Last scanned:
This image carries significant risk; production deployment is highly discouraged without strict compensating controls. The most severe finding, CVE-2026-6653, allows remote code execution via XML inputs, which directly impacts Tomcat's web-facing functionality. The two OpenSSL CVEs (CVE-2026-45447) are less critical as they require processing PKCS#7 messages, which is non-default in Tomcat. Updating libxml2 is strongly recommended to eliminate the high-severity risk.
| CVE ID | Adjusted Severity | Package | Exploit Probability | Risk Context |
|---|---|---|---|---|
| CVE-2026-6653 | HIGH8.33 | libxml2 2.9.1-6.amzn2.5.24 fixed in 2.9.1-6.amzn2.5.25 | 0.3% Theoretical Threat | Directly ExposedContext importance: HIGH |
| CVE-2026-45447 | MEDIUM6.48 | openssl-libs 1:1.0.2k-24.amzn2.0.20 fixed in 1:1.0.2k-24.amzn2.0.21 | 2.7% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2026-45447 | MEDIUM6.48 | openssl11-libs 1:1.1.1zg-1.amzn2.0.1 fixed in 1:1.1.1zh-1.amzn2.0.1 | 2.7% Low-Moderate Risk | Directly ExposedContext importance: MEDIUM |
| CVE-2026-56132 | MEDIUM5.87 | expat 2.1.0-15.amzn2.0.6 fixed in 2.1.0-15.amzn2.0.7 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56403 | MEDIUM5.87 | expat 2.1.0-15.amzn2.0.6 fixed in 2.1.0-15.amzn2.0.8 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-56406 | MEDIUM5.87 | expat 2.1.0-15.amzn2.0.6 fixed in 2.1.0-15.amzn2.0.8 | 0.1% Theoretical Threat | Directly Exposed |
| CVE-2026-7383 | MEDIUM4.67 | openssl-libs 1:1.0.2k-24.amzn2.0.20 fixed in 1:1.0.2k-24.amzn2.0.21 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-7383 | MEDIUM4.67 | openssl11-libs 1:1.1.1zg-1.amzn2.0.1 fixed in 1:1.1.1zh-1.amzn2.0.1 | 0.4% Theoretical Threat | Directly Exposed |
| CVE-2026-9076 | MEDIUM4.02 | openssl-libs 1:1.0.2k-24.amzn2.0.20 fixed in 1:1.0.2k-24.amzn2.0.21 | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-9076 | MEDIUM4.02 | openssl11-libs 1:1.1.1zg-1.amzn2.0.1 fixed in 1:1.1.1zh-1.amzn2.0.1 | 0.3% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-52858 | LOW3.98 | vim-minimal 2:9.0.2153-1.amzn2.0.6 fixed in 2:9.0.2153-1.amzn2.0.7 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-52860 | LOW3.98 | vim-minimal 2:9.0.2153-1.amzn2.0.6 fixed in 2:9.0.2153-1.amzn2.0.7 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-55693 | LOW3.98 | vim-minimal 2:9.0.2153-1.amzn2.0.6 fixed in 2:9.0.2153-1.amzn2.0.8 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-55895 | LOW3.98 | vim-minimal 2:9.0.2153-1.amzn2.0.6 fixed in 2:9.0.2153-1.amzn2.0.8 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-57456 | LOW3.98 | vim-minimal 2:9.0.2153-1.amzn2.0.6 fixed in 2:9.0.2153-1.amzn2.0.8 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-42766 | LOW3.6 | openssl-libs 1:1.0.2k-24.amzn2.0.20 fixed in 1:1.0.2k-24.amzn2.0.21 | 0.6% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-42766 | LOW3.6 | openssl11-libs 1:1.1.1zg-1.amzn2.0.1 fixed in 1:1.1.1zh-1.amzn2.0.1 | 0.6% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-34180 | LOW3.4 | openssl-libs 1:1.0.2k-24.amzn2.0.20 fixed in 1:1.0.2k-24.amzn2.0.21 | 0.5% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-34180 | LOW3.4 | openssl11-libs 1:1.1.1zg-1.amzn2.0.1 fixed in 1:1.1.1zh-1.amzn2.0.1 | 0.5% Theoretical Threat | Directly ExposedContext importance: MEDIUM |
| CVE-2026-58016 | LOW2.78 | glib2 2.56.1-9.amzn2.0.13 fixed in 2.56.1-9.amzn2.0.14 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-7598 | LOW2.78 | libssh2 1.4.3-12.amzn2.2.6 fixed in 1.4.3-12.amzn2.2.7 | 0.5% Theoretical Threat | Post-Exploit |
| CVE-2026-47167 | LOW2.7 | vim-minimal 2:9.0.2153-1.amzn2.0.6 fixed in 2:9.0.2153-1.amzn2.0.7 | 0.1% Theoretical Threat | Post-Exploit |
| CVE-2026-47162 | LOW2.69 | vim-minimal 2:9.0.2153-1.amzn2.0.6 fixed in 2:9.0.2153-1.amzn2.0.7 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-58050 | LOW2.29 | libssh2 1.4.3-12.amzn2.2.6 fixed in 1.4.3-12.amzn2.2.8 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-58051 | LOW1.99 | libssh2 1.4.3-12.amzn2.2.6 fixed in 1.4.3-12.amzn2.2.8 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-11972 | LOW1.99 | python 2.7.18-1.amzn2.0.19 fixed in 2.7.18-1.amzn2.0.21 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-11972 | LOW1.99 | python-libs 2.7.18-1.amzn2.0.19 fixed in 2.7.18-1.amzn2.0.21 | 0.4% Theoretical Threat | Post-Exploit |
| CVE-2026-6019 | LOW1.87 | python 2.7.18-1.amzn2.0.19 fixed in 2.7.18-1.amzn2.0.20 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-6019 | LOW1.87 | python-libs 2.7.18-1.amzn2.0.19 fixed in 2.7.18-1.amzn2.0.20 | 0.2% Theoretical Threat | Post-Exploit |
| CVE-2026-11850 | LOW1.53 | krb5-libs 1.15.1-55.amzn2.2.9 fixed in 1.15.1-55.amzn2.2.10 | 0.3% Theoretical Threat | Post-Exploit |
| CVE-2026-47162 | NONE0 | vim-data 2:9.0.2153-1.amzn2.0.6 fixed in 2:9.0.2153-1.amzn2.0.7 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-52858 | NONE0 | vim-data 2:9.0.2153-1.amzn2.0.6 fixed in 2:9.0.2153-1.amzn2.0.7 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-52860 | NONE0 | vim-data 2:9.0.2153-1.amzn2.0.6 fixed in 2:9.0.2153-1.amzn2.0.7 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-55693 | NONE0 | vim-data 2:9.0.2153-1.amzn2.0.6 fixed in 2:9.0.2153-1.amzn2.0.8 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-55895 | NONE0 | vim-data 2:9.0.2153-1.amzn2.0.6 fixed in 2:9.0.2153-1.amzn2.0.8 | 0.2% Theoretical Threat | Not Applicable |
| CVE-2026-57456 | NONE0 | vim-data 2:9.0.2153-1.amzn2.0.6 fixed in 2:9.0.2153-1.amzn2.0.8 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-47167 | NONE0 | vim-data 2:9.0.2153-1.amzn2.0.6 fixed in 2:9.0.2153-1.amzn2.0.7 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-56407 | NONE0 | expat 2.1.0-15.amzn2.0.6 fixed in 2.1.0-15.amzn2.0.8 | 0.1% Theoretical Threat | Not Applicable |
| CVE-2026-53615 | NONE0 | libblkid 2.30.2-2.amzn2.0.13 fixed in 2.30.2-2.amzn2.0.14 | — | Not Applicable |
| CVE-2026-53615 | NONE0 | libmount 2.30.2-2.amzn2.0.13 fixed in 2.30.2-2.amzn2.0.14 | — | Not Applicable |
| CVE-2026-53615 | NONE0 | libuuid 2.30.2-2.amzn2.0.13 fixed in 2.30.2-2.amzn2.0.14 | — | Not Applicable |
Which CVEs are actually reachable — is the vulnerable code even linked and callable.
Live-container probes: default user, writable paths, capabilities, exposed ports.
A step-by-step hardened build plan, with parity tests proving nothing breaks.
Want to check another image? Run a full scan with the Docker Security Scanner.