Vulnerability Reportsonatype/nexus3:3.93.2-alpine

sonatype/nexus3:3.93.2-alpinesonatype/nexus3:3.93.2
digestsha256:c37df0fbbfb5a7cda4efffe1ff9402cad671f0bc11df0ebbfa5043049084f227

Executive Summary

Last scanned:

Threat Score
25/100NEEDS ATTENTION
Reputation
TRUSTED

This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. The most severe finding, CVE-2026-49268, could allow an attacker to bypass authentication or impersonate users if LDAP authentication is enabled. The other finding, CVE-2026-33630, could lead to denial of service through malicious DNS responses. Note: CVE-2026-49268 only applies if the LDAP authentication module (DefaultLdapRealm) is enabled; upgrading shiro-core to version 2.2.1 or later eliminates the risk. Upgrading c-ares to a patched version is the only full fix for CVE-2026-33630.

Vulnerabilities

Vulnerability Log

45 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-49268MEDIUM6.18
org.apache.shiro:shiro-core
1.13.0
fixed in 2.2.1, 3.0.0-alpha-2
0.5%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33630MEDIUM6
c-ares
1.34.6-r0
fixed in 1.34.8-r0
Directly ExposedContext importance: MEDIUM
CVE-2026-43827MEDIUM4.42
org.apache.shiro:shiro-core
1.13.0
fixed in 2.2.0, 3.0.0-alpha-2
0.4%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-43828MEDIUM4.42
org.apache.shiro:shiro-web
1.13.0
fixed in 2.2.0, 3.0.0-alpha-2
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-11586LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-12064LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8927LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-8932LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-9545LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-9546LOW3.82
curl
8.20.0-r1
fixed in 8.21.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-11586LOW3.82
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-12064LOW3.82
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8927LOW3.82
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-8932LOW3.82
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-9545LOW3.82
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-9546LOW3.82
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-9547LOW3.77
curl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-9547LOW3.77
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-9080LOW3.72
curl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-9080LOW3.72
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-54515LOW3.6
com.fasterxml.jackson.core:jackson-databind
2.22.0
fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-11564LOW3.31
curl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8924LOW3.31
curl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-11564LOW3.31
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8924LOW3.31
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8925LOW2.92
curl
8.20.0-r1
fixed in 8.21.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-8925LOW2.92
libcurl
8.20.0-r1
fixed in 8.21.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-11352LOW2.7
curl
8.20.0-r1
fixed in 8.21.0-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-9079LOW2.7
curl
8.20.0-r1
fixed in 8.21.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-11352LOW2.7
libcurl
8.20.0-r1
fixed in 8.21.0-r0
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-9079LOW2.7
libcurl
8.20.0-r1
fixed in 8.21.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-23903LOW2.7
org.apache.shiro:shiro-spring
1.13.0
fixed in 2.1.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-8286LOW2.48
curl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-8286LOW2.48
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-8926LOW2.45
curl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-8926LOW2.45
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-10536LOW2.4
curl
8.20.0-r1
fixed in 8.21.0-r0
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-10536LOW2.4
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-11856LOW2.34
curl
8.20.0-r1
fixed in 8.21.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-11856LOW2.34
libcurl
8.20.0-r1
fixed in 8.21.0-r0
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-23901LOW2.12
org.apache.shiro:shiro-core
1.13.0
fixed in 2.1.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-8458NONE0
curl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-8458NONE0
libcurl
8.20.0-r1
fixed in 8.21.0-r0
0.5%
Theoretical Threat
Not Applicable
CVE-2026-10532NONE0
ch.qos.logback:logback-core
1.5.32
fixed in 1.5.34
0.3%
Theoretical Threat
Not Applicable
CVE-2026-9828NONE0
ch.qos.logback:logback-core
1.5.32
fixed in 1.5.33
0.4%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.