Vulnerability Reportsonatype/nexus3:3.90.2-alpine

sonatype/nexus3:3.90.2-alpine
digestsha256:900fddb217093ad70c1397a2bdc8498a4d10b3d2473a67dcf9debf9971d932a0

Executive Summary

Last scanned:

Threat Score
0/100NEEDS ATTENTION
Reputation
TRUSTED

AI verdict failed due to an error.

Vulnerabilities

Vulnerability Log

242 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-31789MEDIUM5
openssl
3.5.5-r0
fixed in 3.5.6-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-45447MEDIUM4.86
openssl
3.5.5-r0
fixed in 3.5.7-r0
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-45445MEDIUM4.64
openssl
3.5.5-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-28388MEDIUM4.5
openssl
3.5.5-r0
fixed in 3.5.6-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-28389MEDIUM4.5
openssl
3.5.5-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-28390MEDIUM4.5
openssl
3.5.5-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-34183MEDIUM4.5
openssl
3.5.5-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-28387MEDIUM4.13
openssl
3.5.5-r0
fixed in 3.5.6-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-5773LOW3.82
curl
8.17.0-r1
fixed in 8.20.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-6276LOW3.82
curl
8.17.0-r1
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-34182LOW3.77
openssl
3.5.5-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-31790LOW3.54
openssl
3.5.5-r0
fixed in 3.5.6-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-42764LOW3.54
openssl
3.5.5-r0
fixed in 3.5.7-r0
1.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-1965LOW3.47
curl
8.17.0-r1
fixed in 8.19.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-14819LOW3.47
curl
8.17.0-r1
fixed in 8.19.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-3784LOW3.31
curl
8.17.0-r1
fixed in 8.19.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-5545LOW3.31
curl
8.17.0-r1
fixed in 8.20.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6429LOW3.31
curl
8.17.0-r1
fixed in 8.20.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2025-14524LOW3.31
curl
8.17.0-r1
fixed in 8.19.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-2673LOW3.31
openssl
3.5.5-r0
fixed in 3.5.6-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-3805LOW3.21
curl
8.17.0-r1
fixed in 8.19.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-34181LOW3.21
openssl
3.5.5-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-42768LOW3.21
openssl
3.5.5-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-42769LOW3.01
openssl
3.5.5-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-42770LOW3.01
openssl
3.5.5-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-9076LOW3.01
openssl
3.5.5-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-34180LOW3
openssl
3.5.5-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-3783LOW2.91
curl
8.17.0-r1
fixed in 8.19.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-7383LOW2.8
openssl
3.5.5-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-4873LOW2.7
curl
8.17.0-r1
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-6253LOW2.7
curl
8.17.0-r1
fixed in 8.20.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-7009LOW2.7
curl
8.17.0-r1
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-7168LOW2.7
curl
8.17.0-r1
fixed in 8.20.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-42766LOW2.7
openssl
3.5.5-r0
fixed in 3.5.7-r0
1.0%
Theoretical Threat
Post-Exploit
CVE-2026-42767LOW2.7
openssl
3.5.5-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2025-14017LOW2.45
curl
8.17.0-r1
fixed in 8.19.0-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-45446LOW1.89
openssl
3.5.5-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-45674NONE0
io.netty:netty-resolver-dns
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Not Applicable
CVE-2026-47691NONE0
io.netty:netty-resolver-dns
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-31789NONE0
libcrypto3
3.5.5-r0
fixed in 3.5.6-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-31789NONE0
libssl3
3.5.5-r0
fixed in 3.5.6-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-42581NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2026-45445NONE0
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-45445NONE0
libssl3
3.5.5-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42579NONE0
io.netty:netty-codec-dns
4.2.9.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Not Applicable
CVE-2026-42584NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.8%
Theoretical Threat
Not Applicable
CVE-2026-49268NONE0
org.apache.shiro:shiro-core
1.13.0
fixed in 2.2.1, 3.0.0-alpha-2
0.5%
Theoretical Threat
Not Applicable
CVE-2026-2332NONE0
org.eclipse.jetty:jetty-http
12.0.17
fixed in 12.1.7, 12.0.33
1.1%
Low-Moderate Risk
Not Applicable
CVE-2025-67030NONE0
org.codehaus.plexus:plexus-utils
3.5.1
fixed in 4.0.3, 3.6.1
0.7%
Theoretical Threat
Not Applicable
CVE-2026-28387NONE0
libcrypto3
3.5.5-r0
fixed in 3.5.6-r0
0.8%
Theoretical Threat
Not Applicable
CVE-2026-45447NONE0
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
5.2%
Low-Moderate Risk
Not Applicable
CVE-2026-28387NONE0
libssl3
3.5.5-r0
fixed in 3.5.6-r0
0.8%
Theoretical Threat
Not Applicable
CVE-2026-45447NONE0
libssl3
3.5.5-r0
fixed in 3.5.7-r0
5.2%
Low-Moderate Risk
Not Applicable
CVE-2026-54512NONE0
com.fasterxml.jackson.core:jackson-databind
2.20.1
fixed in 2.18.8, 3.1.4, 2.21.4
0.8%
Theoretical Threat
Not Applicable
CVE-2026-54513NONE0
com.fasterxml.jackson.core:jackson-databind
2.20.1
fixed in 2.18.8, 2.21.4, 3.1.4
0.7%
Theoretical Threat
Not Applicable
CVE-2026-44249NONE0
io.netty:netty-handler
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2026-47838NONE0
org.springframework.security:spring-security-web
6.5.6
fixed in 6.5.11
0.1%
Theoretical Threat
Not Applicable
CVE-2026-40200NONE0
musl
1.2.5-r21
fixed in 1.2.5-r23
0.2%
Theoretical Threat
Not Applicable
CVE-2026-40200NONE0
musl-utils
1.2.5-r21
fixed in 1.2.5-r23
0.2%
Theoretical Threat
Not Applicable
CVE-2026-22184NONE0
zlib
1.3.1-r2
fixed in 1.3.2-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-33636NONE0
libpng
1.6.55-r0
fixed in 1.6.56-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-33630NONE0
c-ares
1.34.6-r0
fixed in 1.34.8-r0
Not Applicable
CVE-2026-41254NONE0
lcms2
2.17-r0
fixed in 2.19-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-28388NONE0
libcrypto3
3.5.5-r0
fixed in 3.5.6-r0
1.1%
Low-Moderate Risk
Not Applicable
CVE-2026-28389NONE0
libcrypto3
3.5.5-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-28390NONE0
libcrypto3
3.5.5-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-34183NONE0
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-5773NONE0
libcurl
8.17.0-r1
fixed in 8.20.0-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-6276NONE0
libcurl
8.17.0-r1
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-33416NONE0
libpng
1.6.55-r0
fixed in 1.6.56-r0
1.1%
Low-Moderate Risk
Not Applicable
CVE-2026-28388NONE0
libssl3
3.5.5-r0
fixed in 3.5.6-r0
1.1%
Low-Moderate Risk
Not Applicable
CVE-2026-28389NONE0
libssl3
3.5.5-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-28390NONE0
libssl3
3.5.5-r0
fixed in 3.5.6-r0
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-34183NONE0
libssl3
3.5.5-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-27135NONE0
nghttp2-libs
1.68.0-r0
fixed in 1.68.1
0.8%
Theoretical Threat
Not Applicable
CVE-2026-22016NONE0
openjdk21
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-34282NONE0
openjdk21
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-22016NONE0
openjdk21-demos
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-34282NONE0
openjdk21-demos
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-22016NONE0
openjdk21-doc
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-34282NONE0
openjdk21-doc
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-22016NONE0
openjdk21-jdk
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-34282NONE0
openjdk21-jdk
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-22016NONE0
openjdk21-jmods
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-34282NONE0
openjdk21-jmods
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-22016NONE0
openjdk21-jre
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-34282NONE0
openjdk21-jre
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-22016NONE0
openjdk21-jre-headless
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-34282NONE0
openjdk21-jre-headless
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-2100NONE0
p11-kit
0.25.5-r2
fixed in 0.26.2-r0
1.2%
Low-Moderate Risk
Not Applicable
CVE-2026-2100NONE0
p11-kit-trust
0.25.5-r2
fixed in 0.26.2-r0
1.2%
Low-Moderate Risk
Not Applicable
CVE-2026-42583NONE0
io.netty:netty-codec-compression
4.2.9.Final
fixed in 4.2.13.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-59901NONE0
io.netty:netty-codec-compression
4.2.9.Final
fixed in 4.2.16.Final
0.2%
Theoretical Threat
Not Applicable
CVE-2026-33870NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.1.132.Final, 4.2.10.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42587NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Not Applicable
CVE-2026-55831NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-55833NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-56745NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.5%
Theoretical Threat
Not Applicable
CVE-2026-42585NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.2%
Theoretical Threat
Not Applicable
CVE-2026-56746NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-59899NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-33871NONE0
io.netty:netty-codec-http2
4.2.9.Final
fixed in 4.1.132.Final, 4.2.11.Final
1.1%
Low-Moderate Risk
Not Applicable
CVE-2026-42587NONE0
io.netty:netty-codec-http2
4.2.9.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Not Applicable
CVE-2026-56819NONE0
io.netty:netty-codec-http2
4.2.9.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-48043NONE0
io.netty:netty-codec-http2
4.2.9.Final
fixed in 4.1.135.Final, 4.2.15.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2026-45416NONE0
io.netty:netty-handler
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.5%
Theoretical Threat
Not Applicable
CVE-2026-50010NONE0
io.netty:netty-handler
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42578NONE0
io.netty:netty-handler-proxy
4.2.9.Final
fixed in 4.1.133.Final, 4.2.13.Final
1.0%
Theoretical Threat
Not Applicable
CVE-2026-45292NONE0
io.opentelemetry:opentelemetry-api
1.47.0
fixed in 1.62.0
1.1%
Low-Moderate Risk
Not Applicable
CVE-2026-3505NONE0
org.bouncycastle:bcpg-jdk15to18
1.81
fixed in 1.84
0.8%
Theoretical Threat
Not Applicable
CVE-2026-5588NONE0
org.bouncycastle:bcpkix-jdk15to18
1.81
fixed in 1.84
0.4%
Theoretical Threat
Not Applicable
CVE-2026-5588NONE0
org.bouncycastle:bcpkix-jdk18on
1.81
fixed in 1.84
0.4%
Theoretical Threat
Not Applicable
CVE-2025-14813NONE0
org.bouncycastle:bcprov-jdk15to18
1.81
fixed in 1.84
0.3%
Theoretical Threat
Not Applicable
CVE-2025-14813NONE0
org.bouncycastle:bcprov-jdk18on
1.81
fixed in 1.80.2, 1.81.1, 1.84
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42198NONE0
org.postgresql:postgresql
42.7.2
fixed in 42.7.11
0.8%
Theoretical Threat
Not Applicable
CVE-2026-41848NONE0
org.springframework:spring-core
6.2.11
fixed in 7.0.8, 6.2.19
0.3%
Theoretical Threat
Not Applicable
CVE-2026-41851NONE0
org.springframework:spring-expression
6.2.11
fixed in 7.0.8, 6.2.19
0.4%
Theoretical Threat
Not Applicable
CVE-2026-34182NONE0
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-34182NONE0
libssl3
3.5.5-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-40973NONE0
org.springframework.boot:spring-boot
3.3.11
fixed in 4.0.6, 3.5.14
0.1%
Theoretical Threat
Not Applicable
CVE-2026-1965NONE0
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2025-14819NONE0
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-45673NONE0
io.netty:netty-resolver-dns
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-2673NONE0
libcrypto3
3.5.5-r0
fixed in 3.5.6-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-3784NONE0
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-5545NONE0
libcurl
8.17.0-r1
fixed in 8.20.0-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-6429NONE0
libcurl
8.17.0-r1
fixed in 8.20.0-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2025-14524NONE0
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-2673NONE0
libssl3
3.5.5-r0
fixed in 3.5.6-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-59888NONE0
com.fasterxml.jackson.core:jackson-databind
2.20.1
fixed in 2.18.8, 2.21.4
0.2%
Theoretical Threat
Not Applicable
CVE-2026-41417NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.1.133.Final, 4.2.13.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42580NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-59900NONE0
io.netty:netty-codec-http2
4.2.9.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-43827NONE0
org.apache.shiro:shiro-core
1.13.0
fixed in 2.2.0, 3.0.0-alpha-2
0.4%
Theoretical Threat
Not Applicable
CVE-2026-43828NONE0
org.apache.shiro:shiro-web
1.13.0
fixed in 2.2.0, 3.0.0-alpha-2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-0636NONE0
org.bouncycastle:bcprov-jdk15to18
1.81
fixed in 1.84
0.5%
Theoretical Threat
Not Applicable
CVE-2026-0636NONE0
org.bouncycastle:bcprov-jdk18on
1.81
fixed in 1.84
0.5%
Theoretical Threat
Not Applicable
CVE-2025-11143NONE0
org.eclipse.jetty:jetty-http
12.0.17
fixed in 12.0.31, 12.1.5
0.2%
Theoretical Threat
Not Applicable
CVE-2026-22732NONE0
org.springframework.security:spring-security-web
6.5.6
fixed in 6.5.9, 7.0.4
0.5%
Theoretical Threat
Not Applicable
CVE-2026-34181NONE0
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-42768NONE0
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-3805NONE0
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-34181NONE0
libssl3
3.5.5-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-42768NONE0
libssl3
3.5.5-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-31790NONE0
libcrypto3
3.5.5-r0
fixed in 3.5.6-r0
1.2%
Low-Moderate Risk
Not Applicable
CVE-2026-42764NONE0
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
1.2%
Low-Moderate Risk
Not Applicable
CVE-2026-42769NONE0
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42770NONE0
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-9076NONE0
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-31790NONE0
libssl3
3.5.5-r0
fixed in 3.5.6-r0
1.2%
Low-Moderate Risk
Not Applicable
CVE-2026-42764NONE0
libssl3
3.5.5-r0
fixed in 3.5.7-r0
1.2%
Low-Moderate Risk
Not Applicable
CVE-2026-42769NONE0
libssl3
3.5.5-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42770NONE0
libssl3
3.5.5-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-9076NONE0
libssl3
3.5.5-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-41850NONE0
org.springframework:spring-expression
6.2.11
fixed in 7.0.8, 6.2.19
0.4%
Theoretical Threat
Not Applicable
CVE-2026-3783NONE0
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-59921NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-7383NONE0
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-7383NONE0
libssl3
3.5.5-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-6042NONE0
musl
1.2.5-r21
fixed in 1.2.5-r22
0.2%
Theoretical Threat
Not Applicable
CVE-2026-6042NONE0
musl-utils
1.2.5-r21
fixed in 1.2.5-r22
0.2%
Theoretical Threat
Not Applicable
CVE-2026-27171NONE0
zlib
1.3.1-r2
fixed in 1.3.2-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-42766NONE0
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
1.0%
Theoretical Threat
Not Applicable
CVE-2026-42767NONE0
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-4873NONE0
libcurl
8.17.0-r1
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-6253NONE0
libcurl
8.17.0-r1
fixed in 8.20.0-r0
0.7%
Theoretical Threat
Not Applicable
CVE-2026-7009NONE0
libcurl
8.17.0-r1
fixed in 8.20.0-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-7168NONE0
libcurl
8.17.0-r1
fixed in 8.20.0-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-42766NONE0
libssl3
3.5.5-r0
fixed in 3.5.7-r0
1.0%
Theoretical Threat
Not Applicable
CVE-2026-42767NONE0
libssl3
3.5.5-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Not Applicable
CVE-2026-22013NONE0
openjdk21
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22021NONE0
openjdk21
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-23865NONE0
openjdk21
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22013NONE0
openjdk21-demos
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22021NONE0
openjdk21-demos
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-23865NONE0
openjdk21-demos
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22013NONE0
openjdk21-doc
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22021NONE0
openjdk21-doc
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-23865NONE0
openjdk21-doc
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22013NONE0
openjdk21-jdk
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22021NONE0
openjdk21-jdk
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-23865NONE0
openjdk21-jdk
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22013NONE0
openjdk21-jmods
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22021NONE0
openjdk21-jmods
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-23865NONE0
openjdk21-jmods
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22013NONE0
openjdk21-jre
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22021NONE0
openjdk21-jre
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-23865NONE0
openjdk21-jre
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22013NONE0
openjdk21-jre-headless
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22021NONE0
openjdk21-jre-headless
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-23865NONE0
openjdk21-jre-headless
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-54514NONE0
com.fasterxml.jackson.core:jackson-databind
2.20.1
fixed in 2.18.8, 2.21.4, 3.1.4
0.2%
Theoretical Threat
Not Applicable
CVE-2026-54515NONE0
com.fasterxml.jackson.core:jackson-databind
2.20.1
fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1
0.3%
Theoretical Threat
Not Applicable
CVE-2026-50020NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Not Applicable
CVE-2026-59898NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-47244NONE0
io.netty:netty-codec-http2
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-50560NONE0
io.netty:netty-codec-http2
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-23903NONE0
org.apache.shiro:shiro-spring
1.13.0
fixed in 2.1.0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-41852NONE0
org.springframework:spring-expression
6.2.11
fixed in 7.0.8, 6.2.19
0.2%
Theoretical Threat
Not Applicable
CVE-2026-34180NONE0
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-34180NONE0
libssl3
3.5.5-r0
fixed in 3.5.7-r0
1.0%
Low-Moderate Risk
Not Applicable
CVE-2026-1225NONE0
ch.qos.logback:logback-core
1.5.19
fixed in 1.5.25
0.2%
Theoretical Threat
Not Applicable
CVE-2025-14017NONE0
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22751NONE0
org.springframework.security:spring-security-core
6.5.6
fixed in 6.5.10, 7.0.5
0.1%
Theoretical Threat
Not Applicable
CVE-2026-34757NONE0
libpng
1.6.55-r0
fixed in 1.6.57-r0
0.2%
Theoretical Threat
Not Applicable
CVE-2024-47554NONE0
commons-io:commons-io
2.8.0
fixed in 2.14.0
1.2%
Low-Moderate Risk
Not Applicable
CVE-2026-45536NONE0
io.netty:netty-transport-native-epoll
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.1%
Theoretical Threat
Not Applicable
CVE-2026-45536NONE0
io.netty:netty-transport-native-kqueue
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.1%
Theoretical Threat
Not Applicable
CVE-2026-45446NONE0
libcrypto3
3.5.5-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-45446NONE0
libssl3
3.5.5-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-22018NONE0
openjdk21
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22018NONE0
openjdk21-demos
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22018NONE0
openjdk21-doc
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22018NONE0
openjdk21-jdk
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22018NONE0
openjdk21-jmods
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22018NONE0
openjdk21-jre
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22018NONE0
openjdk21-jre-headless
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-22746NONE0
org.springframework.security:spring-security-core
6.5.6
fixed in 6.5.10, 7.0.5
0.2%
Theoretical Threat
Not Applicable
CVE-2026-22007NONE0
openjdk21
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-34268NONE0
openjdk21
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22007NONE0
openjdk21-demos
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-34268NONE0
openjdk21-demos
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22007NONE0
openjdk21-doc
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-34268NONE0
openjdk21-doc
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22007NONE0
openjdk21-jdk
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-34268NONE0
openjdk21-jdk
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22007NONE0
openjdk21-jmods
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-34268NONE0
openjdk21-jmods
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22007NONE0
openjdk21-jre
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-34268NONE0
openjdk21-jre
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22007NONE0
openjdk21-jre-headless
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-34268NONE0
openjdk21-jre-headless
21.0.10_p7-r0
fixed in 21.0.11_p10-r0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-23901NONE0
org.apache.shiro:shiro-core
1.13.0
fixed in 2.1.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-40930NONE0
libpng
1.6.55-r0
fixed in 1.6.58-r1
0.2%
Theoretical Threat
Not Applicable
CVE-2026-10532NONE0
ch.qos.logback:logback-core
1.5.19
fixed in 1.5.34
0.4%
Theoretical Threat
Not Applicable
CVE-2026-9828NONE0
ch.qos.logback:logback-core
1.5.19
fixed in 1.5.33
0.4%
Theoretical Threat
Not Applicable
GHSA-r7wm-3cxj-wff9NONE0
com.fasterxml.jackson.core:jackson-core
2.20.1
fixed in 2.18.8, 2.21.4, 2.22.1
Not Applicable
GHSA-72hv-8253-57qqNONE0
com.fasterxml.jackson.core:jackson-core
2.20.1
fixed in 2.21.1, 2.18.6
Not Applicable
GHSA-mfg7-5gfp-c4w3NONE0
io.netty:netty-codec-dns
4.2.9.Final
fixed in 4.2.16.Final, 4.1.136.Final
Not Applicable
CVE-2026-42577NONE0
io.netty:netty-transport-classes-epoll
4.2.9.Final
fixed in 4.2.13.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-10050NONE0
org.eclipse.jetty.ee8:jetty-ee8-security
12.0.17
fixed in 12.0.36, 12.1.10
Not Applicable
CVE-2026-8384NONE0
org.eclipse.jetty:jetty-util
12.0.17
fixed in 12.0.35, 12.1.9
0.2%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.