Last scanned:
This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could achieve remote code execution on the Nexus server via crafted PDFs exploiting CVE-2025-66516, or bypass access controls through HTTP request smuggling via CVE-2026-2332. The container exposes 298 vulnerabilities overall, with 29 rated 7.0 or higher, and the most severe (10.0) is directly applicable to artifact upload processing. While the image is from a trusted publisher and pinned by digest, the exposed attack surface is far too high for production use. Some OpenSSL findings require specific API usage, but the critical Tika and Jetty issues do not.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2025-66516 | CRITICAL10 | org.apache.tika:tika-core 1.28.4 fixed in 3.2.2 | 78.8% Actively Exploited | Directly ExposedContext importance: HIGH |
| CVE-2026-2332 | CRITICAL9.1 | org.eclipse.jetty:jetty-http 12.0.17 fixed in 12.1.7, 12.0.33 | 1.1% Low-Moderate Risk | Directly ExposedContext importance: HIGH |
| CVE-2026-45445 | HIGH7.73 | libcrypto3 3.5.1-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-45445 | HIGH7.73 | libssl3 3.5.1-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42584 | HIGH7.73 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-49268 | HIGH7.73 | org.apache.shiro:shiro-core 1.13.0 fixed in 2.2.1, 3.0.0-alpha-2 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2024-8698 | HIGH7.7 | org.keycloak:keycloak-saml-core 18.0.2 fixed in 22.0.13, 24.0.8, 25.0.6 | 2.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-33630 | HIGH7.5 | c-ares 1.34.5-r0 fixed in 1.34.8-r0 | — | Directly Exposed |
| CVE-2026-28388 | HIGH7.5 | libcrypto3 3.5.1-r0 fixed in 3.5.6-r0 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28389 | HIGH7.5 | libcrypto3 3.5.1-r0 fixed in 3.5.6-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28390 | HIGH7.5 | libcrypto3 3.5.1-r0 fixed in 3.5.6-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-34183 | HIGH7.5 | libcrypto3 3.5.1-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-33416 | HIGH7.5 | libpng 1.6.47-r0 fixed in 1.6.56-r0 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28388 | HIGH7.5 | libssl3 3.5.1-r0 fixed in 3.5.6-r0 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28389 | HIGH7.5 | libssl3 3.5.1-r0 fixed in 3.5.6-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-28390 | HIGH7.5 | libssl3 3.5.1-r0 fixed in 3.5.6-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-34183 | HIGH7.5 | libssl3 3.5.1-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-2100 | HIGH7.5 | p11-kit 0.25.5-r2 fixed in 0.26.2-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-2100 | HIGH7.5 | p11-kit-trust 0.25.5-r2 fixed in 0.26.2-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-55163 | HIGH7.5 | io.netty:netty-codec-http2 4.1.119.Final fixed in 4.2.4.Final, 4.1.124.Final | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-33871 | HIGH7.5 | io.netty:netty-codec-http2 4.1.119.Final fixed in 4.1.132.Final, 4.2.11.Final | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2023-31418 | HIGH7.5 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.17.13, 8.9.0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-67030 | HIGH7.48 | org.codehaus.plexus:plexus-utils 3.5.1 fixed in 4.0.3, 3.6.1 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-50059 | HIGH7.31 | openjdk17 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-50059 | HIGH7.31 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-50059 | HIGH7.31 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-50059 | HIGH7.31 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-50059 | HIGH7.31 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-50059 | HIGH7.31 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-28387 | MEDIUM6.88 | libcrypto3 3.5.1-r0 fixed in 3.5.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-25646 | MEDIUM6.88 | libpng 1.6.47-r0 fixed in 1.6.55-r0 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-28387 | MEDIUM6.88 | libssl3 3.5.1-r0 fixed in 3.5.6-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-50106 | MEDIUM6.88 | openjdk17 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-50106 | MEDIUM6.88 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-50106 | MEDIUM6.88 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-50106 | MEDIUM6.88 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-50106 | MEDIUM6.88 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-50106 | MEDIUM6.88 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-54512 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.17.0 fixed in 2.18.8, 3.1.4, 2.21.4 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-54513 | MEDIUM6.88 | com.fasterxml.jackson.core:jackson-databind 2.17.0 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-44249 | MEDIUM6.88 | io.netty:netty-handler 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-45674 | MEDIUM6.8 | io.netty:netty-resolver-dns 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.2% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-47691 | MEDIUM6.8 | io.netty:netty-resolver-dns 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-22801 | MEDIUM6.63 | libpng 1.6.47-r0 fixed in 1.6.54-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-40200 | MEDIUM6.63 | musl 1.2.5-r10 fixed in 1.2.5-r12 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-40200 | MEDIUM6.63 | musl-utils 1.2.5-r10 fixed in 1.2.5-r12 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-22184 | MEDIUM6.63 | zlib 1.3.1-r2 fixed in 1.3.2-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2020-7019 | MEDIUM6.5 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.9.0, 6.8.12 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2021-22144 | MEDIUM6.5 | org.elasticsearch:elasticsearch 2.4.3 fixed in 6.8.17, 7.13.3 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-33636 | MEDIUM6.46 | libpng 1.6.47-r0 fixed in 1.6.56-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-41254 | MEDIUM6.38 | lcms2 2.16-r0 fixed in 2.19-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69421 | MEDIUM6.38 | libcrypto3 3.5.1-r0 fixed in 3.5.5-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-69421 | MEDIUM6.38 | libssl3 3.5.1-r0 fixed in 3.5.5-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-27135 | MEDIUM6.38 | nghttp2-libs 1.65.0-r0 fixed in 1.68.1 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-21945 | MEDIUM6.38 | openjdk17 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-22016 | MEDIUM6.38 | openjdk17 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-34282 | MEDIUM6.38 | openjdk17 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-21945 | MEDIUM6.38 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-22016 | MEDIUM6.38 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-34282 | MEDIUM6.38 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-21945 | MEDIUM6.38 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-22016 | MEDIUM6.38 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-34282 | MEDIUM6.38 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-21945 | MEDIUM6.38 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-22016 | MEDIUM6.38 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-34282 | MEDIUM6.38 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-21945 | MEDIUM6.38 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-22016 | MEDIUM6.38 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-34282 | MEDIUM6.38 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-21945 | MEDIUM6.38 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2026-22016 | MEDIUM6.38 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-34282 | MEDIUM6.38 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-7962 | MEDIUM6.38 | com.sun.mail:jakarta.mail 1.6.7 fixed in 1.6.8, 2.0.2 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-42583 | MEDIUM6.38 | io.netty:netty-codec 4.1.119.Final fixed in 4.1.133.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59901 | MEDIUM6.38 | io.netty:netty-codec 4.1.119.Final fixed in 4.1.136.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-58057 | MEDIUM6.38 | io.netty:netty-codec 4.1.119.Final fixed in 4.1.125.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-33870 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.1.132.Final, 4.2.10.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42587 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.13.Final, 4.1.133.Final | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-55831 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-55833 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-56745 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42585 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-56746 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59899 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-58056 | MEDIUM6.38 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.1.125.Final, 4.2.5.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42587 | MEDIUM6.38 | io.netty:netty-codec-http2 4.1.119.Final fixed in 4.2.13.Final, 4.1.133.Final | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-56819 | MEDIUM6.38 | io.netty:netty-codec-http2 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-48043 | MEDIUM6.38 | io.netty:netty-codec-http2 4.1.119.Final fixed in 4.1.135.Final, 4.2.15.Final | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-45416 | MEDIUM6.38 | io.netty:netty-handler 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-50010 | MEDIUM6.38 | io.netty:netty-handler 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42578 | MEDIUM6.38 | io.netty:netty-handler-proxy 4.1.119.Final fixed in 4.1.133.Final, 4.2.13.Final | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-3505 | MEDIUM6.38 | org.bouncycastle:bcpg-jdk15to18 1.78.1 fixed in 1.84 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-5588 | MEDIUM6.38 | org.bouncycastle:bcpkix-jdk15to18 1.78.1 fixed in 1.84 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-5588 | MEDIUM6.38 | org.bouncycastle:bcpkix-jdk18on 1.78.1 fixed in 1.84 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-14813 | MEDIUM6.38 | org.bouncycastle:bcprov-jdk15to18 1.78.1 fixed in 1.84 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-5598 | MEDIUM6.38 | org.bouncycastle:bcprov-jdk15to18 1.78.1 fixed in 1.80.2 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-14813 | MEDIUM6.38 | org.bouncycastle:bcprov-jdk18on 1.78.1 fixed in 1.80.2, 1.81.1, 1.84 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-64518 | MEDIUM6.38 | org.cyclonedx:cyclonedx-core-java 9.1.0 fixed in 11.0.1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2024-23444 | MEDIUM6.38 | org.elasticsearch:elasticsearch 2.4.3 fixed in 8.13.0, 7.17.23 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-43709 | MEDIUM6.38 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.17.21, 8.13.3 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2024-52979 | MEDIUM6.38 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.17.25, 8.16.0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-7307 | MEDIUM6.38 | org.keycloak:keycloak-saml-core 18.0.2 fixed in 26.6.2 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2026-42198 | MEDIUM6.38 | org.postgresql:postgresql 42.7.2 fixed in 42.7.11 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2025-41249 | MEDIUM6.38 | org.springframework:spring-core 6.1.15 fixed in 6.2.11 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-41848 | MEDIUM6.38 | org.springframework:spring-core 6.1.15 fixed in 7.0.8, 6.2.19 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-41851 | MEDIUM6.38 | org.springframework:spring-expression 6.1.15 fixed in 7.0.8, 6.2.19 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69419 | MEDIUM6.29 | libcrypto3 3.5.1-r0 fixed in 3.5.5-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-34182 | MEDIUM6.29 | libcrypto3 3.5.1-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69419 | MEDIUM6.29 | libssl3 3.5.1-r0 fixed in 3.5.5-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-34182 | MEDIUM6.29 | libssl3 3.5.1-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-21932 | MEDIUM6.29 | openjdk17 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-21932 | MEDIUM6.29 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-21932 | MEDIUM6.29 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-21932 | MEDIUM6.29 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-21932 | MEDIUM6.29 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-21932 | MEDIUM6.29 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-22235 | MEDIUM6.21 | org.springframework.boot:spring-boot 3.3.6 fixed in 3.3.11, 3.4.5 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42579 | MEDIUM6.18 | io.netty:netty-codec-dns 4.1.119.Final fixed in 4.2.13.Final, 4.1.133.Final | 1.0% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2025-11187 | MEDIUM6.1 | libcrypto3 3.5.1-r0 fixed in 3.5.5-r0 | 4.5% Low-Moderate Risk | Directly Exposed |
| CVE-2025-11187 | MEDIUM6.1 | libssl3 3.5.1-r0 fixed in 3.5.5-r0 | 4.5% Low-Moderate Risk | Directly Exposed |
| CVE-2025-64720 | MEDIUM6.03 | libpng 1.6.47-r0 fixed in 1.6.51-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-65018 | MEDIUM6.03 | libpng 1.6.47-r0 fixed in 1.6.51-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-66293 | MEDIUM6.03 | libpng 1.6.47-r0 fixed in 1.6.53-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-22695 | MEDIUM6.03 | libpng 1.6.47-r0 fixed in 1.6.54-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-40973 | MEDIUM5.95 | org.springframework.boot:spring-boot 3.3.6 fixed in 4.0.6, 3.5.14 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-9231 | MEDIUM5.9 | libcrypto3 3.5.1-r0 fixed in 3.5.4-r0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-31790 | MEDIUM5.9 | libcrypto3 3.5.1-r0 fixed in 3.5.6-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-42764 | MEDIUM5.9 | libcrypto3 3.5.1-r0 fixed in 3.5.7-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-9231 | MEDIUM5.9 | libssl3 3.5.1-r0 fixed in 3.5.4-r0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-31790 | MEDIUM5.9 | libssl3 3.5.1-r0 fixed in 3.5.6-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-42764 | MEDIUM5.9 | libssl3 3.5.1-r0 fixed in 3.5.7-r0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-13151 | MEDIUM5.9 | libtasn1 4.20.0-r0 fixed in 4.21.0-r0 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2019-7614 | MEDIUM5.9 | org.elasticsearch:elasticsearch 2.4.3 fixed in 6.8.2, 7.2.1 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-45673 | MEDIUM5.78 | io.netty:netty-resolver-dns 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-9230 | MEDIUM5.6 | libcrypto3 3.5.1-r0 fixed in 3.5.4-r0 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2025-9230 | MEDIUM5.6 | libssl3 3.5.1-r0 fixed in 3.5.4-r0 | 1.7% Low-Moderate Risk | Directly Exposed |
| CVE-2026-2673 | MEDIUM5.52 | libcrypto3 3.5.1-r0 fixed in 3.5.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-2673 | MEDIUM5.52 | libssl3 3.5.1-r0 fixed in 3.5.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59888 | MEDIUM5.52 | com.fasterxml.jackson.core:jackson-databind 2.17.0 fixed in 2.18.8, 2.21.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-67735 | MEDIUM5.52 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.8.Final, 4.1.129.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-41417 | MEDIUM5.52 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.1.133.Final, 4.2.13.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-42580 | MEDIUM5.52 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-59900 | MEDIUM5.52 | io.netty:netty-codec-http2 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-43827 | MEDIUM5.52 | org.apache.shiro:shiro-core 1.13.0 fixed in 2.2.0, 3.0.0-alpha-2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-43828 | MEDIUM5.52 | org.apache.shiro:shiro-web 1.13.0 fixed in 2.2.0, 3.0.0-alpha-2 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-0636 | MEDIUM5.52 | org.bouncycastle:bcprov-jdk15to18 1.78.1 fixed in 1.84 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-0636 | MEDIUM5.52 | org.bouncycastle:bcprov-jdk18on 1.78.1 fixed in 1.84 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-11143 | MEDIUM5.52 | org.eclipse.jetty:jetty-http 12.0.17 fixed in 12.0.31, 12.1.5 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2023-49921 | MEDIUM5.52 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.17.16, 8.11.2 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-11226 | MEDIUM5.44 | ch.qos.logback:logback-core 1.5.16 fixed in 1.5.19, 1.3.16 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-34181 | MEDIUM5.35 | libcrypto3 3.5.1-r0 fixed in 3.5.7-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42768 | MEDIUM5.35 | libcrypto3 3.5.1-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-34181 | MEDIUM5.35 | libssl3 3.5.1-r0 fixed in 3.5.7-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42768 | MEDIUM5.35 | libssl3 3.5.1-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2021-22135 | MEDIUM5.3 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.11.2, 6.8.15 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2021-22137 | MEDIUM5.3 | org.elasticsearch:elasticsearch 2.4.3 fixed in 7.11.2, 6.8.15 | 1.1% Low-Moderate Risk | Directly Exposed |
| CVE-2025-9341 | MEDIUM5.27 | org.bouncycastle:bc-fips 2.1.0 fixed in 2.1.1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-64506 | MEDIUM5.18 | libpng 1.6.47-r0 fixed in 1.6.51-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-21933 | MEDIUM5.18 | openjdk17 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-21933 | MEDIUM5.18 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-21933 | MEDIUM5.18 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-21933 | MEDIUM5.18 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-21933 | MEDIUM5.18 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-21933 | MEDIUM5.18 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-22227 | MEDIUM5.18 | io.projectreactor.netty:reactor-netty-http 1.0.39 fixed in 1.3.0-M5, 1.2.8 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2018-3824 | MEDIUM5.18 | org.elasticsearch:elasticsearch 2.4.3 fixed in 5.6.9, 6.2.4 | 0.9% Theoretical Threat | Directly Exposed |
| CVE-2025-62408 | MEDIUM5.02 | c-ares 1.34.5-r0 fixed in 1.34.6-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-15468 | MEDIUM5.02 | libcrypto3 3.5.1-r0 fixed in 3.5.5-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-66199 | MEDIUM5.02 | libcrypto3 3.5.1-r0 fixed in 3.5.5-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69420 | MEDIUM5.02 | libcrypto3 3.5.1-r0 fixed in 3.5.5-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-22796 | MEDIUM5.02 | libcrypto3 3.5.1-r0 fixed in 3.5.5-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-42769 | MEDIUM5.02 | libcrypto3 3.5.1-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42770 | MEDIUM5.02 | libcrypto3 3.5.1-r0 fixed in 3.5.7-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-9076 | MEDIUM5.02 | libcrypto3 3.5.1-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-15468 | MEDIUM5.02 | libssl3 3.5.1-r0 fixed in 3.5.5-r0 | 0.7% Theoretical Threat | Directly Exposed |
| CVE-2025-66199 | MEDIUM5.02 | libssl3 3.5.1-r0 fixed in 3.5.5-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-69420 | MEDIUM5.02 | libssl3 3.5.1-r0 fixed in 3.5.5-r0 | 0.8% Theoretical Threat | Directly Exposed |
| CVE-2026-22796 | MEDIUM5.02 | libssl3 3.5.1-r0 fixed in 3.5.5-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-42769 | MEDIUM5.02 | libssl3 3.5.1-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-42770 | MEDIUM5.02 | libssl3 3.5.1-r0 fixed in 3.5.7-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-9076 | MEDIUM5.02 | libssl3 3.5.1-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-53057 | MEDIUM5.02 | openjdk17 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-53057 | MEDIUM5.02 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-53057 | MEDIUM5.02 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-53057 | MEDIUM5.02 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-53057 | MEDIUM5.02 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-53057 | MEDIUM5.02 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-9340 | MEDIUM5.02 | org.bouncycastle:bc-fips 2.1.0 fixed in 2.1.1 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-41850 | MEDIUM5.02 | org.springframework:spring-expression 6.1.15 fixed in 7.0.8, 6.2.19 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-34180 | MEDIUM5 | libcrypto3 3.5.1-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2026-34180 | MEDIUM5 | libssl3 3.5.1-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2020-7021 | MEDIUM4.9 | org.elasticsearch:elasticsearch 2.4.3 fixed in 6.8.14, 7.10.0 | 1.3% Low-Moderate Risk | Directly Exposed |
| CVE-2026-59921 | MEDIUM4.84 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-15469 | MEDIUM4.67 | libcrypto3 3.5.1-r0 fixed in 3.5.5-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-22795 | MEDIUM4.67 | libcrypto3 3.5.1-r0 fixed in 3.5.5-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-7383 | MEDIUM4.67 | libcrypto3 3.5.1-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2025-15469 | MEDIUM4.67 | libssl3 3.5.1-r0 fixed in 3.5.5-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-22795 | MEDIUM4.67 | libssl3 3.5.1-r0 fixed in 3.5.5-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-7383 | MEDIUM4.67 | libssl3 3.5.1-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-6042 | MEDIUM4.67 | musl 1.2.5-r10 fixed in 1.2.5-r11 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-6042 | MEDIUM4.67 | musl-utils 1.2.5-r10 fixed in 1.2.5-r11 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-27171 | MEDIUM4.67 | zlib 1.3.1-r2 fixed in 1.3.2-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-42766 | MEDIUM4.5 | libcrypto3 3.5.1-r0 fixed in 3.5.7-r0 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-42767 | MEDIUM4.5 | libcrypto3 3.5.1-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-42766 | MEDIUM4.5 | libssl3 3.5.1-r0 fixed in 3.5.7-r0 | 1.0% Theoretical Threat | Directly Exposed |
| CVE-2026-42767 | MEDIUM4.5 | libssl3 3.5.1-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-22013 | MEDIUM4.5 | openjdk17 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-22021 | MEDIUM4.5 | openjdk17 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-23865 | MEDIUM4.5 | openjdk17 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-22013 | MEDIUM4.5 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-22021 | MEDIUM4.5 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-23865 | MEDIUM4.5 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-22013 | MEDIUM4.5 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-22021 | MEDIUM4.5 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-23865 | MEDIUM4.5 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-22013 | MEDIUM4.5 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-22021 | MEDIUM4.5 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-23865 | MEDIUM4.5 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-22013 | MEDIUM4.5 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-22021 | MEDIUM4.5 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-23865 | MEDIUM4.5 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-22013 | MEDIUM4.5 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-22021 | MEDIUM4.5 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-23865 | MEDIUM4.5 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-54514 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.17.0 fixed in 2.18.8, 2.21.4, 3.1.4 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-54515 | MEDIUM4.5 | com.fasterxml.jackson.core:jackson-databind 2.17.0 fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-50020 | MEDIUM4.5 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-59898 | MEDIUM4.5 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-47244 | MEDIUM4.5 | io.netty:netty-codec-http2 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-50560 | MEDIUM4.5 | io.netty:netty-codec-http2 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-8916 | MEDIUM4.5 | org.bouncycastle:bcpkix-jdk15to18 1.78.1 fixed in 1.79 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2025-8916 | MEDIUM4.5 | org.bouncycastle:bcpkix-jdk18on 1.78.1 fixed in 1.79 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-2575 | MEDIUM4.5 | org.keycloak:keycloak-saml-adapter-core 18.0.2 fixed in 26.5.4 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-2575 | MEDIUM4.5 | org.keycloak:keycloak-saml-core 18.0.2 fixed in 26.5.4 | 0.5% Theoretical Threat | Directly Exposed |
| CVE-2026-41852 | MEDIUM4.5 | org.springframework:spring-expression 6.1.15 fixed in 7.0.8, 6.2.19 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2024-47554 | MEDIUM4.3 | commons-io:commons-io 2.8.0 fixed in 2.14.0 | 1.2% Low-Moderate Risk | Directly Exposed |
| CVE-2026-1225 | MEDIUM4.25 | ch.qos.logback:logback-core 1.5.16 fixed in 1.5.25 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-30754 | MEDIUM4.08 | openjdk17 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-53066 | MEDIUM4.08 | openjdk17 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-21925 | MEDIUM4.08 | openjdk17 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-30754 | MEDIUM4.08 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-53066 | MEDIUM4.08 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-21925 | MEDIUM4.08 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-30754 | MEDIUM4.08 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-53066 | MEDIUM4.08 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-21925 | MEDIUM4.08 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-30754 | MEDIUM4.08 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-53066 | MEDIUM4.08 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-21925 | MEDIUM4.08 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-30754 | MEDIUM4.08 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-53066 | MEDIUM4.08 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-21925 | MEDIUM4.08 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-30754 | MEDIUM4.08 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2025-53066 | MEDIUM4.08 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Directly Exposed |
| CVE-2026-21925 | MEDIUM4.08 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-15467 | MEDIUM4.06 | libcrypto3 3.5.1-r0 fixed in 3.5.5-r0 | 47.6% High Exploitation Risk | Post-Exploit |
| CVE-2025-15467 | MEDIUM4.06 | libssl3 3.5.1-r0 fixed in 3.5.5-r0 | 47.6% High Exploitation Risk | Post-Exploit |
| CVE-2025-15467 | MEDIUM4.06 | openssl 3.5.1-r0 fixed in 3.5.5-r0 | 47.6% High Exploitation Risk | Post-Exploit |
| CVE-2025-68160 | MEDIUM4 | libcrypto3 3.5.1-r0 fixed in 3.5.5-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-68160 | MEDIUM4 | libssl3 3.5.1-r0 fixed in 3.5.5-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69419 | LOW3.77 | openssl 3.5.1-r0 fixed in 3.5.5-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-34182 | LOW3.77 | openssl 3.5.1-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-64505 | LOW3.74 | libpng 1.6.47-r0 fixed in 1.6.51-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-34757 | LOW3.74 | libpng 1.6.47-r0 fixed in 1.6.57-r0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-48924 | LOW3.7 | org.apache.commons:commons-lang3 3.13.0 fixed in 3.18.0 | 2.2% Low-Moderate Risk | Directly Exposed |
| CVE-2025-11187 | LOW3.66 | openssl 3.5.1-r0 fixed in 3.5.5-r0 | 4.5% Low-Moderate Risk | Post-Exploit |
| CVE-2025-9231 | LOW3.54 | openssl 3.5.1-r0 fixed in 3.5.4-r0 | 2.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-31790 | LOW3.54 | openssl 3.5.1-r0 fixed in 3.5.6-r0 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-42764 | LOW3.54 | openssl 3.5.1-r0 fixed in 3.5.7-r0 | 1.2% Low-Moderate Risk | Post-Exploit |
| CVE-2025-69418 | LOW3.4 | libcrypto3 3.5.1-r0 fixed in 3.5.5-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-69418 | LOW3.4 | libssl3 3.5.1-r0 fixed in 3.5.5-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-45536 | LOW3.4 | io.netty:netty-transport-native-epoll 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-45536 | LOW3.4 | io.netty:netty-transport-native-kqueue 4.1.119.Final fixed in 4.2.15.Final, 4.1.135.Final | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-12194 | LOW3.4 | org.bouncycastle:bc-fips 2.1.0 fixed in 2.1.2 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-9230 | LOW3.36 | openssl 3.5.1-r0 fixed in 3.5.4-r0 | 1.7% Low-Moderate Risk | Post-Exploit |
| CVE-2026-5545 | LOW3.31 | curl 8.14.1-r1 fixed in 8.14.1-r3 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-5545 | LOW3.31 | libcurl 8.14.1-r1 fixed in 8.14.1-r3 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-2673 | LOW3.31 | openssl 3.5.1-r0 fixed in 3.5.6-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-34181 | LOW3.21 | openssl 3.5.1-r0 fixed in 3.5.7-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-42768 | LOW3.21 | openssl 3.5.1-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2025-9086 | LOW3.18 | curl 8.14.1-r1 fixed in 8.14.1-r2 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2025-9086 | LOW3.18 | libcurl 8.14.1-r1 fixed in 8.14.1-r2 | 1.3% Low-Moderate Risk | Post-Exploit |
| CVE-2025-48734 | LOW3.17 | commons-beanutils:commons-beanutils 1.9.4 fixed in 1.11.0 | 1.5% Low-Moderate Risk | Post-Exploit |
| CVE-2026-45446 | LOW3.15 | libcrypto3 3.5.1-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-45446 | LOW3.15 | libssl3 3.5.1-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-22018 | LOW3.15 | openjdk17 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-22018 | LOW3.15 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-22018 | LOW3.15 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-22018 | LOW3.15 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-22018 | LOW3.15 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2026-22018 | LOW3.15 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Directly Exposed |
| CVE-2025-9232 | LOW3.1 | libcrypto3 3.5.1-r0 fixed in 3.5.4-r0 | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2025-9232 | LOW3.1 | libssl3 3.5.1-r0 fixed in 3.5.4-r0 | 2.3% Low-Moderate Risk | Directly Exposed |
| CVE-2020-7020 | LOW3.1 | org.elasticsearch:elasticsearch 2.4.3 fixed in 6.8.13, 7.9.2 | 1.0% Low-Moderate Risk | Directly Exposed |
| CVE-2025-15468 | LOW3.01 | openssl 3.5.1-r0 fixed in 3.5.5-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2025-66199 | LOW3.01 | openssl 3.5.1-r0 fixed in 3.5.5-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-69420 | LOW3.01 | openssl 3.5.1-r0 fixed in 3.5.5-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-22796 | LOW3.01 | openssl 3.5.1-r0 fixed in 3.5.5-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-42769 | LOW3.01 | openssl 3.5.1-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-42770 | LOW3.01 | openssl 3.5.1-r0 fixed in 3.5.7-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-9076 | LOW3.01 | openssl 3.5.1-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-31789 | LOW3 | libcrypto3 3.5.1-r0 fixed in 3.5.6-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-31789 | LOW3 | libssl3 3.5.1-r0 fixed in 3.5.6-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-31789 | LOW3 | openssl 3.5.1-r0 fixed in 3.5.6-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-42581 | LOW3 | io.netty:netty-codec-http 4.1.119.Final fixed in 4.2.13.Final, 4.1.133.Final | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-34180 | LOW3 | openssl 3.5.1-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-45447 | LOW2.92 | libcrypto3 3.5.1-r0 fixed in 3.5.7-r0 | 5.2% Low-Moderate Risk | Post-Exploit |
| CVE-2026-45447 | LOW2.92 | libssl3 3.5.1-r0 fixed in 3.5.7-r0 | 5.2% Low-Moderate Risk | Post-Exploit |
| CVE-2025-30749 | LOW2.92 | openjdk17 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2025-30749 | LOW2.92 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2025-30749 | LOW2.92 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2025-30749 | LOW2.92 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2025-30749 | LOW2.92 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2025-30749 | LOW2.92 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-45447 | LOW2.92 | openssl 3.5.1-r0 fixed in 3.5.7-r0 | 5.2% Low-Moderate Risk | Post-Exploit |
| CVE-2019-7611 | LOW2.92 | org.elasticsearch:elasticsearch 2.4.3 fixed in 5.6.15, 6.6.1 | 2.1% Low-Moderate Risk | Post-Exploit |
| CVE-2025-15469 | LOW2.8 | openssl 3.5.1-r0 fixed in 3.5.5-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-22795 | LOW2.8 | openssl 3.5.1-r0 fixed in 3.5.5-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-7383 | LOW2.8 | openssl 3.5.1-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-45445 | LOW2.78 | openssl 3.5.1-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-28388 | LOW2.7 | openssl 3.5.1-r0 fixed in 3.5.6-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28389 | LOW2.7 | openssl 3.5.1-r0 fixed in 3.5.6-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-28390 | LOW2.7 | openssl 3.5.1-r0 fixed in 3.5.6-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-34183 | LOW2.7 | openssl 3.5.1-r0 fixed in 3.5.7-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-42766 | LOW2.7 | openssl 3.5.1-r0 fixed in 3.5.7-r0 | 1.0% Theoretical Threat | Post-Exploit |
| CVE-2026-42767 | LOW2.7 | openssl 3.5.1-r0 fixed in 3.5.7-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-28387 | LOW2.48 | openssl 3.5.1-r0 fixed in 3.5.6-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-22007 | LOW2.46 | openjdk17 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-34268 | LOW2.46 | openjdk17 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-22007 | LOW2.46 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-34268 | LOW2.46 | openjdk17-demos 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-22007 | LOW2.46 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-34268 | LOW2.46 | openjdk17-jdk 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-22007 | LOW2.46 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-34268 | LOW2.46 | openjdk17-jmods 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-22007 | LOW2.46 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-34268 | LOW2.46 | openjdk17-jre 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-22007 | LOW2.46 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-34268 | LOW2.46 | openjdk17-jre-headless 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-10148 | LOW2.45 | curl 8.14.1-r1 fixed in 8.14.1-r2 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-10148 | LOW2.45 | libcurl 8.14.1-r1 fixed in 8.14.1-r2 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2025-68160 | LOW2.4 | openssl 3.5.1-r0 fixed in 3.5.5-r0 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-69421 | LOW2.29 | openssl 3.5.1-r0 fixed in 3.5.5-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-23901 | LOW2.12 | org.apache.shiro:shiro-core 1.13.0 fixed in 2.1.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2025-69418 | LOW2.04 | openssl 3.5.1-r0 fixed in 3.5.5-r0 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-45446 | LOW1.89 | openssl 3.5.1-r0 fixed in 3.5.7-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2025-9232 | LOW1.86 | openssl 3.5.1-r0 fixed in 3.5.4-r0 | 2.3% Low-Moderate Risk | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | busybox 1.37.0-r18 fixed in 1.37.0-r20 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | busybox-binsh 1.37.0-r18 fixed in 1.37.0-r20 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-46394 | LOW1.68 | ssl_client 1.37.0-r18 fixed in 1.37.0-r20 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2025-9092 | LOW1.53 | org.bouncycastle:bc-fips 2.1.0 fixed in 2.1.1 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2025-50059 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2025-30749 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 1.1% Low-Moderate Risk | Not Applicable |
| CVE-2025-50106 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-21945 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.9% Theoretical Threat | Not Applicable |
| CVE-2026-22016 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.7% Theoretical Threat | Not Applicable |
| CVE-2026-34282 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-21932 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-21933 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-53057 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-22013 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-22021 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-23865 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2025-30754 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.16_p8-r0 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2025-53066 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.17_p10-r0 | 0.6% Theoretical Threat | Not Applicable |
| CVE-2026-21925 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.18_p8-r0 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-22018 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2025-48924 | NONE0 | commons-lang:commons-lang 2.6 No fix yet | 2.2% Low-Moderate Risk | Not Applicable |
| CVE-2026-22007 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-34268 | NONE0 | openjdk17-doc 17.0.15_p6-r0 fixed in 17.0.19_p10-r0 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | busybox 1.37.0-r18 fixed in 1.37.0-r20 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | busybox-binsh 1.37.0-r18 fixed in 1.37.0-r20 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2024-58251 | NONE0 | ssl_client 1.37.0-r18 fixed in 1.37.0-r20 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-10532 | NONE0 | ch.qos.logback:logback-core 1.5.16 fixed in 1.5.34 | 0.4% Theoretical Threat | Not Applicable |
| CVE-2026-9828 | NONE0 | ch.qos.logback:logback-core 1.5.16 fixed in 1.5.33 | 0.4% Theoretical Threat | Not Applicable |
| GHSA-r7wm-3cxj-wff9 | NONE0 | com.fasterxml.jackson.core:jackson-core 2.17.0 fixed in 2.18.8, 2.21.4, 2.22.1 | — | Not Applicable |
| GHSA-72hv-8253-57qq | NONE0 | com.fasterxml.jackson.core:jackson-core 2.17.0 fixed in 2.21.1, 2.18.6 | — | Not Applicable |
| GHSA-mfg7-5gfp-c4w3 | NONE0 | io.netty:netty-codec-dns 4.1.119.Final fixed in 4.2.16.Final, 4.1.136.Final | — | Not Applicable |
| CVE-2026-10050 | NONE0 | org.eclipse.jetty.ee8:jetty-ee8-security 12.0.17 fixed in 12.0.36, 12.1.10 | — | Not Applicable |
| CVE-2026-8384 | NONE0 | org.eclipse.jetty:jetty-util 12.0.17 fixed in 12.0.35, 12.1.9 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2025-22233 | NONE0 | org.springframework:spring-context 6.1.15 fixed in 6.2.7, 6.1.20 | 0.4% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.