Vulnerability Reporttomcat:9.0.118-jdk11-corretto

tomcat:9.0.118-jdk11-corretto-al2tomcat:9.0.118-jdk11-correttotomcat:9.0-jdk11-corretto-al2tomcat:9.0-jdk11-correttotomcat:9-jdk11-corretto-al2tomcat:9-jdk11-corretto
digestsha256:9fa3e733a2ae3fcf6ffd1993bd62c461097372daec33cb553c09119e3d01d6af

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
TRUSTED

This image is safe for production use. It contains 9 exposed and 32 post-exploit vulnerabilities, but all are low severity (below 6.0) and none pose a realistic threat in typical deployment scenarios. The image is an official Docker Tomcat release, widely trusted and deployed.

Vulnerabilities

Vulnerability Log

41 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-56132MEDIUM5.87
expat
2.1.0-15.amzn2.0.6
fixed in 2.1.0-15.amzn2.0.7
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56403MEDIUM5.87
expat
2.1.0-15.amzn2.0.6
fixed in 2.1.0-15.amzn2.0.8
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-56406MEDIUM5.87
expat
2.1.0-15.amzn2.0.6
fixed in 2.1.0-15.amzn2.0.8
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
openssl-libs
1:1.0.2k-24.amzn2.0.20
fixed in 1:1.0.2k-24.amzn2.0.21
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-7383MEDIUM4.67
openssl11-libs
1:1.1.1zg-1.amzn2.0.1
fixed in 1:1.1.1zh-1.amzn2.0.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-52858LOW3.98
vim-data
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-52860LOW3.98
vim-data
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-55693LOW3.98
vim-data
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.8
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-55895LOW3.98
vim-data
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-57456LOW3.98
vim-data
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.8
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-52858LOW3.98
vim-minimal
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-52860LOW3.98
vim-minimal
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-55693LOW3.98
vim-minimal
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.8
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-55895LOW3.98
vim-minimal
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-57456LOW3.98
vim-minimal
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.8
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-6653LOW3
libxml2
2.9.1-6.amzn2.5.24
fixed in 2.9.1-6.amzn2.5.25
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45447LOW2.92
openssl-libs
1:1.0.2k-24.amzn2.0.20
fixed in 1:1.0.2k-24.amzn2.0.21
2.7%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
openssl11-libs
1:1.1.1zg-1.amzn2.0.1
fixed in 1:1.1.1zh-1.amzn2.0.1
2.7%
Low-Moderate Risk
Post-Exploit
CVE-2026-58016LOW2.78
glib2
2.56.1-9.amzn2.0.13
fixed in 2.56.1-9.amzn2.0.14
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-7598LOW2.78
libssh2
1.4.3-12.amzn2.2.6
fixed in 1.4.3-12.amzn2.2.7
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-47167LOW2.7
vim-data
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.7
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-47167LOW2.7
vim-minimal
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.7
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-47162LOW2.69
vim-data
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-47162LOW2.69
vim-minimal
2:9.0.2153-1.amzn2.0.6
fixed in 2:9.0.2153-1.amzn2.0.7
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-58050LOW2.29
libssh2
1.4.3-12.amzn2.2.6
fixed in 1.4.3-12.amzn2.2.8
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-58051LOW1.99
libssh2
1.4.3-12.amzn2.2.6
fixed in 1.4.3-12.amzn2.2.8
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-11972LOW1.99
python
2.7.18-1.amzn2.0.19
fixed in 2.7.18-1.amzn2.0.21
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-11972LOW1.99
python-libs
2.7.18-1.amzn2.0.19
fixed in 2.7.18-1.amzn2.0.21
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-6019LOW1.87
python
2.7.18-1.amzn2.0.19
fixed in 2.7.18-1.amzn2.0.20
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-6019LOW1.87
python-libs
2.7.18-1.amzn2.0.19
fixed in 2.7.18-1.amzn2.0.20
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-9076LOW1.81
openssl-libs
1:1.0.2k-24.amzn2.0.20
fixed in 1:1.0.2k-24.amzn2.0.21
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-9076LOW1.81
openssl11-libs
1:1.1.1zg-1.amzn2.0.1
fixed in 1:1.1.1zh-1.amzn2.0.1
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-42766LOW1.62
openssl-libs
1:1.0.2k-24.amzn2.0.20
fixed in 1:1.0.2k-24.amzn2.0.21
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-42766LOW1.62
openssl11-libs
1:1.1.1zg-1.amzn2.0.1
fixed in 1:1.1.1zh-1.amzn2.0.1
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-11850LOW1.53
krb5-libs
1.15.1-55.amzn2.2.9
fixed in 1.15.1-55.amzn2.2.10
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-34180LOW1.53
openssl-libs
1:1.0.2k-24.amzn2.0.20
fixed in 1:1.0.2k-24.amzn2.0.21
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-34180LOW1.53
openssl11-libs
1:1.1.1zg-1.amzn2.0.1
fixed in 1:1.1.1zh-1.amzn2.0.1
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-56407NONE0
expat
2.1.0-15.amzn2.0.6
fixed in 2.1.0-15.amzn2.0.8
0.1%
Theoretical Threat
Not Applicable
CVE-2026-53615NONE0
libblkid
2.30.2-2.amzn2.0.13
fixed in 2.30.2-2.amzn2.0.14
Not Applicable
CVE-2026-53615NONE0
libmount
2.30.2-2.amzn2.0.13
fixed in 2.30.2-2.amzn2.0.14
Not Applicable
CVE-2026-53615NONE0
libuuid
2.30.2-2.amzn2.0.13
fixed in 2.30.2-2.amzn2.0.14
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.