Vulnerability Reportsonatype/nexus3:3.84.2-alpine

sonatype/nexus3:3.84.2-alpine
digestsha256:0e4eb2535ebabab15057a097bd387ced8e935885694ee4a77610f2c750556420

Executive Summary

Last scanned:

Threat Score
100/100DANGEROUS
Reputation
TRUSTED

This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could exploit CVE-2026-2332 to smuggle HTTP requests to the Nexus repository service, bypassing access controls and potentially accessing sensitive data or poisoning request handling. Other remotely reachable DoS flaws, such as CVE-2026-33630, could crash the service, leading to availability loss. With 14 exposed high-severity findings and a maximum severity of 9.1, the attack surface is unacceptable for production deployment.

Vulnerabilities

Vulnerability Log

337 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-2332CRITICAL9.1
org.eclipse.jetty:jetty-http
12.0.17
fixed in 12.1.7, 12.0.33
1.1%
Low-Moderate Risk
Directly ExposedContext importance: HIGH
CVE-2026-33630HIGH7.5
c-ares
1.34.6-r0
fixed in 1.34.8-r0
Directly Exposed
CVE-2026-28388HIGH7.5
libcrypto3
3.5.4-r0
fixed in 3.5.6-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-28389HIGH7.5
libcrypto3
3.5.4-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-28390HIGH7.5
libcrypto3
3.5.4-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-34183HIGH7.5
libcrypto3
3.5.4-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-33416HIGH7.5
libpng
1.6.53-r0
fixed in 1.6.56-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-28388HIGH7.5
libssl3
3.5.4-r0
fixed in 3.5.6-r0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-28389HIGH7.5
libssl3
3.5.4-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-28390HIGH7.5
libssl3
3.5.4-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-34183HIGH7.5
libssl3
3.5.4-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-33871HIGH7.5
io.netty:netty-codec-http2
4.1.124.Final
fixed in 4.1.132.Final, 4.2.11.Final
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-45292HIGH7.5
io.opentelemetry:opentelemetry-api
1.47.0
fixed in 1.62.0
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2025-67030HIGH7.48
org.codehaus.plexus:plexus-utils
3.5.1
fixed in 4.0.3, 3.6.1
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-28387MEDIUM6.88
libcrypto3
3.5.4-r0
fixed in 3.5.6-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-25646MEDIUM6.88
libpng
1.6.53-r0
fixed in 1.6.55-r0
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-28387MEDIUM6.88
libssl3
3.5.4-r0
fixed in 3.5.6-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-54512MEDIUM6.88
com.fasterxml.jackson.core:jackson-databind
2.17.0
fixed in 2.18.8, 3.1.4, 2.21.4
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-54513MEDIUM6.88
com.fasterxml.jackson.core:jackson-databind
2.17.0
fixed in 2.18.8, 2.21.4, 3.1.4
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-44249MEDIUM6.88
io.netty:netty-handler
4.1.124.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-45674MEDIUM6.8
io.netty:netty-resolver-dns
4.1.112.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-47691MEDIUM6.8
io.netty:netty-resolver-dns
4.1.112.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42581MEDIUM6.66
io.netty:netty-codec-http
4.1.124.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-22801MEDIUM6.63
libpng
1.6.53-r0
fixed in 1.6.54-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-40200MEDIUM6.63
musl
1.2.5-r21
fixed in 1.2.5-r23
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-22184MEDIUM6.63
zlib
1.3.1-r2
fixed in 1.3.2-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2020-7019MEDIUM6.5
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.9.0, 6.8.12
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2021-22144MEDIUM6.5
org.elasticsearch:elasticsearch
2.4.3
fixed in 6.8.17, 7.13.3
2.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-33636MEDIUM6.46
libpng
1.6.53-r0
fixed in 1.6.56-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-41254MEDIUM6.38
lcms2
2.17-r0
fixed in 2.19-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69421MEDIUM6.38
libcrypto3
3.5.4-r0
fixed in 3.5.5-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-69421MEDIUM6.38
libssl3
3.5.4-r0
fixed in 3.5.5-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-27135MEDIUM6.38
nghttp2-libs
1.68.0-r0
fixed in 1.68.1
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-21945MEDIUM6.38
openjdk21
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-22016MEDIUM6.38
openjdk21
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-34282MEDIUM6.38
openjdk21
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-21945MEDIUM6.38
openjdk21-jre
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-22016MEDIUM6.38
openjdk21-jre
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-34282MEDIUM6.38
openjdk21-jre
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-21945MEDIUM6.38
openjdk21-jre-headless
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.9%
Theoretical Threat
Directly Exposed
CVE-2026-22016MEDIUM6.38
openjdk21-jre-headless
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-34282MEDIUM6.38
openjdk21-jre-headless
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-7962MEDIUM6.38
com.sun.mail:jakarta.mail
1.6.7
fixed in 1.6.8, 2.0.2
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-42583MEDIUM6.38
io.netty:netty-codec
4.1.124.Final
fixed in 4.1.133.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59901MEDIUM6.38
io.netty:netty-codec
4.1.124.Final
fixed in 4.1.136.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-58057MEDIUM6.38
io.netty:netty-codec
4.1.124.Final
fixed in 4.1.125.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-33870MEDIUM6.38
io.netty:netty-codec-http
4.1.124.Final
fixed in 4.1.132.Final, 4.2.10.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42587MEDIUM6.38
io.netty:netty-codec-http
4.1.124.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-55831MEDIUM6.38
io.netty:netty-codec-http
4.1.124.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-55833MEDIUM6.38
io.netty:netty-codec-http
4.1.124.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-56745MEDIUM6.38
io.netty:netty-codec-http
4.1.124.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42585MEDIUM6.38
io.netty:netty-codec-http
4.1.124.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-56746MEDIUM6.38
io.netty:netty-codec-http
4.1.124.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59899MEDIUM6.38
io.netty:netty-codec-http
4.1.124.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-58056MEDIUM6.38
io.netty:netty-codec-http
4.1.124.Final
fixed in 4.1.125.Final, 4.2.5.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42587MEDIUM6.38
io.netty:netty-codec-http2
4.1.124.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-56819MEDIUM6.38
io.netty:netty-codec-http2
4.1.124.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-48043MEDIUM6.38
io.netty:netty-codec-http2
4.1.124.Final
fixed in 4.1.135.Final, 4.2.15.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-45416MEDIUM6.38
io.netty:netty-handler
4.1.124.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-50010MEDIUM6.38
io.netty:netty-handler
4.1.124.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42578MEDIUM6.38
io.netty:netty-handler-proxy
4.1.118.Final
fixed in 4.1.133.Final, 4.2.13.Final
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-3505MEDIUM6.38
org.bouncycastle:bcpg-jdk15to18
1.81
fixed in 1.84
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-5588MEDIUM6.38
org.bouncycastle:bcpkix-jdk15to18
1.81
fixed in 1.84
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5588MEDIUM6.38
org.bouncycastle:bcpkix-jdk18on
1.81
fixed in 1.84
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-14813MEDIUM6.38
org.bouncycastle:bcprov-jdk15to18
1.81
fixed in 1.84
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-14813MEDIUM6.38
org.bouncycastle:bcprov-jdk18on
1.81
fixed in 1.80.2, 1.81.1, 1.84
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-64518MEDIUM6.38
org.cyclonedx:cyclonedx-core-java
9.1.0
fixed in 11.0.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-23444MEDIUM6.38
org.elasticsearch:elasticsearch
2.4.3
fixed in 8.13.0, 7.17.23
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-43709MEDIUM6.38
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.17.21, 8.13.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2024-52979MEDIUM6.38
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.17.25, 8.16.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-7307MEDIUM6.38
org.keycloak:keycloak-saml-core
18.0.2
fixed in 26.6.2
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-42198MEDIUM6.38
org.postgresql:postgresql
42.7.2
fixed in 42.7.11
0.8%
Theoretical Threat
Directly Exposed
CVE-2025-41249MEDIUM6.38
org.springframework:spring-core
6.1.15
fixed in 6.2.11
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-41848MEDIUM6.38
org.springframework:spring-core
6.1.15
fixed in 7.0.8, 6.2.19
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-41851MEDIUM6.38
org.springframework:spring-expression
6.1.15
fixed in 7.0.8, 6.2.19
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69419MEDIUM6.29
libcrypto3
3.5.4-r0
fixed in 3.5.5-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34182MEDIUM6.29
libcrypto3
3.5.4-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69419MEDIUM6.29
libssl3
3.5.4-r0
fixed in 3.5.5-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34182MEDIUM6.29
libssl3
3.5.4-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-21932MEDIUM6.29
openjdk21
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-21932MEDIUM6.29
openjdk21-jre
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-21932MEDIUM6.29
openjdk21-jre-headless
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-22235MEDIUM6.21
org.springframework.boot:spring-boot
3.3.6
fixed in 3.3.11, 3.4.5
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42579MEDIUM6.18
io.netty:netty-codec-dns
4.1.112.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42584MEDIUM6.18
io.netty:netty-codec-http
4.1.124.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.8%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-49268MEDIUM6.18
org.apache.shiro:shiro-core
1.13.0
fixed in 2.2.1, 3.0.0-alpha-2
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2024-8698MEDIUM6.16
org.keycloak:keycloak-saml-core
18.0.2
fixed in 22.0.13, 24.0.8, 25.0.6
2.0%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2025-11187MEDIUM6.1
libcrypto3
3.5.4-r0
fixed in 3.5.5-r0
4.5%
Low-Moderate Risk
Directly Exposed
CVE-2025-11187MEDIUM6.1
libssl3
3.5.4-r0
fixed in 3.5.5-r0
4.5%
Low-Moderate Risk
Directly Exposed
CVE-2026-22695MEDIUM6.03
libpng
1.6.53-r0
fixed in 1.6.54-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-31418MEDIUM6
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.17.13, 8.9.0
1.2%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-40973MEDIUM5.95
org.springframework.boot:spring-boot
3.3.6
fixed in 4.0.6, 3.5.14
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-31790MEDIUM5.9
libcrypto3
3.5.4-r0
fixed in 3.5.6-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-42764MEDIUM5.9
libcrypto3
3.5.4-r0
fixed in 3.5.7-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-31790MEDIUM5.9
libssl3
3.5.4-r0
fixed in 3.5.6-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-42764MEDIUM5.9
libssl3
3.5.4-r0
fixed in 3.5.7-r0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2019-7614MEDIUM5.9
org.elasticsearch:elasticsearch
2.4.3
fixed in 6.8.2, 7.2.1
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-45673MEDIUM5.78
io.netty:netty-resolver-dns
4.1.112.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-2673MEDIUM5.52
libcrypto3
3.5.4-r0
fixed in 3.5.6-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-2673MEDIUM5.52
libssl3
3.5.4-r0
fixed in 3.5.6-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59888MEDIUM5.52
com.fasterxml.jackson.core:jackson-databind
2.17.0
fixed in 2.18.8, 2.21.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-67735MEDIUM5.52
io.netty:netty-codec-http
4.1.124.Final
fixed in 4.2.8.Final, 4.1.129.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-41417MEDIUM5.52
io.netty:netty-codec-http
4.1.124.Final
fixed in 4.1.133.Final, 4.2.13.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42580MEDIUM5.52
io.netty:netty-codec-http
4.1.124.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-59900MEDIUM5.52
io.netty:netty-codec-http2
4.1.124.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-43827MEDIUM5.52
org.apache.shiro:shiro-core
1.13.0
fixed in 2.2.0, 3.0.0-alpha-2
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-43828MEDIUM5.52
org.apache.shiro:shiro-web
1.13.0
fixed in 2.2.0, 3.0.0-alpha-2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-0636MEDIUM5.52
org.bouncycastle:bcprov-jdk15to18
1.81
fixed in 1.84
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-0636MEDIUM5.52
org.bouncycastle:bcprov-jdk18on
1.81
fixed in 1.84
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-11143MEDIUM5.52
org.eclipse.jetty:jetty-http
12.0.17
fixed in 12.0.31, 12.1.5
0.2%
Theoretical Threat
Directly Exposed
CVE-2023-49921MEDIUM5.52
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.17.16, 8.11.2
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-11226MEDIUM5.44
ch.qos.logback:logback-core
1.5.16
fixed in 1.5.19, 1.3.16
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-34181MEDIUM5.35
libcrypto3
3.5.4-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
libcrypto3
3.5.4-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-34181MEDIUM5.35
libssl3
3.5.4-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
libssl3
3.5.4-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2021-22135MEDIUM5.3
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.11.2, 6.8.15
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2021-22137MEDIUM5.3
org.elasticsearch:elasticsearch
2.4.3
fixed in 7.11.2, 6.8.15
1.1%
Low-Moderate Risk
Directly Exposed
CVE-2025-9341MEDIUM5.27
org.bouncycastle:bc-fips
2.1.0
fixed in 2.1.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-21933MEDIUM5.18
openjdk21
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-21933MEDIUM5.18
openjdk21-jre
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-21933MEDIUM5.18
openjdk21-jre-headless
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-22227MEDIUM5.18
io.projectreactor.netty:reactor-netty-http
1.0.48
fixed in 1.3.0-M5, 1.2.8
0.3%
Theoretical Threat
Directly Exposed
CVE-2018-3824MEDIUM5.18
org.elasticsearch:elasticsearch
2.4.3
fixed in 5.6.9, 6.2.4
0.9%
Theoretical Threat
Directly Exposed
CVE-2025-15468MEDIUM5.02
libcrypto3
3.5.4-r0
fixed in 3.5.5-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-66199MEDIUM5.02
libcrypto3
3.5.4-r0
fixed in 3.5.5-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69420MEDIUM5.02
libcrypto3
3.5.4-r0
fixed in 3.5.5-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-22796MEDIUM5.02
libcrypto3
3.5.4-r0
fixed in 3.5.5-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
libcrypto3
3.5.4-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
libcrypto3
3.5.4-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
libcrypto3
3.5.4-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-15468MEDIUM5.02
libssl3
3.5.4-r0
fixed in 3.5.5-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2025-66199MEDIUM5.02
libssl3
3.5.4-r0
fixed in 3.5.5-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-69420MEDIUM5.02
libssl3
3.5.4-r0
fixed in 3.5.5-r0
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-22796MEDIUM5.02
libssl3
3.5.4-r0
fixed in 3.5.5-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
libssl3
3.5.4-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
libssl3
3.5.4-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
libssl3
3.5.4-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-9340MEDIUM5.02
org.bouncycastle:bc-fips
2.1.0
fixed in 2.1.1
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-41850MEDIUM5.02
org.springframework:spring-expression
6.1.15
fixed in 7.0.8, 6.2.19
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM5
libcrypto3
3.5.4-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2026-34180MEDIUM5
libssl3
3.5.4-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2020-7021MEDIUM4.9
org.elasticsearch:elasticsearch
2.4.3
fixed in 6.8.14, 7.10.0
1.3%
Low-Moderate Risk
Directly Exposed
CVE-2019-7611MEDIUM4.86
org.elasticsearch:elasticsearch
2.4.3
fixed in 5.6.15, 6.6.1
2.1%
Low-Moderate Risk
Directly Exposed
CVE-2026-59921MEDIUM4.84
io.netty:netty-codec-http
4.1.124.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2025-15469MEDIUM4.67
libcrypto3
3.5.4-r0
fixed in 3.5.5-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-22795MEDIUM4.67
libcrypto3
3.5.4-r0
fixed in 3.5.5-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
libcrypto3
3.5.4-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2025-15469MEDIUM4.67
libssl3
3.5.4-r0
fixed in 3.5.5-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-22795MEDIUM4.67
libssl3
3.5.4-r0
fixed in 3.5.5-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
libssl3
3.5.4-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-6042MEDIUM4.67
musl
1.2.5-r21
fixed in 1.2.5-r22
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27171MEDIUM4.67
zlib
1.3.1-r2
fixed in 1.3.2-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
libcrypto3
3.5.4-r0
fixed in 3.5.7-r0
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
libcrypto3
3.5.4-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
libssl3
3.5.4-r0
fixed in 3.5.7-r0
1.0%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
libssl3
3.5.4-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-22013MEDIUM4.5
openjdk21
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-22021MEDIUM4.5
openjdk21
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-23865MEDIUM4.5
openjdk21
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-22013MEDIUM4.5
openjdk21-jre
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-22021MEDIUM4.5
openjdk21-jre
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-23865MEDIUM4.5
openjdk21-jre
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-22013MEDIUM4.5
openjdk21-jre-headless
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-22021MEDIUM4.5
openjdk21-jre-headless
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-23865MEDIUM4.5
openjdk21-jre-headless
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-54514MEDIUM4.5
com.fasterxml.jackson.core:jackson-databind
2.17.0
fixed in 2.18.8, 2.21.4, 3.1.4
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-54515MEDIUM4.5
com.fasterxml.jackson.core:jackson-databind
2.17.0
fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-50020MEDIUM4.5
io.netty:netty-codec-http
4.1.124.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-59898MEDIUM4.5
io.netty:netty-codec-http
4.1.124.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-47244MEDIUM4.5
io.netty:netty-codec-http2
4.1.124.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-50560MEDIUM4.5
io.netty:netty-codec-http2
4.1.124.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-23903MEDIUM4.5
org.apache.shiro:shiro-spring
1.13.0
fixed in 2.1.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-2575MEDIUM4.5
org.keycloak:keycloak-saml-adapter-core
18.0.2
fixed in 26.5.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-2575MEDIUM4.5
org.keycloak:keycloak-saml-core
18.0.2
fixed in 26.5.4
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-41852MEDIUM4.5
org.springframework:spring-expression
6.1.15
fixed in 7.0.8, 6.2.19
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-47554MEDIUM4.3
commons-io:commons-io
2.8.0
fixed in 2.14.0
1.2%
Low-Moderate Risk
Directly Exposed
CVE-2026-1225MEDIUM4.25
ch.qos.logback:logback-core
1.5.16
fixed in 1.5.25
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-21925MEDIUM4.08
openjdk21
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-21925MEDIUM4.08
openjdk21-jre
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-21925MEDIUM4.08
openjdk21-jre-headless
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-15467MEDIUM4.06
libcrypto3
3.5.4-r0
fixed in 3.5.5-r0
47.6%
High Exploitation Risk
Post-Exploit
CVE-2025-15467MEDIUM4.06
libssl3
3.5.4-r0
fixed in 3.5.5-r0
47.6%
High Exploitation Risk
Post-Exploit
CVE-2025-15467MEDIUM4.06
openssl
3.5.4-r0
fixed in 3.5.5-r0
47.6%
High Exploitation Risk
Post-Exploit
CVE-2025-68160MEDIUM4
libcrypto3
3.5.4-r0
fixed in 3.5.5-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-68160MEDIUM4
libssl3
3.5.4-r0
fixed in 3.5.5-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5773LOW3.82
curl
8.17.0-r1
fixed in 8.20.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-6276LOW3.82
curl
8.17.0-r1
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-5773LOW3.82
libcurl
8.17.0-r1
fixed in 8.20.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-6276LOW3.82
libcurl
8.17.0-r1
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-21945LOW3.82
openjdk21-jdk
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-22016LOW3.82
openjdk21-jdk
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-34282LOW3.82
openjdk21-jdk
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-21932LOW3.77
openjdk21-jdk
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-69419LOW3.77
openssl
3.5.4-r0
fixed in 3.5.5-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-34182LOW3.77
openssl
3.5.4-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-34757LOW3.74
libpng
1.6.53-r0
fixed in 1.6.57-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-11187LOW3.66
openssl
3.5.4-r0
fixed in 3.5.5-r0
4.5%
Low-Moderate Risk
Post-Exploit
CVE-2026-31790LOW3.54
openssl
3.5.4-r0
fixed in 3.5.6-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-42764LOW3.54
openssl
3.5.4-r0
fixed in 3.5.7-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-1965LOW3.47
curl
8.17.0-r1
fixed in 8.19.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-14819LOW3.47
curl
8.17.0-r1
fixed in 8.19.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-1965LOW3.47
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-14819LOW3.47
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2025-69418LOW3.4
libcrypto3
3.5.4-r0
fixed in 3.5.5-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-69418LOW3.4
libssl3
3.5.4-r0
fixed in 3.5.5-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-45536LOW3.4
io.netty:netty-transport-native-epoll
4.1.118.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-45536LOW3.4
io.netty:netty-transport-native-kqueue
4.1.118.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-12194LOW3.4
org.bouncycastle:bc-fips
2.1.0
fixed in 2.1.2
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-3784LOW3.31
curl
8.17.0-r1
fixed in 8.19.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-5545LOW3.31
curl
8.17.0-r1
fixed in 8.20.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6429LOW3.31
curl
8.17.0-r1
fixed in 8.20.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-14524LOW3.31
curl
8.17.0-r1
fixed in 8.19.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-3784LOW3.31
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-5545LOW3.31
libcurl
8.17.0-r1
fixed in 8.20.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6429LOW3.31
libcurl
8.17.0-r1
fixed in 8.20.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-14524LOW3.31
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-2673LOW3.31
openssl
3.5.4-r0
fixed in 3.5.6-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-3805LOW3.21
curl
8.17.0-r1
fixed in 8.19.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-3805LOW3.21
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-34181LOW3.21
openssl
3.5.4-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-42768LOW3.21
openssl
3.5.4-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-45446LOW3.15
libcrypto3
3.5.4-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
libssl3
3.5.4-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-22018LOW3.15
openjdk21
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-22018LOW3.15
openjdk21-jre
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-22018LOW3.15
openjdk21-jre-headless
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-21933LOW3.11
openjdk21-jdk
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2020-7020LOW3.1
org.elasticsearch:elasticsearch
2.4.3
fixed in 6.8.13, 7.9.2
1.0%
Low-Moderate Risk
Directly Exposed
CVE-2025-15468LOW3.01
openssl
3.5.4-r0
fixed in 3.5.5-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2025-66199LOW3.01
openssl
3.5.4-r0
fixed in 3.5.5-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-69420LOW3.01
openssl
3.5.4-r0
fixed in 3.5.5-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-22796LOW3.01
openssl
3.5.4-r0
fixed in 3.5.5-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-42769LOW3.01
openssl
3.5.4-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-42770LOW3.01
openssl
3.5.4-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-9076LOW3.01
openssl
3.5.4-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-31789LOW3
libcrypto3
3.5.4-r0
fixed in 3.5.6-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-31789LOW3
libssl3
3.5.4-r0
fixed in 3.5.6-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-31789LOW3
openssl
3.5.4-r0
fixed in 3.5.6-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-34180LOW3
openssl
3.5.4-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
libcrypto3
3.5.4-r0
fixed in 3.5.7-r0
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
libssl3
3.5.4-r0
fixed in 3.5.7-r0
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
openssl
3.5.4-r0
fixed in 3.5.7-r0
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-3783LOW2.91
curl
8.17.0-r1
fixed in 8.19.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-3783LOW2.91
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-15469LOW2.8
openssl
3.5.4-r0
fixed in 3.5.5-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-22795LOW2.8
openssl
3.5.4-r0
fixed in 3.5.5-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-7383LOW2.8
openssl
3.5.4-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
libcrypto3
3.5.4-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
libssl3
3.5.4-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl
3.5.4-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-28388LOW2.7
openssl
3.5.4-r0
fixed in 3.5.6-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-28389LOW2.7
openssl
3.5.4-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-28390LOW2.7
openssl
3.5.4-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-34183LOW2.7
openssl
3.5.4-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-2100LOW2.7
p11-kit
0.25.5-r2
fixed in 0.26.2-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-2100LOW2.7
p11-kit-trust
0.25.5-r2
fixed in 0.26.2-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-4873LOW2.7
curl
8.17.0-r1
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6253LOW2.7
curl
8.17.0-r1
fixed in 8.20.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-7009LOW2.7
curl
8.17.0-r1
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-7168LOW2.7
curl
8.17.0-r1
fixed in 8.20.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-4873LOW2.7
libcurl
8.17.0-r1
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6253LOW2.7
libcurl
8.17.0-r1
fixed in 8.20.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-7009LOW2.7
libcurl
8.17.0-r1
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-7168LOW2.7
libcurl
8.17.0-r1
fixed in 8.20.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-22013LOW2.7
openjdk21-jdk
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-22021LOW2.7
openjdk21-jdk
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-23865LOW2.7
openjdk21-jdk
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-42766LOW2.7
openssl
3.5.4-r0
fixed in 3.5.7-r0
1.0%
Theoretical Threat
Post-Exploit
CVE-2026-42767LOW2.7
openssl
3.5.4-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-28387LOW2.48
openssl
3.5.4-r0
fixed in 3.5.6-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-22007LOW2.46
openjdk21
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-34268LOW2.46
openjdk21
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-22007LOW2.46
openjdk21-jre
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-34268LOW2.46
openjdk21-jre
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-22007LOW2.46
openjdk21-jre-headless
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-34268LOW2.46
openjdk21-jre-headless
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-14017LOW2.45
curl
8.17.0-r1
fixed in 8.19.0-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-14017LOW2.45
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-21925LOW2.45
openjdk21-jdk
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-68160LOW2.4
openssl
3.5.4-r0
fixed in 3.5.5-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2025-69421LOW2.29
openssl
3.5.4-r0
fixed in 3.5.5-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-23901LOW2.12
org.apache.shiro:shiro-core
1.13.0
fixed in 2.1.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2025-69418LOW2.04
openssl
3.5.4-r0
fixed in 3.5.5-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-22018LOW1.89
openjdk21-jdk
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45446LOW1.89
openssl
3.5.4-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2025-9092LOW1.53
org.bouncycastle:bc-fips
2.1.0
fixed in 2.1.1
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-22007LOW1.48
openjdk21-jdk
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-34268LOW1.48
openjdk21-jdk
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-40200NONE0
musl-utils
1.2.5-r21
fixed in 1.2.5-r23
0.2%
Theoretical Threat
Not Applicable
CVE-2026-21945NONE0
openjdk21-demos
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.9%
Theoretical Threat
Not Applicable
CVE-2026-22016NONE0
openjdk21-demos
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-34282NONE0
openjdk21-demos
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-21945NONE0
openjdk21-doc
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.9%
Theoretical Threat
Not Applicable
CVE-2026-22016NONE0
openjdk21-doc
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-34282NONE0
openjdk21-doc
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-21945NONE0
openjdk21-jmods
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.9%
Theoretical Threat
Not Applicable
CVE-2026-22016NONE0
openjdk21-jmods
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-34282NONE0
openjdk21-jmods
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-21932NONE0
openjdk21-demos
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-21932NONE0
openjdk21-doc
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-21932NONE0
openjdk21-jmods
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-21933NONE0
openjdk21-demos
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-21933NONE0
openjdk21-doc
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-21933NONE0
openjdk21-jmods
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-6042NONE0
musl-utils
1.2.5-r21
fixed in 1.2.5-r22
0.2%
Theoretical Threat
Not Applicable
CVE-2026-22013NONE0
openjdk21-demos
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22021NONE0
openjdk21-demos
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-23865NONE0
openjdk21-demos
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22013NONE0
openjdk21-doc
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22021NONE0
openjdk21-doc
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-23865NONE0
openjdk21-doc
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22013NONE0
openjdk21-jmods
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22021NONE0
openjdk21-jmods
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-23865NONE0
openjdk21-jmods
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-21925NONE0
openjdk21-demos
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-21925NONE0
openjdk21-doc
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-21925NONE0
openjdk21-jmods
21.0.9_p10-r0
fixed in 21.0.10_p7-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-22018NONE0
openjdk21-demos
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22018NONE0
openjdk21-doc
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22018NONE0
openjdk21-jmods
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2025-48924NONE0
commons-lang:commons-lang
2.6
No fix yet
2.2%
Low-Moderate Risk
Not Applicable
CVE-2026-22007NONE0
openjdk21-demos
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-34268NONE0
openjdk21-demos
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22007NONE0
openjdk21-doc
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-34268NONE0
openjdk21-doc
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22007NONE0
openjdk21-jmods
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-34268NONE0
openjdk21-jmods
21.0.9_p10-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-40930NONE0
libpng
1.6.53-r0
fixed in 1.6.58-r1
0.2%
Theoretical Threat
Not Applicable
CVE-2026-10532NONE0
ch.qos.logback:logback-core
1.5.16
fixed in 1.5.34
0.4%
Theoretical Threat
Not Applicable
CVE-2026-9828NONE0
ch.qos.logback:logback-core
1.5.16
fixed in 1.5.33
0.4%
Theoretical Threat
Not Applicable
GHSA-r7wm-3cxj-wff9NONE0
com.fasterxml.jackson.core:jackson-core
2.17.0
fixed in 2.18.8, 2.21.4, 2.22.1
Not Applicable
GHSA-72hv-8253-57qqNONE0
com.fasterxml.jackson.core:jackson-core
2.17.0
fixed in 2.21.1, 2.18.6
Not Applicable
GHSA-mfg7-5gfp-c4w3NONE0
io.netty:netty-codec-dns
4.1.112.Final
fixed in 4.2.16.Final, 4.1.136.Final
Not Applicable
CVE-2026-10050NONE0
org.eclipse.jetty.ee8:jetty-ee8-security
12.0.17
fixed in 12.0.36, 12.1.10
Not Applicable
CVE-2026-8384NONE0
org.eclipse.jetty:jetty-util
12.0.17
fixed in 12.0.35, 12.1.9
0.2%
Theoretical Threat
Not Applicable
CVE-2025-22233NONE0
org.springframework:spring-context
6.1.15
fixed in 6.2.7, 6.1.20
0.4%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.