Vulnerability Reportsonatype/nexus3:3.82.1-alpine

sonatype/nexus3:3.82.1-alpine
digestsha256:9a5c21bff028fb3ada619a9841d01dee27ff4b1ac9a4003614ab4da6ab3e962b

Executive Summary

Last scanned:

Threat Score
100/100DANGEROUS
Reputation
TRUSTED

This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could exploit a critical XXE in Apache Tika (CVE-2025-66516) via uploaded PDFs to disclose data or execute code, or use Jetty HTTP request smuggling (CVE-2026-2332) to bypass access controls and compromise the Nexus endpoint. The image contains 235 exposed vulnerabilities, including 17 with severity 7.0 or higher. Although the publisher is trusted and post-exploit-only findings are low severity, the remotely reachable critical flaws make this image unsafe; updating Tika and Jetty is required.

Vulnerabilities

Vulnerability Log

353 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2025-66516CRITICAL10
org.apache.tika:tika-core
1.28.4
fixed in 3.2.2
78.8%
Actively Exploited
Directly ExposedContext importance: HIGH
CVE-2026-2332CRITICAL9.1
org.eclipse.jetty:jetty-http
12.0.17
fixed in 12.1.7, 12.0.33
1.1%
Low-Moderate Risk
Directly ExposedContext importance: HIGH
CVE-2026-33630HIGH7.5
c-ares
1.34.5-r0
fixed in 1.34.8-r0
Directly Exposed
CVE-2026-28388HIGH7.5
libcrypto3
3.5.2-r0
fixed in 3.5.6-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-28389HIGH7.5
libcrypto3
3.5.2-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-28390HIGH7.5
libcrypto3
3.5.2-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-34183HIGH7.5
libcrypto3
3.5.2-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-33416HIGH7.5
libpng
1.6.47-r0
fixed in 1.6.56-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-28388HIGH7.5
libssl3
3.5.2-r0
fixed in 3.5.6-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-28389HIGH7.5
libssl3
3.5.2-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-28390HIGH7.5
libssl3
3.5.2-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-34183HIGH7.5
libssl3
3.5.2-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-2100HIGH7.5
p11-kit
0.25.5-r2
fixed in 0.26.2-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-2100HIGH7.5
p11-kit-trust
0.25.5-r2
fixed in 0.26.2-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-55163HIGH7.5
io.netty:netty-codec-http2
4.1.119.Final
fixed in 4.2.4.Final, 4.1.124.Final
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-33871HIGH7.5
io.netty:netty-codec-http2
4.1.119.Final
fixed in 4.1.132.Final, 4.2.11.Final
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2025-67030HIGH7.48
org.codehaus.plexus:plexus-utils
3.5.1
fixed in 4.0.3, 3.6.1
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-28387MEDIUM6.88
libcrypto3
3.5.2-r0
fixed in 3.5.6-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-25646MEDIUM6.88
libpng
1.6.47-r0
fixed in 1.6.55-r0
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-28387MEDIUM6.88
libssl3
3.5.2-r0
fixed in 3.5.6-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-54512MEDIUM6.88
com.fasterxml.jackson.core:jackson-databind
2.17.0
fixed in 2.18.8, 3.1.4, 2.21.4
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-54513MEDIUM6.88
com.fasterxml.jackson.core:jackson-databind
2.17.0
fixed in 2.18.8, 2.21.4, 3.1.4
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-44249MEDIUM6.88
io.netty:netty-handler
4.1.119.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-45674MEDIUM6.8
io.netty:netty-resolver-dns
4.1.119.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-47691MEDIUM6.8
io.netty:netty-resolver-dns
4.1.119.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-22801MEDIUM6.63
libpng
1.6.47-r0
fixed in 1.6.54-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-40200MEDIUM6.63
musl
1.2.5-r10
fixed in 1.2.5-r12
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-40200MEDIUM6.63
musl-utils
1.2.5-r10
fixed in 1.2.5-r12
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-22184MEDIUM6.63
zlib
1.3.1-r2
fixed in 1.3.2-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2020-7019MEDIUM6.5
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.9.0, 6.8.12
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2021-22144MEDIUM6.5
org.elasticsearch:elasticsearch
2.4.3
fixed in 6.8.17, 7.13.3
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-33636MEDIUM6.46
libpng
1.6.47-r0
fixed in 1.6.56-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-41254MEDIUM6.38
lcms2
2.16-r0
fixed in 2.19-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69421MEDIUM6.38
libcrypto3
3.5.2-r0
fixed in 3.5.5-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-69421MEDIUM6.38
libssl3
3.5.2-r0
fixed in 3.5.5-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-27135MEDIUM6.38
nghttp2-libs
1.65.0-r0
fixed in 1.68.1
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-21945MEDIUM6.38
openjdk17
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-22016MEDIUM6.38
openjdk17
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-34282MEDIUM6.38
openjdk17
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-21945MEDIUM6.38
openjdk17-jre
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-22016MEDIUM6.38
openjdk17-jre
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-34282MEDIUM6.38
openjdk17-jre
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-21945MEDIUM6.38
openjdk17-jre-headless
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-22016MEDIUM6.38
openjdk17-jre-headless
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-34282MEDIUM6.38
openjdk17-jre-headless
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-7962MEDIUM6.38
com.sun.mail:jakarta.mail
1.6.7
fixed in 1.6.8, 2.0.2
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-42583MEDIUM6.38
io.netty:netty-codec
4.1.119.Final
fixed in 4.1.133.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59901MEDIUM6.38
io.netty:netty-codec
4.1.119.Final
fixed in 4.1.136.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-58057MEDIUM6.38
io.netty:netty-codec
4.1.119.Final
fixed in 4.1.125.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-33870MEDIUM6.38
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.1.132.Final, 4.2.10.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42587MEDIUM6.38
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-55831MEDIUM6.38
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-55833MEDIUM6.38
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-56745MEDIUM6.38
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42585MEDIUM6.38
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-56746MEDIUM6.38
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59899MEDIUM6.38
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-58056MEDIUM6.38
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.1.125.Final, 4.2.5.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42587MEDIUM6.38
io.netty:netty-codec-http2
4.1.119.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-56819MEDIUM6.38
io.netty:netty-codec-http2
4.1.119.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-48043MEDIUM6.38
io.netty:netty-codec-http2
4.1.119.Final
fixed in 4.1.135.Final, 4.2.15.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-45416MEDIUM6.38
io.netty:netty-handler
4.1.119.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-50010MEDIUM6.38
io.netty:netty-handler
4.1.119.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42578MEDIUM6.38
io.netty:netty-handler-proxy
4.1.119.Final
fixed in 4.1.133.Final, 4.2.13.Final
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-3505MEDIUM6.38
org.bouncycastle:bcpg-jdk15to18
1.78.1
fixed in 1.84
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-5588MEDIUM6.38
org.bouncycastle:bcpkix-jdk15to18
1.78.1
fixed in 1.84
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5588MEDIUM6.38
org.bouncycastle:bcpkix-jdk18on
1.78.1
fixed in 1.84
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-14813MEDIUM6.38
org.bouncycastle:bcprov-jdk15to18
1.78.1
fixed in 1.84
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-5598MEDIUM6.38
org.bouncycastle:bcprov-jdk15to18
1.78.1
fixed in 1.80.2
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-14813MEDIUM6.38
org.bouncycastle:bcprov-jdk18on
1.78.1
fixed in 1.80.2, 1.81.1, 1.84
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-64518MEDIUM6.38
org.cyclonedx:cyclonedx-core-java
9.1.0
fixed in 11.0.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-23444MEDIUM6.38
org.elasticsearch:elasticsearch
2.4.3
fixed in 8.13.0, 7.17.23
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-43709MEDIUM6.38
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.17.21, 8.13.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2024-52979MEDIUM6.38
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.17.25, 8.16.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-7307MEDIUM6.38
org.keycloak:keycloak-saml-core
18.0.2
fixed in 26.6.2
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-42198MEDIUM6.38
org.postgresql:postgresql
42.7.2
fixed in 42.7.11
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-41249MEDIUM6.38
org.springframework:spring-core
6.1.15
fixed in 6.2.11
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-41848MEDIUM6.38
org.springframework:spring-core
6.1.15
fixed in 7.0.8, 6.2.19
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-41851MEDIUM6.38
org.springframework:spring-expression
6.1.15
fixed in 7.0.8, 6.2.19
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69419MEDIUM6.29
libcrypto3
3.5.2-r0
fixed in 3.5.5-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34182MEDIUM6.29
libcrypto3
3.5.2-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69419MEDIUM6.29
libssl3
3.5.2-r0
fixed in 3.5.5-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34182MEDIUM6.29
libssl3
3.5.2-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-21932MEDIUM6.29
openjdk17
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-21932MEDIUM6.29
openjdk17-jre
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-21932MEDIUM6.29
openjdk17-jre-headless
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-22235MEDIUM6.21
org.springframework.boot:spring-boot
3.3.6
fixed in 3.3.11, 3.4.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42579MEDIUM6.18
io.netty:netty-codec-dns
4.1.119.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42584MEDIUM6.18
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.8%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-49268MEDIUM6.18
org.apache.shiro:shiro-core
1.13.0
fixed in 2.2.1, 3.0.0-alpha-2
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2024-8698MEDIUM6.16
org.keycloak:keycloak-saml-core
18.0.2
fixed in 22.0.13, 24.0.8, 25.0.6
2.0%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2025-11187MEDIUM6.1
libcrypto3
3.5.2-r0
fixed in 3.5.5-r0
4.5%
Low-Moderate Risk
Directly Exposed
CVE-2025-11187MEDIUM6.1
libssl3
3.5.2-r0
fixed in 3.5.5-r0
4.5%
Low-Moderate Risk
Directly Exposed
CVE-2025-64720MEDIUM6.03
libpng
1.6.47-r0
fixed in 1.6.51-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-65018MEDIUM6.03
libpng
1.6.47-r0
fixed in 1.6.51-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-66293MEDIUM6.03
libpng
1.6.47-r0
fixed in 1.6.53-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-22695MEDIUM6.03
libpng
1.6.47-r0
fixed in 1.6.54-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-40973MEDIUM5.95
org.springframework.boot:spring-boot
3.3.6
fixed in 4.0.6, 3.5.14
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-9231MEDIUM5.9
libcrypto3
3.5.2-r0
fixed in 3.5.4-r0
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-31790MEDIUM5.9
libcrypto3
3.5.2-r0
fixed in 3.5.6-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-42764MEDIUM5.9
libcrypto3
3.5.2-r0
fixed in 3.5.7-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-9231MEDIUM5.9
libssl3
3.5.2-r0
fixed in 3.5.4-r0
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-31790MEDIUM5.9
libssl3
3.5.2-r0
fixed in 3.5.6-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-42764MEDIUM5.9
libssl3
3.5.2-r0
fixed in 3.5.7-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-13151MEDIUM5.9
libtasn1
4.20.0-r0
fixed in 4.21.0-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2019-7614MEDIUM5.9
org.elasticsearch:elasticsearch
2.4.3
fixed in 6.8.2, 7.2.1
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-45673MEDIUM5.78
io.netty:netty-resolver-dns
4.1.119.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-9230MEDIUM5.6
libcrypto3
3.5.2-r0
fixed in 3.5.4-r0
1.7%
Low-Moderate Risk
Directly Exposed
CVE-2025-9230MEDIUM5.6
libssl3
3.5.2-r0
fixed in 3.5.4-r0
1.7%
Low-Moderate Risk
Directly Exposed
CVE-2026-2673MEDIUM5.52
libcrypto3
3.5.2-r0
fixed in 3.5.6-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-2673MEDIUM5.52
libssl3
3.5.2-r0
fixed in 3.5.6-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59888MEDIUM5.52
com.fasterxml.jackson.core:jackson-databind
2.17.0
fixed in 2.18.8, 2.21.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-67735MEDIUM5.52
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.8.Final, 4.1.129.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-41417MEDIUM5.52
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.1.133.Final, 4.2.13.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42580MEDIUM5.52
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59900MEDIUM5.52
io.netty:netty-codec-http2
4.1.119.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-43827MEDIUM5.52
org.apache.shiro:shiro-core
1.13.0
fixed in 2.2.0, 3.0.0-alpha-2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-43828MEDIUM5.52
org.apache.shiro:shiro-web
1.13.0
fixed in 2.2.0, 3.0.0-alpha-2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-0636MEDIUM5.52
org.bouncycastle:bcprov-jdk15to18
1.78.1
fixed in 1.84
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-0636MEDIUM5.52
org.bouncycastle:bcprov-jdk18on
1.78.1
fixed in 1.84
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-11143MEDIUM5.52
org.eclipse.jetty:jetty-http
12.0.17
fixed in 12.0.31, 12.1.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-49921MEDIUM5.52
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.17.16, 8.11.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-11226MEDIUM5.44
ch.qos.logback:logback-core
1.5.16
fixed in 1.5.19, 1.3.16
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-34181MEDIUM5.35
libcrypto3
3.5.2-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
libcrypto3
3.5.2-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-34181MEDIUM5.35
libssl3
3.5.2-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
libssl3
3.5.2-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2021-22135MEDIUM5.3
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.11.2, 6.8.15
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2021-22137MEDIUM5.3
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.11.2, 6.8.15
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2025-9341MEDIUM5.27
org.bouncycastle:bc-fips
2.1.0
fixed in 2.1.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-64506MEDIUM5.18
libpng
1.6.47-r0
fixed in 1.6.51-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-21933MEDIUM5.18
openjdk17
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-21933MEDIUM5.18
openjdk17-jre
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-21933MEDIUM5.18
openjdk17-jre-headless
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-22227MEDIUM5.18
io.projectreactor.netty:reactor-netty-http
1.0.39
fixed in 1.3.0-M5, 1.2.8
0.3%
Theoretical Threat
Directly Exposed
CVE-2018-3824MEDIUM5.18
org.elasticsearch:elasticsearch
2.4.3
fixed in 5.6.9, 6.2.4
0.9%
Theoretical Threat
Directly Exposed
CVE-2025-62408MEDIUM5.02
c-ares
1.34.5-r0
fixed in 1.34.6-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-15468MEDIUM5.02
libcrypto3
3.5.2-r0
fixed in 3.5.5-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-66199MEDIUM5.02
libcrypto3
3.5.2-r0
fixed in 3.5.5-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69420MEDIUM5.02
libcrypto3
3.5.2-r0
fixed in 3.5.5-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-22796MEDIUM5.02
libcrypto3
3.5.2-r0
fixed in 3.5.5-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
libcrypto3
3.5.2-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
libcrypto3
3.5.2-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
libcrypto3
3.5.2-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-15468MEDIUM5.02
libssl3
3.5.2-r0
fixed in 3.5.5-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-66199MEDIUM5.02
libssl3
3.5.2-r0
fixed in 3.5.5-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69420MEDIUM5.02
libssl3
3.5.2-r0
fixed in 3.5.5-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-22796MEDIUM5.02
libssl3
3.5.2-r0
fixed in 3.5.5-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
libssl3
3.5.2-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
libssl3
3.5.2-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
libssl3
3.5.2-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-53057MEDIUM5.02
openjdk17
17.0.16_p8-r0
fixed in 17.0.17_p10-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-53057MEDIUM5.02
openjdk17-jre
17.0.16_p8-r0
fixed in 17.0.17_p10-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-53057MEDIUM5.02
openjdk17-jre-headless
17.0.16_p8-r0
fixed in 17.0.17_p10-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-9340MEDIUM5.02
org.bouncycastle:bc-fips
2.1.0
fixed in 2.1.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-41850MEDIUM5.02
org.springframework:spring-expression
6.1.15
fixed in 7.0.8, 6.2.19
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM5
libcrypto3
3.5.2-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-34180MEDIUM5
libssl3
3.5.2-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2020-7021MEDIUM4.9
org.elasticsearch:elasticsearch
2.4.3
fixed in 6.8.14, 7.10.0
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-59921MEDIUM4.84
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-15469MEDIUM4.67
libcrypto3
3.5.2-r0
fixed in 3.5.5-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-22795MEDIUM4.67
libcrypto3
3.5.2-r0
fixed in 3.5.5-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
libcrypto3
3.5.2-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-15469MEDIUM4.67
libssl3
3.5.2-r0
fixed in 3.5.5-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-22795MEDIUM4.67
libssl3
3.5.2-r0
fixed in 3.5.5-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
libssl3
3.5.2-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-6042MEDIUM4.67
musl
1.2.5-r10
fixed in 1.2.5-r11
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-6042MEDIUM4.67
musl-utils
1.2.5-r10
fixed in 1.2.5-r11
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib
1.3.1-r2
fixed in 1.3.2-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
libcrypto3
3.5.2-r0
fixed in 3.5.7-r0
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
libcrypto3
3.5.2-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
libssl3
3.5.2-r0
fixed in 3.5.7-r0
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
libssl3
3.5.2-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-22013MEDIUM4.5
openjdk17
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-22021MEDIUM4.5
openjdk17
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-23865MEDIUM4.5
openjdk17
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-22013MEDIUM4.5
openjdk17-jre
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-22021MEDIUM4.5
openjdk17-jre
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-23865MEDIUM4.5
openjdk17-jre
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-22013MEDIUM4.5
openjdk17-jre-headless
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-22021MEDIUM4.5
openjdk17-jre-headless
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-23865MEDIUM4.5
openjdk17-jre-headless
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-54514MEDIUM4.5
com.fasterxml.jackson.core:jackson-databind
2.17.0
fixed in 2.18.8, 2.21.4, 3.1.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-54515MEDIUM4.5
com.fasterxml.jackson.core:jackson-databind
2.17.0
fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-50020MEDIUM4.5
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-59898MEDIUM4.5
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-47244MEDIUM4.5
io.netty:netty-codec-http2
4.1.119.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-50560MEDIUM4.5
io.netty:netty-codec-http2
4.1.119.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-8916MEDIUM4.5
org.bouncycastle:bcpkix-jdk15to18
1.78.1
fixed in 1.79
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-8916MEDIUM4.5
org.bouncycastle:bcpkix-jdk18on
1.78.1
fixed in 1.79
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-2575MEDIUM4.5
org.keycloak:keycloak-saml-adapter-core
18.0.2
fixed in 26.5.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-2575MEDIUM4.5
org.keycloak:keycloak-saml-core
18.0.2
fixed in 26.5.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-41852MEDIUM4.5
org.springframework:spring-expression
6.1.15
fixed in 7.0.8, 6.2.19
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-47554MEDIUM4.3
commons-io:commons-io
2.8.0
fixed in 2.14.0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-1225MEDIUM4.25
ch.qos.logback:logback-core
1.5.16
fixed in 1.5.25
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-53066MEDIUM4.08
openjdk17
17.0.16_p8-r0
fixed in 17.0.17_p10-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-21925MEDIUM4.08
openjdk17
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-53066MEDIUM4.08
openjdk17-jre
17.0.16_p8-r0
fixed in 17.0.17_p10-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-21925MEDIUM4.08
openjdk17-jre
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-53066MEDIUM4.08
openjdk17-jre-headless
17.0.16_p8-r0
fixed in 17.0.17_p10-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-21925MEDIUM4.08
openjdk17-jre-headless
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-15467MEDIUM4.06
libcrypto3
3.5.2-r0
fixed in 3.5.5-r0
47.6%
High Exploitation Risk
Post-Exploit
CVE-2025-15467MEDIUM4.06
libssl3
3.5.2-r0
fixed in 3.5.5-r0
47.6%
High Exploitation Risk
Post-Exploit
CVE-2025-15467MEDIUM4.06
openssl
3.5.2-r0
fixed in 3.5.5-r0
47.6%
High Exploitation Risk
Post-Exploit
CVE-2025-68160MEDIUM4
libcrypto3
3.5.2-r0
fixed in 3.5.5-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-68160MEDIUM4
libssl3
3.5.2-r0
fixed in 3.5.5-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-21945LOW3.82
openjdk17-jdk
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-22016LOW3.82
openjdk17-jdk
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-34282LOW3.82
openjdk17-jdk
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-21932LOW3.77
openjdk17-jdk
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-69419LOW3.77
openssl
3.5.2-r0
fixed in 3.5.5-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-34182LOW3.77
openssl
3.5.2-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-64505LOW3.74
libpng
1.6.47-r0
fixed in 1.6.51-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-34757LOW3.74
libpng
1.6.47-r0
fixed in 1.6.57-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-48924LOW3.7
org.apache.commons:commons-lang3
3.13.0
fixed in 3.18.0
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2025-11187LOW3.66
openssl
3.5.2-r0
fixed in 3.5.5-r0
4.5%
Low-Moderate Risk
Post-Exploit
CVE-2025-9231LOW3.54
openssl
3.5.2-r0
fixed in 3.5.4-r0
2.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-31790LOW3.54
openssl
3.5.2-r0
fixed in 3.5.6-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-42764LOW3.54
openssl
3.5.2-r0
fixed in 3.5.7-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2025-69418LOW3.4
libcrypto3
3.5.2-r0
fixed in 3.5.5-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-69418LOW3.4
libssl3
3.5.2-r0
fixed in 3.5.5-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-45536LOW3.4
io.netty:netty-transport-native-epoll
4.1.119.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-45536LOW3.4
io.netty:netty-transport-native-kqueue
4.1.119.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-12194LOW3.4
org.bouncycastle:bc-fips
2.1.0
fixed in 2.1.2
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-9230LOW3.36
openssl
3.5.2-r0
fixed in 3.5.4-r0
1.7%
Low-Moderate Risk
Post-Exploit
CVE-2026-5545LOW3.31
curl
8.14.1-r1
fixed in 8.14.1-r3
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-5545LOW3.31
libcurl
8.14.1-r1
fixed in 8.14.1-r3
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-2673LOW3.31
openssl
3.5.2-r0
fixed in 3.5.6-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-34181LOW3.21
openssl
3.5.2-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-42768LOW3.21
openssl
3.5.2-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-9086LOW3.18
curl
8.14.1-r1
fixed in 8.14.1-r2
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-9086LOW3.18
libcurl
8.14.1-r1
fixed in 8.14.1-r2
1.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-48734LOW3.17
commons-beanutils:commons-beanutils
1.9.4
fixed in 1.11.0
1.5%
Low-Moderate Risk
Post-Exploit
CVE-2026-45446LOW3.15
libcrypto3
3.5.2-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
libssl3
3.5.2-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-22018LOW3.15
openjdk17
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-22018LOW3.15
openjdk17-jre
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-22018LOW3.15
openjdk17-jre-headless
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-21933LOW3.11
openjdk17-jdk
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-9232LOW3.1
libcrypto3
3.5.2-r0
fixed in 3.5.4-r0
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2025-9232LOW3.1
libssl3
3.5.2-r0
fixed in 3.5.4-r0
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2020-7020LOW3.1
org.elasticsearch:elasticsearch
2.4.3
fixed in 6.8.13, 7.9.2
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2025-53057LOW3.01
openjdk17-jdk
17.0.16_p8-r0
fixed in 17.0.17_p10-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-15468LOW3.01
openssl
3.5.2-r0
fixed in 3.5.5-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2025-66199LOW3.01
openssl
3.5.2-r0
fixed in 3.5.5-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-69420LOW3.01
openssl
3.5.2-r0
fixed in 3.5.5-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-22796LOW3.01
openssl
3.5.2-r0
fixed in 3.5.5-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-42769LOW3.01
openssl
3.5.2-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-42770LOW3.01
openssl
3.5.2-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-9076LOW3.01
openssl
3.5.2-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-31789LOW3
libcrypto3
3.5.2-r0
fixed in 3.5.6-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-31789LOW3
libssl3
3.5.2-r0
fixed in 3.5.6-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-31789LOW3
openssl
3.5.2-r0
fixed in 3.5.6-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-42581LOW3
io.netty:netty-codec-http
4.1.119.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-34180LOW3
openssl
3.5.2-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
libcrypto3
3.5.2-r0
fixed in 3.5.7-r0
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
libssl3
3.5.2-r0
fixed in 3.5.7-r0
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
openssl
3.5.2-r0
fixed in 3.5.7-r0
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2019-7611LOW2.92
org.elasticsearch:elasticsearch
2.4.3
fixed in 5.6.15, 6.6.1
2.1%
Low-Moderate Risk
Post-Exploit
CVE-2025-15469LOW2.8
openssl
3.5.2-r0
fixed in 3.5.5-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-22795LOW2.8
openssl
3.5.2-r0
fixed in 3.5.5-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-7383LOW2.8
openssl
3.5.2-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
libcrypto3
3.5.2-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
libssl3
3.5.2-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl
3.5.2-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-28388LOW2.7
openssl
3.5.2-r0
fixed in 3.5.6-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-28389LOW2.7
openssl
3.5.2-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-28390LOW2.7
openssl
3.5.2-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-34183LOW2.7
openssl
3.5.2-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2023-31418LOW2.7
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.17.13, 8.9.0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-22013LOW2.7
openjdk17-jdk
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-22021LOW2.7
openjdk17-jdk
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-23865LOW2.7
openjdk17-jdk
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-42766LOW2.7
openssl
3.5.2-r0
fixed in 3.5.7-r0
1.0%
Theoretical Threat
Post-Exploit
CVE-2026-42767LOW2.7
openssl
3.5.2-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-28387LOW2.48
openssl
3.5.2-r0
fixed in 3.5.6-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-22007LOW2.46
openjdk17
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-34268LOW2.46
openjdk17
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-22007LOW2.46
openjdk17-jre
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-34268LOW2.46
openjdk17-jre
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-22007LOW2.46
openjdk17-jre-headless
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-34268LOW2.46
openjdk17-jre-headless
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-10148LOW2.45
curl
8.14.1-r1
fixed in 8.14.1-r2
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-10148LOW2.45
libcurl
8.14.1-r1
fixed in 8.14.1-r2
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-53066LOW2.45
openjdk17-jdk
17.0.16_p8-r0
fixed in 17.0.17_p10-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-21925LOW2.45
openjdk17-jdk
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-68160LOW2.4
openssl
3.5.2-r0
fixed in 3.5.5-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-69421LOW2.29
openssl
3.5.2-r0
fixed in 3.5.5-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-23901LOW2.12
org.apache.shiro:shiro-core
1.13.0
fixed in 2.1.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69418LOW2.04
openssl
3.5.2-r0
fixed in 3.5.5-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-22018LOW1.89
openjdk17-jdk
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45446LOW1.89
openssl
3.5.2-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-9232LOW1.86
openssl
3.5.2-r0
fixed in 3.5.4-r0
2.3%
Low-Moderate Risk
Post-Exploit
CVE-2025-46394LOW1.68
busybox
1.37.0-r18
fixed in 1.37.0-r20
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-46394LOW1.68
busybox-binsh
1.37.0-r18
fixed in 1.37.0-r20
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-46394LOW1.68
ssl_client
1.37.0-r18
fixed in 1.37.0-r20
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-9092LOW1.53
org.bouncycastle:bc-fips
2.1.0
fixed in 2.1.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-22007LOW1.48
openjdk17-jdk
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-34268LOW1.48
openjdk17-jdk
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-21945NONE0
openjdk17-demos
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.9%
Theoretical Threat
Not Applicable
CVE-2026-22016NONE0
openjdk17-demos
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-34282NONE0
openjdk17-demos
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-21945NONE0
openjdk17-doc
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.9%
Theoretical Threat
Not Applicable
CVE-2026-22016NONE0
openjdk17-doc
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-34282NONE0
openjdk17-doc
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-21945NONE0
openjdk17-jmods
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.9%
Theoretical Threat
Not Applicable
CVE-2026-22016NONE0
openjdk17-jmods
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-34282NONE0
openjdk17-jmods
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-21932NONE0
openjdk17-demos
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-21932NONE0
openjdk17-doc
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-21932NONE0
openjdk17-jmods
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-21933NONE0
openjdk17-demos
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-21933NONE0
openjdk17-doc
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-21933NONE0
openjdk17-jmods
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2025-53057NONE0
openjdk17-demos
17.0.16_p8-r0
fixed in 17.0.17_p10-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2025-53057NONE0
openjdk17-doc
17.0.16_p8-r0
fixed in 17.0.17_p10-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2025-53057NONE0
openjdk17-jmods
17.0.16_p8-r0
fixed in 17.0.17_p10-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-22013NONE0
openjdk17-demos
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22021NONE0
openjdk17-demos
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-23865NONE0
openjdk17-demos
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22013NONE0
openjdk17-doc
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22021NONE0
openjdk17-doc
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-23865NONE0
openjdk17-doc
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22013NONE0
openjdk17-jmods
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22021NONE0
openjdk17-jmods
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-23865NONE0
openjdk17-jmods
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2025-53066NONE0
openjdk17-demos
17.0.16_p8-r0
fixed in 17.0.17_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-21925NONE0
openjdk17-demos
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2025-53066NONE0
openjdk17-doc
17.0.16_p8-r0
fixed in 17.0.17_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-21925NONE0
openjdk17-doc
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2025-53066NONE0
openjdk17-jmods
17.0.16_p8-r0
fixed in 17.0.17_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-21925NONE0
openjdk17-jmods
17.0.16_p8-r0
fixed in 17.0.18_p8-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-22018NONE0
openjdk17-demos
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22018NONE0
openjdk17-doc
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22018NONE0
openjdk17-jmods
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2025-48924NONE0
commons-lang:commons-lang
2.6
No fix yet
2.2%
Low-Moderate Risk
Not Applicable
CVE-2026-22007NONE0
openjdk17-demos
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-34268NONE0
openjdk17-demos
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22007NONE0
openjdk17-doc
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-34268NONE0
openjdk17-doc
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22007NONE0
openjdk17-jmods
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-34268NONE0
openjdk17-jmods
17.0.16_p8-r0
fixed in 17.0.19_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2024-58251NONE0
busybox
1.37.0-r18
fixed in 1.37.0-r20
0.2%
Theoretical Threat
Not Applicable
CVE-2024-58251NONE0
busybox-binsh
1.37.0-r18
fixed in 1.37.0-r20
0.2%
Theoretical Threat
Not Applicable
CVE-2024-58251NONE0
ssl_client
1.37.0-r18
fixed in 1.37.0-r20
0.2%
Theoretical Threat
Not Applicable
CVE-2026-10532NONE0
ch.qos.logback:logback-core
1.5.16
fixed in 1.5.34
0.4%
Theoretical Threat
Not Applicable
CVE-2026-9828NONE0
ch.qos.logback:logback-core
1.5.16
fixed in 1.5.33
0.4%
Theoretical Threat
Not Applicable
GHSA-r7wm-3cxj-wff9NONE0
com.fasterxml.jackson.core:jackson-core
2.17.0
fixed in 2.18.8, 2.21.4, 2.22.1
Not Applicable
GHSA-72hv-8253-57qqNONE0
com.fasterxml.jackson.core:jackson-core
2.17.0
fixed in 2.21.1, 2.18.6
Not Applicable
GHSA-mfg7-5gfp-c4w3NONE0
io.netty:netty-codec-dns
4.1.119.Final
fixed in 4.2.16.Final, 4.1.136.Final
Not Applicable
CVE-2026-10050NONE0
org.eclipse.jetty.ee8:jetty-ee8-security
12.0.17
fixed in 12.0.36, 12.1.10
Not Applicable
CVE-2026-8384NONE0
org.eclipse.jetty:jetty-util
12.0.17
fixed in 12.0.35, 12.1.9
0.2%
Theoretical Threat
Not Applicable
CVE-2025-22233NONE0
org.springframework:spring-context
6.1.15
fixed in 6.2.7, 6.1.20
0.4%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.