUM5.02 | libssl3 3.5.0-r0 fixed in 3.5.5-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-22796 | MEDIUM5.02 | libssl3 3.5.0-r0 fixed in 3.5.5-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-42769 | MEDIUM5.02 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42770 | MEDIUM5.02 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-9076 | MEDIUM5.02 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-53057 | MEDIUM5.02 | openjdk17 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-53057 | MEDIUM5.02 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-53057 | MEDIUM5.02 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-9340 | MEDIUM5.02 | org.bouncycastle:bc-fips 2.1.0 fixed in 2.1.1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-41850 | MEDIUM5.02 | org.springframework:spring-expression 6.1.15 fixed in 7.0.8, 6.2.19 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-34180 | MEDIUM5 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-34180 | MEDIUM5 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2020-7021 | MEDIUM4.9 | org.elasticsearch:elasticsearch 2.4.3 fixed in 6.8.14, 7.10.0 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-59921 | MEDIUM4.84 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-15469 | MEDIUM4.67 | libcrypto3 3.5.0-r0 fixed in 3.5.5-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-22795 | MEDIUM4.67 | libcrypto3 3.5.0-r0 fixed in 3.5.5-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-7383 | MEDIUM4.67 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-15469 | MEDIUM4.67 | libssl3 3.5.0-r0 fixed in 3.5.5-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-22795 | MEDIUM4.67 | libssl3 3.5.0-r0 fixed in 3.5.5-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-7383 | MEDIUM4.67 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-6042 | MEDIUM4.67 | musl 1.2.5-r10 fixed in 1.2.5-r11 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-27171 | MEDIUM4.67 | zlib 1.3.1-r2 fixed in 1.3.2-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42766 | MEDIUM4.5 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-42767 | MEDIUM4.5 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42766 | MEDIUM4.5 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-42767 | MEDIUM4.5 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-22013 | MEDIUM4.5 | openjdk17 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-22021 | MEDIUM4.5 | openjdk17 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-23865 | MEDIUM4.5 | openjdk17 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-22013 | MEDIUM4.5 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-22021 | MEDIUM4.5 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-23865 | MEDIUM4.5 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-22013 | MEDIUM4.5 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-22021 | MEDIUM4.5 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-23865 | MEDIUM4.5 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-54514 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.17.0 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-54515 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.17.0 fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-50020 | MEDIUM4.5 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-59898 | MEDIUM4.5 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-47244 | MEDIUM4.5 | io.netty:netty-codec-http2 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-50560 | MEDIUM4.5 | io.netty:netty-codec-http2 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-8916 | MEDIUM4.5 | org.bouncycastle:bcpkix-jdk15to18 1.78.1 fixed in 1.79 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-8916 | MEDIUM4.5 | org.bouncycastle:bcpkix-jdk18on 1.78.1 fixed in 1.79 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-2575 | MEDIUM4.5 | org.keycloak:keycloak-saml-adapter-core 18.0.2 fixed in 26.5.4 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-2575 | MEDIUM4.5 | org.keycloak:keycloak-saml-core 18.0.2 fixed in 26.5.4 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-41852 | MEDIUM4.5 | org.springframework:spring-expression 6.1.15 fixed in 7.0.8, 6.2.19 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-47554 | MEDIUM4.3 | commons-io:commons-io 2.8.0 fixed in 2.14.0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-1225 | MEDIUM4.25 | ch.qos.logback:logback-core 1.5.16 fixed in 1.5.25 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-50106 | MEDIUM4.13 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-28387 | MEDIUM4.13 | openssl 3.5.0-r0 fixed in 3.5.6-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2025-30754 | MEDIUM4.08 | openjdk17 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-53066 | MEDIUM4.08 | openjdk17 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-21925 | MEDIUM4.08 | openjdk17 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-30754 | MEDIUM4.08 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-53066 | MEDIUM4.08 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-21925 | MEDIUM4.08 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-30754 | MEDIUM4.08 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-53066 | MEDIUM4.08 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-21925 | MEDIUM4.08 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-15467 | MEDIUM4.06 | libcrypto3 3.5.0-r0 fixed in 3.5.5-r0 | 47.6% High Exploitation Risk | Post-Exploit |
| CVE-2025-15467 | MEDIUM4.06 | libssl3 3.5.0-r0 fixed in 3.5.5-r0 | 47.6% High Exploitation Risk | Post-Exploit |
| CVE-2025-15467 | MEDIUM4.06 | openssl 3.5.0-r0 fixed in 3.5.5-r0 | 47.6% High Exploitation Risk | Post-Exploit |
| CVE-2025-68160 | MEDIUM4 | libcrypto3 3.5.0-r0 fixed in 3.5.5-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-68160 | MEDIUM4 | libssl3 3.5.0-r0 fixed in 3.5.5-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-40200 | LOW3.98 | musl-utils 1.2.5-r10 fixed in 1.2.5-r12 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-21945 | LOW3.82 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2026-22016 | LOW3.82 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-34282 | LOW3.82 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-69421 | LOW3.82 | openssl 3.5.0-r0 fixed in 3.5.5-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-21932 | LOW3.77 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-69419 | LOW3.77 | openssl 3.5.0-r0 fixed in 3.5.5-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-34182 | LOW3.77 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-64505 | LOW3.74 | libpng 1.6.47-r0 fixed in 1.6.51-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-34757 | LOW3.74 | libpng 1.6.47-r0 fixed in 1.6.57-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-48924 | LOW3.7 | org.apache.commons:commons-lang3 3.13.0 fixed in 3.18.0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-11187 | LOW3.66 | openssl 3.5.0-r0 fixed in 3.5.5-r0 | 4.5% Low-Moderate Risk | Post-Exploit |
| CVE-2025-9231 | LOW3.54 | openssl 3.5.0-r0 fixed in 3.5.4-r0 | 2.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-31790 | LOW3.54 | openssl 3.5.0-r0 fixed in 3.5.6-r0 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-42764 | LOW3.54 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2025-69418 | LOW3.4 | libcrypto3 3.5.0-r0 fixed in 3.5.5-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-69418 | LOW3.4 | libssl3 3.5.0-r0 fixed in 3.5.5-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-45536 | LOW3.4 | io.netty:netty-transport-native-epoll 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-45536 | LOW3.4 | io.netty:netty-transport-native-kqueue 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-12194 | LOW3.4 | org.bouncycastle:bc-fips 2.1.0 fixed in 2.1.2 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-9230 | LOW3.36 | openssl 3.5.0-r0 fixed in 3.5.4-r0 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2026-5545 | LOW3.31 | curl 8.14.1-r0 fixed in 8.14.1-r3 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-5545 | LOW3.31 | libcurl 8.14.1-r0 fixed in 8.14.1-r3 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-2673 | LOW3.31 | openssl 3.5.0-r0 fixed in 3.5.6-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-34181 | LOW3.21 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-42768 | LOW3.21 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-9086 | LOW3.18 | curl 8.14.1-r0 fixed in 8.14.1-r2 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2025-9086 | LOW3.18 | libcurl 8.14.1-r0 fixed in 8.14.1-r2 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2026-45446 | LOW3.15 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-45446 | LOW3.15 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-22018 | LOW3.15 | openjdk17 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-22018 | LOW3.15 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-22018 | LOW3.15 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-21933 | LOW3.11 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2025-9232 | LOW3.1 | libcrypto3 3.5.0-r0 fixed in 3.5.4-r0 | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2025-9232 | LOW3.1 | libssl3 3.5.0-r0 fixed in 3.5.4-r0 | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2020-7020 | LOW3.1 | org.elasticsearch:elasticsearch 2.4.3 fixed in 6.8.13, 7.9.2 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2025-53057 | LOW3.01 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-15468 | LOW3.01 | openssl 3.5.0-r0 fixed in 3.5.5-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2025-66199 | LOW3.01 | openssl 3.5.0-r0 fixed in 3.5.5-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-69420 | LOW3.01 | openssl 3.5.0-r0 fixed in 3.5.5-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-22796 | LOW3.01 | openssl 3.5.0-r0 fixed in 3.5.5-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-42769 | LOW3.01 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-42770 | LOW3.01 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-9076 | LOW3.01 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-31789 | LOW3 | libcrypto3 3.5.0-r0 fixed in 3.5.6-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-31789 | LOW3 | libssl3 3.5.0-r0 fixed in 3.5.6-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-31789 | LOW3 | openssl 3.5.0-r0 fixed in 3.5.6-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-34180 | LOW3 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-45447 | LOW2.92 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 5.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-45447 | LOW2.92 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 5.2% Low-Moderate Risk | Post-Exploit |
| CVE-2025-30749 | LOW2.92 | openjdk17 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2025-30749 | LOW2.92 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2025-30749 | LOW2.92 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2025-30749 | LOW2.92 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-45447 | LOW2.92 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 5.2% Low-Moderate Risk | Post-Exploit |
| CVE-2019-7611 | LOW2.92 | org.elasticsearch:elasticsearch 2.4.3 fixed in 5.6.15, 6.6.1 | 2.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-6042 | LOW2.8 | musl-utils 1.2.5-r10 fixed in 1.2.5-r11 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-15469 | LOW2.8 | openssl 3.5.0-r0 fixed in 3.5.5-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-22795 | LOW2.8 | openssl 3.5.0-r0 fixed in 3.5.5-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-7383 | LOW2.8 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-45445 | LOW2.78 | libcrypto3 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-45445 | LOW2.78 | libssl3 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-45445 | LOW2.78 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-28388 | LOW2.7 | openssl 3.5.0-r0 fixed in 3.5.6-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28389 | LOW2.7 | openssl 3.5.0-r0 fixed in 3.5.6-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28390 | LOW2.7 | openssl 3.5.0-r0 fixed in 3.5.6-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-34183 | LOW2.7 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-22013 | LOW2.7 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-22021 | LOW2.7 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-23865 | LOW2.7 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-42766 | LOW2.7 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 1.0% Theoretical Threat | Post-Exploit |
| CVE-2026-42767 | LOW2.7 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-50059 | LOW2.63 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-22007 | LOW2.46 | openjdk17 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-34268 | LOW2.46 | openjdk17 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-22007 | LOW2.46 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-34268 | LOW2.46 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-22007 | LOW2.46 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-34268 | LOW2.46 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-10148 | LOW2.45 | curl 8.14.1-r0 fixed in 8.14.1-r2 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-10148 | LOW2.45 | libcurl 8.14.1-r0 fixed in 8.14.1-r2 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-30754 | LOW2.45 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-53066 | LOW2.45 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-21925 | LOW2.45 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-68160 | LOW2.4 | openssl 3.5.0-r0 fixed in 3.5.5-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-23901 | LOW2.12 | org.apache.shiro:shiro-core 1.13.0 fixed in 2.1.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69418 | LOW2.04 | openssl 3.5.0-r0 fixed in 3.5.5-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-22018 | LOW1.89 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-45446 | LOW1.89 | openssl 3.5.0-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-9232 | LOW1.86 | openssl 3.5.0-r0 fixed in 3.5.4-r0 | 2.3% Low-Moderate Risk | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | busybox 1.37.0-r18 fixed in 1.37.0-r20 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | busybox-binsh 1.37.0-r18 fixed in 1.37.0-r20 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | ssl_client 1.37.0-r18 fixed in 1.37.0-r20 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-9092 | LOW1.53 | org.bouncycastle:bc-fips 2.1.0 fixed in 2.1.1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-22007 | LOW1.48 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-34268 | LOW1.48 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2025-50059 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-50059 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-50059 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-30749 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2025-50106 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-30749 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2025-50106 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2025-30749 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2025-50106 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-21945 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2026-22016 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-34282 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-21945 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2026-22016 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-34282 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-21945 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2026-22016 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-34282 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-21932 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-21932 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-21932 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-21933 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-21933 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-21933 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-53057 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-53057 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-53057 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-22013 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-22021 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-23865 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-22013 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-22021 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-23865 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-22013 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-22021 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-23865 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2025-30754 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-53066 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-21925 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-30754 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-53066 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-21925 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-30754 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-53066 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-21925 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-22018 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-22018 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-22018 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-48924 | NONE0 | commons-lang:commons-lang 2.6 No fix yet | 2.2% Low-Moderate Risk | Not Applicable |
| CVE-2026-22007 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-34268 | NONE0 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-22007 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-34268 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-22007 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-34268 | NONE0 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | busybox 1.37.0-r18 fixed in 1.37.0-r20 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | busybox-binsh 1.37.0-r18 fixed in 1.37.0-r20 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-4575 | NONE0 | libcrypto3 3.5.0-r0 fixed in 3.5.1-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-4575 | NONE0 | libssl3 3.5.0-r0 fixed in 3.5.1-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-4575 | NONE0 | openssl 3.5.0-r0 fixed in 3.5.1-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | ssl_client 1.37.0-r18 fixed in 1.37.0-r20 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-10532 | NONE0 | ch.qos.logback:logback-core 1.5.16 fixed in 1.5.34 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-9828 | NONE0 | ch.qos.logback:logback-core 1.5.16 fixed in 1.5.33 | 0.4% Theoretical Threat | Not Applicable |
| GHSA-r7wm-3cxj-wff9 | NONE0 | com.fasterxml.jackson.core:jackson-core 2.17.0 fixed in 2.18.8, 2.21.4, 2.22.1 | — | Not Applicable |
| GHSA-72hv-8253-57qq | NONE0 | com.fasterxml.jackson.core:jackson-core 2.17.0 fixed in 2.21.1, 2.18.6 | — | Not Applicable |
| GHSA-mfg7-5gfp-c4w3 | NONE0 | io.netty:netty-codec-dns 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | — | Not Applicable |
| CVE-2026-10050 | NONE0 | org.eclipse.jetty.ee8:jetty-ee8-security 12.0.17 fixed in 12.0.36, 12.1.10 | — | Not Applicable |
| CVE-2026-10050 | NONE0 | org.eclipse.jetty:jetty-security 12.0.17 fixed in 9.4.63, 10.0.31, 11.0.31, 12.0.36, 12.1.10 | — | Not Applicable |
| CVE-2026-6790 | NONE0 | org.eclipse.jetty:jetty-server 12.0.17 fixed in 12.0.35, 12.1.9 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-8384 | NONE0 | org.eclipse.jetty:jetty-util 12.0.17 fixed in 12.0.35, 12.1.9 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-22233 | NONE0 | org.springframework:spring-context 6.1.15 fixed in 6.2.7, 6.1.20 | 0.4% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.