Last scanned:
This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. The most severe finding, CVE-2026-49268, could allow an attacker to bypass authentication or impersonate users if LDAP authentication is enabled. The other finding, CVE-2026-33630, could lead to denial of service through malicious DNS responses. Note: CVE-2026-49268 only applies if the LDAP authentication module (DefaultLdapRealm) is enabled; upgrading shiro-core to version 2.2.1 or later eliminates the risk. Upgrading c-ares to a patched version is the only full fix for CVE-2026-33630.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-49268 | MEDIUM6.18 | org.apache.shiro:shiro-core 1.13.0 fixed in 2.2.1, 3.0.0-alpha-2 | 0.5% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-33630 | MEDIUM6 | c-ares 1.34.6-r0 fixed in 1.34.8-r0 | — | Directly ExposedContext importance: MEDIUM |
| CVE-2026-43827 | MEDIUM4.42 | org.apache.shiro:shiro-core 1.13.0 fixed in 2.2.0, 3.0.0-alpha-2 | 0.4% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-43828 | MEDIUM4.42 | org.apache.shiro:shiro-web 1.13.0 fixed in 2.2.0, 3.0.0-alpha-2 | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-11586 | LOW3.82 | curl 8.20.0-r1 fixed in 8.21.0-r0 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2026-12064 | LOW3.82 | curl 8.20.0-r1 fixed in 8.21.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-8927 | LOW3.82 | curl 8.20.0-r1 fixed in 8.21.0-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-8932 | LOW3.82 | curl 8.20.0-r1 fixed in 8.21.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-9545 | LOW3.82 | curl 8.20.0-r1 fixed in 8.21.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-9546 | LOW3.82 | curl 8.20.0-r1 fixed in 8.21.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-11586 | LOW3.82 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2026-12064 | LOW3.82 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-8927 | LOW3.82 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.8% Theoretical Threat | Post-Exploit |
| CVE-2026-8932 | LOW3.82 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-9545 | LOW3.82 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-9546 | LOW3.82 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.7% Theoretical Threat | Post-Exploit |
| CVE-2026-9547 | LOW3.77 | curl 8.20.0-r1 fixed in 8.21.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-9547 | LOW3.77 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-9080 | LOW3.72 | curl 8.20.0-r1 fixed in 8.21.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-9080 | LOW3.72 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-54515 | LOW3.6 | com.fasterxml.jackson.core:jackson-databind 2.22.0 fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1 | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-11564 | LOW3.31 | curl 8.20.0-r1 fixed in 8.21.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-8924 | LOW3.31 | curl 8.20.0-r1 fixed in 8.21.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-11564 | LOW3.31 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-8924 | LOW3.31 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-8925 | LOW2.92 | curl 8.20.0-r1 fixed in 8.21.0-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-8925 | LOW2.92 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-11352 | LOW2.7 | curl 8.20.0-r1 fixed in 8.21.0-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-9079 | LOW2.7 | curl 8.20.0-r1 fixed in 8.21.0-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-11352 | LOW2.7 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 1.0% Low-Moderate Risk | Post-Exploit |
| CVE-2026-9079 | LOW2.7 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-23903 | LOW2.7 | org.apache.shiro:shiro-spring 1.13.0 fixed in 2.1.0 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-8286 | LOW2.48 | curl 8.20.0-r1 fixed in 8.21.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-8286 | LOW2.48 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-8926 | LOW2.45 | curl 8.20.0-r1 fixed in 8.21.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-8926 | LOW2.45 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.6% Theoretical Threat | Post-Exploit |
| CVE-2026-10536 | LOW2.4 | curl 8.20.0-r1 fixed in 8.21.0-r0 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2026-10536 | LOW2.4 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.9% Theoretical Threat | Post-Exploit |
| CVE-2026-11856 | LOW2.34 | curl 8.20.0-r1 fixed in 8.21.0-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-11856 | LOW2.34 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 1.1% Low-Moderate Risk | Post-Exploit |
| CVE-2026-23901 | LOW2.12 | org.apache.shiro:shiro-core 1.13.0 fixed in 2.1.0 | 0.2% Theoretical Threat | Directly Exposed |
| CVE-2026-8458 | NONE0 | curl 8.20.0-r1 fixed in 8.21.0-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-8458 | NONE0 | libcurl 8.20.0-r1 fixed in 8.21.0-r0 | 0.5% Theoretical Threat | Not Applicable |
| CVE-2026-10532 | NONE0 | ch.qos.logback:logback-core 1.5.32 fixed in 1.5.34 | 0.3% Theoretical Threat | Not Applicable |
| CVE-2026-9828 | NONE0 | ch.qos.logback:logback-core 1.5.32 fixed in 1.5.33 | 0.4% Theoretical Threat | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.