This image is safe for production use. It has no exploitable vulnerabilities on the exposed surface, and the only post-exploit finding is a low-severity issue (max CVSS 2.78) that requires prior local access, posing negligible real-world risk for this Tomcat container.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-7598 | LOW2.78 | libssh2 1.4.3-12.amzn2.2.6 fixed in 1.4.3-12.amzn2.2.7 | 0.4% Theoretical Threat | Post-Exploit |