Vulnerability Reportsonatype/nexus3:3.92.2

sonatype/nexus3:3.92.2-alpinesonatype/nexus3:3.92.2
DIGESTsha256:a32ae23e0fdacccc4f2a9cbf3aa613388d11a1495d5dd66c639c8e84ad39b179

Executive Summary

Threat Score
100/100DANGEROUS
Reputation
TRUSTED

This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could exploit DNS cache poisoning (CVE-2026-45674, CVE-2026-47691) to redirect artifact downloads to malicious sources, or use HTTP request smuggling (CVE-2026-42581) to bypass security controls and access sensitive data. The vulnerabilities are in core Netty components (DNS resolver, HTTP codec) that are essential for Nexus operation, and no full mitigations exist without disabling critical functionality.

Vulnerabilities

Vulnerability Log

143 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-45674HIGH8.5
io.netty:netty-resolver-dns
4.2.12.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-47691HIGH8.5
io.netty:netty-resolver-dns
4.2.12.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-42581HIGH8.33
io.netty:netty-codec-http
4.2.12.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.4%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-42579HIGH7.73
io.netty:netty-codec-dns
4.2.12.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.4%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-42584HIGH7.73
io.netty:netty-codec-http
4.2.12.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.3%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-22016MEDIUM6.38
openjdk25-jre
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.4%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-34282MEDIUM6.38
openjdk25-jre
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.3%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-22016MEDIUM6.38
openjdk25-jre-headless
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.4%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-34282MEDIUM6.38
openjdk25-jre-headless
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.3%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-42587MEDIUM6.38
io.netty:netty-codec-http
4.2.12.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.5%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-42585MEDIUM6.38
io.netty:netty-codec-http
4.2.12.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.2%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-42587MEDIUM6.38
io.netty:netty-codec-http2
4.2.12.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-48043MEDIUM6.38
io.netty:netty-codec-http2
4.2.12.Final
fixed in 4.1.135.Final, 4.2.15.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-45416MEDIUM6.38
io.netty:netty-handler
4.2.12.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-50010MEDIUM6.38
io.netty:netty-handler
4.2.12.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45292MEDIUM6.38
io.opentelemetry:opentelemetry-api
1.47.0
fixed in 1.62.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-34182MEDIUM6.29
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-34182MEDIUM6.29
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45673MEDIUM5.78
io.netty:netty-resolver-dns
4.2.12.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-41417MEDIUM5.52
io.netty:netty-codec-http
4.2.12.Final
fixed in 4.1.133.Final, 4.2.13.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42580MEDIUM5.52
io.netty:netty-codec-http
4.2.12.Final
fixed in 4.2.13.Final, 4.1.133.Final
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-44249MEDIUM5.5
io.netty:netty-handler
4.2.12.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-34181MEDIUM5.35
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34181MEDIUM5.35
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42768MEDIUM5.35
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42578MEDIUM5.1
io.netty:netty-handler-proxy
4.2.12.Final
fixed in 4.1.133.Final, 4.2.13.Final
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42198MEDIUM5.1
org.postgresql:postgresql
42.7.2
fixed in 42.7.11
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42764MEDIUM5.02
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42764MEDIUM5.02
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.7%
Theoretical Threat
Directly Exposed
CVE-2026-42769MEDIUM5.02
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42770MEDIUM5.02
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-9076MEDIUM5.02
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42766MEDIUM4.5
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42767MEDIUM4.5
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-22013MEDIUM4.5
openjdk25-jre
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-22021MEDIUM4.5
openjdk25-jre
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-23865MEDIUM4.5
openjdk25-jre
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-22013MEDIUM4.5
openjdk25-jre-headless
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-22021MEDIUM4.5
openjdk25-jre-headless
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-23865MEDIUM4.5
openjdk25-jre-headless
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-50020MEDIUM4.5
io.netty:netty-codec-http
4.2.12.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-47244MEDIUM4.5
io.netty:netty-codec-http2
4.2.12.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-50560MEDIUM4.5
io.netty:netty-codec-http2
4.2.12.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-23903MEDIUM4.5
org.apache.shiro:shiro-spring
1.13.0
fixed in 2.1.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM4.25
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-34180MEDIUM4.25
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-1225MEDIUM4.25
ch.qos.logback:logback-core
1.5.19
fixed in 1.5.25
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-34182LOW3.77
openssl
3.5.6-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-1965LOW3.47
curl
8.17.0-r1
fixed in 8.19.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-14819LOW3.47
curl
8.17.0-r1
fixed in 8.19.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-1965LOW3.47
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-14819LOW3.47
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-45536LOW3.4
io.netty:netty-transport-native-epoll
4.2.12.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45536LOW3.4
io.netty:netty-transport-native-kqueue
4.2.12.Final
fixed in 4.2.15.Final, 4.1.135.Final
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-3784LOW3.31
curl
8.17.0-r1
fixed in 8.19.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-14524LOW3.31
curl
8.17.0-r1
fixed in 8.19.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-3784LOW3.31
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2025-14524LOW3.31
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-3805LOW3.21
curl
8.17.0-r1
fixed in 8.19.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-3805LOW3.21
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-34181LOW3.21
openssl
3.5.6-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-42768LOW3.21
openssl
3.5.6-r0
fixed in 3.5.7-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-45446LOW3.15
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-45446LOW3.15
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-22008LOW3.15
openjdk25-jre
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-22018LOW3.15
openjdk25-jre
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-22008LOW3.15
openjdk25-jre-headless
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-22018LOW3.15
openjdk25-jre-headless
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42764LOW3.01
openssl
3.5.6-r0
fixed in 3.5.7-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-42769LOW3.01
openssl
3.5.6-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-42770LOW3.01
openssl
3.5.6-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-9076LOW3.01
openssl
3.5.6-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45447LOW2.92
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
libssl3
3.5.6-r0
fixed in 3.5.7-r0
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
openssl
3.5.6-r0
fixed in 3.5.7-r0
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2026-3783LOW2.91
curl
8.17.0-r1
fixed in 8.19.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-3783LOW2.91
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-7383LOW2.8
openssl
3.5.6-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45445LOW2.78
openssl
3.5.6-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-22013LOW2.7
openjdk25
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-22021LOW2.7
openjdk25
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-23865LOW2.7
openjdk25
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-22013LOW2.7
openjdk25-demos
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-22021LOW2.7
openjdk25-demos
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-23865LOW2.7
openjdk25-demos
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-22013LOW2.7
openjdk25-jdk
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-22021LOW2.7
openjdk25-jdk
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-23865LOW2.7
openjdk25-jdk
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-22013LOW2.7
openjdk25-jmods
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-22021LOW2.7
openjdk25-jmods
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-23865LOW2.7
openjdk25-jmods
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-42766LOW2.7
openssl
3.5.6-r0
fixed in 3.5.7-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-42767LOW2.7
openssl
3.5.6-r0
fixed in 3.5.7-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-34180LOW2.55
openssl
3.5.6-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-22007LOW2.46
openjdk25-jre
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-34268LOW2.46
openjdk25-jre
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-22007LOW2.46
openjdk25-jre-headless
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-34268LOW2.46
openjdk25-jre-headless
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.1%
Theoretical Threat
Directly Exposed
CVE-2025-14017LOW2.45
curl
8.17.0-r1
fixed in 8.19.0-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-14017LOW2.45
libcurl
8.17.0-r1
fixed in 8.19.0-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-34183LOW2.29
libcrypto3
3.5.6-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-34183LOW2.29
libssl3
3.5.6-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-22016LOW2.29
openjdk25
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-34282LOW2.29
openjdk25
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-22016LOW2.29
openjdk25-demos
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-34282LOW2.29
openjdk25-demos
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-22016LOW2.29
openjdk25-jdk
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-34282LOW2.29
openjdk25-jdk
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-22016LOW2.29
openjdk25-jmods
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-34282LOW2.29
openjdk25-jmods
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-34183LOW2.29
openssl
3.5.6-r0
fixed in 3.5.7-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-23901LOW2.12
org.apache.shiro:shiro-core
1.13.0
fixed in 2.1.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-22008LOW1.89
openjdk25
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-22018LOW1.89
openjdk25
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-22008LOW1.89
openjdk25-demos
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-22018LOW1.89
openjdk25-demos
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-22008LOW1.89
openjdk25-jdk
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-22018LOW1.89
openjdk25-jdk
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-22008LOW1.89
openjdk25-jmods
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-22018LOW1.89
openjdk25-jmods
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45446LOW1.89
openssl
3.5.6-r0
fixed in 3.5.7-r0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-22007LOW1.48
openjdk25
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-34268LOW1.48
openjdk25
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-22007LOW1.48
openjdk25-demos
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-34268LOW1.48
openjdk25-demos
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-22007LOW1.48
openjdk25-jdk
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-34268LOW1.48
openjdk25-jdk
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-22007LOW1.48
openjdk25-jmods
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-34268LOW1.48
openjdk25-jmods
25.0.2_p10-r1
fixed in 25.0.3_p9-r0
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-40930NONE0
libpng
1.6.57-r0
fixed in 1.6.58-r1
0.2%
Theoretical Threat
Not Applicable
CVE-2026-42583NONE0
io.netty:netty-codec-compression
4.2.12.Final
fixed in 4.2.13.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42577NONE0
io.netty:netty-transport-native-epoll
4.2.12.Final
fixed in 4.2.13.Final
0.4%
Theoretical Threat
Not Applicable
CVE-2026-8149NONE0
org.bouncycastle:bc-fips
2.1.2
No fix yet
0.2%
Theoretical Threat
Not Applicable