Vulnerability Reportsonatype/nexus3:3.90.4

sonatype/nexus3:3.90.4-alpinesonatype/nexus3:3.90.4
digestsha256:e71768c68f3bfd69b95735b7e328cd88a274135d3c448dafcdcc2555b3035ebe

Executive Summary

Last scanned:

Threat Score
0/100NEEDS ATTENTION
Reputation
TRUSTED

AI verdict failed due to an error.

Vulnerabilities

Vulnerability Log

75 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-45674NONE0
io.netty:netty-resolver-dns
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Not Applicable
CVE-2026-47691NONE0
io.netty:netty-resolver-dns
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42581NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42579NONE0
io.netty:netty-codec-dns
4.2.9.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Not Applicable
CVE-2026-42584NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.8%
Theoretical Threat
Not Applicable
CVE-2026-49268NONE0
org.apache.shiro:shiro-core
1.13.0
fixed in 2.2.1, 3.0.0-alpha-2
0.5%
Theoretical Threat
Not Applicable
CVE-2026-2332NONE0
org.eclipse.jetty:jetty-http
12.0.17
fixed in 12.1.7, 12.0.33
1.1%
Low-Moderate Risk
Not Applicable
CVE-2025-67030NONE0
org.codehaus.plexus:plexus-utils
3.5.1
fixed in 4.0.3, 3.6.1
0.7%
Theoretical Threat
Not Applicable
CVE-2026-54512NONE0
com.fasterxml.jackson.core:jackson-databind
2.20.1
fixed in 2.18.8, 3.1.4, 2.21.4
0.8%
Theoretical Threat
Not Applicable
CVE-2026-54513NONE0
com.fasterxml.jackson.core:jackson-databind
2.20.1
fixed in 2.18.8, 2.21.4, 3.1.4
0.7%
Theoretical Threat
Not Applicable
CVE-2026-44249NONE0
io.netty:netty-handler
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2026-47838NONE0
org.springframework.security:spring-security-web
6.5.6
fixed in 6.5.11
0.1%
Theoretical Threat
Not Applicable
CVE-2026-33630NONE0
c-ares
1.34.6-r0
fixed in 1.34.8-r0
Not Applicable
CVE-2026-42583NONE0
io.netty:netty-codec-compression
4.2.9.Final
fixed in 4.2.13.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-59901NONE0
io.netty:netty-codec-compression
4.2.9.Final
fixed in 4.2.16.Final
0.2%
Theoretical Threat
Not Applicable
CVE-2026-33870NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.1.132.Final, 4.2.10.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42587NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Not Applicable
CVE-2026-55831NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-55833NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-56745NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.5%
Theoretical Threat
Not Applicable
CVE-2026-42585NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.2%
Theoretical Threat
Not Applicable
CVE-2026-56746NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-59899NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-33871NONE0
io.netty:netty-codec-http2
4.2.9.Final
fixed in 4.1.132.Final, 4.2.11.Final
1.1%
Low-Moderate Risk
Not Applicable
CVE-2026-42587NONE0
io.netty:netty-codec-http2
4.2.9.Final
fixed in 4.2.13.Final, 4.1.133.Final
1.0%
Theoretical Threat
Not Applicable
CVE-2026-56819NONE0
io.netty:netty-codec-http2
4.2.9.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-48043NONE0
io.netty:netty-codec-http2
4.2.9.Final
fixed in 4.1.135.Final, 4.2.15.Final
0.6%
Theoretical Threat
Not Applicable
CVE-2026-45416NONE0
io.netty:netty-handler
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.5%
Theoretical Threat
Not Applicable
CVE-2026-50010NONE0
io.netty:netty-handler
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42578NONE0
io.netty:netty-handler-proxy
4.2.9.Final
fixed in 4.1.133.Final, 4.2.13.Final
1.0%
Theoretical Threat
Not Applicable
CVE-2026-45292NONE0
io.opentelemetry:opentelemetry-api
1.47.0
fixed in 1.62.0
1.1%
Low-Moderate Risk
Not Applicable
CVE-2026-3505NONE0
org.bouncycastle:bcpg-jdk15to18
1.81
fixed in 1.84
0.8%
Theoretical Threat
Not Applicable
CVE-2026-5588NONE0
org.bouncycastle:bcpkix-jdk15to18
1.81
fixed in 1.84
0.4%
Theoretical Threat
Not Applicable
CVE-2026-5588NONE0
org.bouncycastle:bcpkix-jdk18on
1.81
fixed in 1.84
0.4%
Theoretical Threat
Not Applicable
CVE-2025-14813NONE0
org.bouncycastle:bcprov-jdk15to18
1.81
fixed in 1.84
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42198NONE0
org.postgresql:postgresql
42.7.2
fixed in 42.7.11
0.8%
Theoretical Threat
Not Applicable
CVE-2026-41848NONE0
org.springframework:spring-core
6.2.11
fixed in 7.0.8, 6.2.19
0.3%
Theoretical Threat
Not Applicable
CVE-2026-41851NONE0
org.springframework:spring-expression
6.2.11
fixed in 7.0.8, 6.2.19
0.4%
Theoretical Threat
Not Applicable
CVE-2026-40973NONE0
org.springframework.boot:spring-boot
3.3.11
fixed in 4.0.6, 3.5.14
0.1%
Theoretical Threat
Not Applicable
CVE-2026-45673NONE0
io.netty:netty-resolver-dns
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-59888NONE0
com.fasterxml.jackson.core:jackson-databind
2.20.1
fixed in 2.18.8, 2.21.4
0.2%
Theoretical Threat
Not Applicable
CVE-2026-41417NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.1.133.Final, 4.2.13.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42580NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-59900NONE0
io.netty:netty-codec-http2
4.2.9.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-43827NONE0
org.apache.shiro:shiro-core
1.13.0
fixed in 2.2.0, 3.0.0-alpha-2
0.4%
Theoretical Threat
Not Applicable
CVE-2026-43828NONE0
org.apache.shiro:shiro-web
1.13.0
fixed in 2.2.0, 3.0.0-alpha-2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-0636NONE0
org.bouncycastle:bcprov-jdk15to18
1.81
fixed in 1.84
0.5%
Theoretical Threat
Not Applicable
CVE-2026-0636NONE0
org.bouncycastle:bcprov-jdk18on
1.81.1
fixed in 1.84
0.5%
Theoretical Threat
Not Applicable
CVE-2025-11143NONE0
org.eclipse.jetty:jetty-http
12.0.17
fixed in 12.0.31, 12.1.5
0.2%
Theoretical Threat
Not Applicable
CVE-2026-22732NONE0
org.springframework.security:spring-security-web
6.5.6
fixed in 6.5.9, 7.0.4
0.5%
Theoretical Threat
Not Applicable
CVE-2026-41850NONE0
org.springframework:spring-expression
6.2.11
fixed in 7.0.8, 6.2.19
0.4%
Theoretical Threat
Not Applicable
CVE-2026-59921NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-54514NONE0
com.fasterxml.jackson.core:jackson-databind
2.20.1
fixed in 2.18.8, 2.21.4, 3.1.4
0.2%
Theoretical Threat
Not Applicable
CVE-2026-54515NONE0
com.fasterxml.jackson.core:jackson-databind
2.20.1
fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1
0.3%
Theoretical Threat
Not Applicable
CVE-2026-50020NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Not Applicable
CVE-2026-59898NONE0
io.netty:netty-codec-http
4.2.9.Final
fixed in 4.2.16.Final, 4.1.136.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-47244NONE0
io.netty:netty-codec-http2
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-50560NONE0
io.netty:netty-codec-http2
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Not Applicable
CVE-2026-23903NONE0
org.apache.shiro:shiro-spring
1.13.0
fixed in 2.1.0
0.4%
Theoretical Threat
Not Applicable
CVE-2026-41852NONE0
org.springframework:spring-expression
6.2.11
fixed in 7.0.8, 6.2.19
0.2%
Theoretical Threat
Not Applicable
CVE-2026-1225NONE0
ch.qos.logback:logback-core
1.5.19
fixed in 1.5.25
0.2%
Theoretical Threat
Not Applicable
CVE-2026-22751NONE0
org.springframework.security:spring-security-core
6.5.6
fixed in 6.5.10, 7.0.5
0.1%
Theoretical Threat
Not Applicable
CVE-2024-47554NONE0
commons-io:commons-io
2.8.0
fixed in 2.14.0
1.2%
Low-Moderate Risk
Not Applicable
CVE-2026-45536NONE0
io.netty:netty-transport-native-epoll
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.1%
Theoretical Threat
Not Applicable
CVE-2026-45536NONE0
io.netty:netty-transport-native-kqueue
4.2.9.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.1%
Theoretical Threat
Not Applicable
CVE-2026-22746NONE0
org.springframework.security:spring-security-core
6.5.6
fixed in 6.5.10, 7.0.5
0.2%
Theoretical Threat
Not Applicable
CVE-2026-23901NONE0
org.apache.shiro:shiro-core
1.13.0
fixed in 2.1.0
0.2%
Theoretical Threat
Not Applicable
CVE-2026-10532NONE0
ch.qos.logback:logback-core
1.5.19
fixed in 1.5.34
0.4%
Theoretical Threat
Not Applicable
CVE-2026-9828NONE0
ch.qos.logback:logback-core
1.5.19
fixed in 1.5.33
0.4%
Theoretical Threat
Not Applicable
GHSA-r7wm-3cxj-wff9NONE0
com.fasterxml.jackson.core:jackson-core
2.20.1
fixed in 2.18.8, 2.21.4, 2.22.1
Not Applicable
GHSA-72hv-8253-57qqNONE0
com.fasterxml.jackson.core:jackson-core
2.20.1
fixed in 2.21.1, 2.18.6
Not Applicable
GHSA-mfg7-5gfp-c4w3NONE0
io.netty:netty-codec-dns
4.2.9.Final
fixed in 4.2.16.Final, 4.1.136.Final
Not Applicable
CVE-2026-42577NONE0
io.netty:netty-transport-classes-epoll
4.2.9.Final
fixed in 4.2.13.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-10050NONE0
org.eclipse.jetty.ee8:jetty-ee8-security
12.0.17
fixed in 12.0.36, 12.1.10
Not Applicable
CVE-2026-8384NONE0
org.eclipse.jetty:jetty-util
12.0.17
fixed in 12.0.35, 12.1.9
0.2%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.