Vulnerability Reportvespaengine/vespa:8

vespaengine/vespa:latestvespaengine/vespa:8vespaengine/vespa:8.710.53
digestsha256:9e0759666b2e9c89244b31494fc4cf088f4b7b4d182d7619660bff37ee35957e

Executive Summary

Last scanned:

Threat Score
0/100SAFE
Reputation
RELIABLE

This image is safe for production use. While the image contains 48 exposed and 57 post-exploit-only vulnerabilities, none exceed the low-severity threshold (max exposed severity 5.52, max post-exploit severity 3.98). These findings are not exploitable to a significant degree and do not present practical risks for normal deployment. The image is officially endorsed as reliable and packed with a strong community reputation.

Vulnerabilities

Vulnerability Log

118 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-6238MEDIUM5.52
glibc-common
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
glibc-langpack-en
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-6238MEDIUM5.52
glibc-minimal-langpack
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.4%
Theoretical Threat
Directly Exposed
CVE-2024-34459MEDIUM5.5
libxml2
2.9.7-21.el8_10.4
fixed in 2.9.7-21.el8_10.5
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-54370MEDIUM5.35
libacl
2.2.53-3.el8
fixed in 2.4.0-1.el8_10
<0.1%
Theoretical Threat
Directly Exposed
CVE-2026-47063MEDIUM5.1
java-17-openjdk
1:17.0.19.0.10-1.el8
fixed in 1:17.0.20.0.8-1.1.el8
0.2%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-47063MEDIUM5.1
java-17-openjdk-headless
1:17.0.19.0.10-1.el8
fixed in 1:17.0.20.0.8-1.1.el8
0.2%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-5435MEDIUM5.02
glibc
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
glibc-common
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
glibc-langpack-en
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-5435MEDIUM5.02
glibc-minimal-langpack
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-46968MEDIUM5.02
java-17-openjdk
1:17.0.19.0.10-1.el8
fixed in 1:17.0.20.0.8-1.1.el8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-46968MEDIUM5.02
java-17-openjdk-devel
1:17.0.19.0.10-1.el8
fixed in 1:17.0.20.0.8-1.1.el8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-46968MEDIUM5.02
java-17-openjdk-headless
1:17.0.19.0.10-1.el8
fixed in 1:17.0.20.0.8-1.1.el8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-35568MEDIUM4.84
io.modelcontextprotocol.sdk:mcp-core
0.18.2
fixed in 1.0.0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-46917MEDIUM4.5
java-17-openjdk
1:17.0.19.0.10-1.el8
fixed in 1:17.0.20.0.8-1.1.el8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-47021MEDIUM4.5
java-17-openjdk
1:17.0.19.0.10-1.el8
fixed in 1:17.0.20.0.8-1.1.el8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-47027MEDIUM4.5
java-17-openjdk
1:17.0.19.0.10-1.el8
fixed in 1:17.0.20.0.8-1.1.el8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-46917MEDIUM4.5
java-17-openjdk-devel
1:17.0.19.0.10-1.el8
fixed in 1:17.0.20.0.8-1.1.el8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-47021MEDIUM4.5
java-17-openjdk-devel
1:17.0.19.0.10-1.el8
fixed in 1:17.0.20.0.8-1.1.el8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-47027MEDIUM4.5
java-17-openjdk-devel
1:17.0.19.0.10-1.el8
fixed in 1:17.0.20.0.8-1.1.el8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-46917MEDIUM4.5
java-17-openjdk-headless
1:17.0.19.0.10-1.el8
fixed in 1:17.0.20.0.8-1.1.el8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-47021MEDIUM4.5
java-17-openjdk-headless
1:17.0.19.0.10-1.el8
fixed in 1:17.0.20.0.8-1.1.el8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-47027MEDIUM4.5
java-17-openjdk-headless
1:17.0.19.0.10-1.el8
fixed in 1:17.0.20.0.8-1.1.el8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-54515MEDIUM4.5
com.fasterxml.jackson.core:jackson-databind
2.21.4
fixed in 3.1.4, 2.18.9, 2.21.5, 2.22.1
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-60147MEDIUM4.42
java-17-openjdk
1:17.0.19.0.10-1.el8
fixed in 1:17.0.20.0.8-1.1.el8
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-60147MEDIUM4.42
java-17-openjdk-headless
1:17.0.19.0.10-1.el8
fixed in 1:17.0.20.0.8-1.1.el8
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-5450MEDIUM4.25
glibc
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.38
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc-common
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.38
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc-common
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc-langpack-en
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.38
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc-langpack-en
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-5450MEDIUM4.25
glibc-minimal-langpack
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.38
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-5928MEDIUM4.25
glibc-minimal-langpack
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-71089LOW3.98
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.143.1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-23216LOW3.98
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.139.1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-31488LOW3.98
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.136.1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-43499LOW3.98
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.143.1.el8_10
0.7%
Theoretical Threat
Post-Exploit
CVE-2026-45984LOW3.98
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.139.1.el8_10
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-46189LOW3.98
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.139.1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-53059LOW3.98
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.147.1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-53359LOW3.98
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.143.1.el8_10
0.9%
Theoretical Threat
Post-Exploit
CVE-2026-53071LOW3.82
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.146.1.el8_10
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-41411LOW3.72
vim-minimal
2:8.0.1763-22.el8_10.3
fixed in 2:8.0.1763-24.el8_10
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-54369LOW3.62
acl
2.2.53-3.el8
fixed in 2.4.0-1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-43056LOW3.62
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.136.1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-43450LOW3.62
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.140.1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-46135LOW3.62
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.136.1.el8_10
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-46209LOW3.62
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.140.1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-46259LOW3.62
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.140.1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-35177LOW3.62
vim-minimal
2:8.0.1763-22.el8_10.3
fixed in 2:8.0.1763-23.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-31419LOW3.57
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.136.1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-43198LOW3.57
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.140.1.el8_10
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-46054LOW3.57
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.137.1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-46090LOW3.57
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.136.1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-46116LOW3.57
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.144.1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-46117LOW3.57
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.146.1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-46145LOW3.57
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.136.1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-46227LOW3.57
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.140.1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-52993LOW3.57
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.147.1.el8_10
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-53006LOW3.57
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.148.1.el8_10
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-46331LOW3.42
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.136.1.el8_10
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-54370LOW3.21
acl
2.2.53-3.el8
fixed in 2.4.0-1.el8_10
<0.1%
Theoretical Threat
Post-Exploit
CVE-2025-71066LOW3.16
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.143.1.el8_10
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-47010LOW3.15
java-17-openjdk
1:17.0.19.0.10-1.el8
fixed in 1:17.0.20.0.8-1.1.el8
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-47059LOW3.15
java-17-openjdk
1:17.0.19.0.10-1.el8
fixed in 1:17.0.20.0.8-1.1.el8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-47010LOW3.15
java-17-openjdk-devel
1:17.0.19.0.10-1.el8
fixed in 1:17.0.20.0.8-1.1.el8
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-47059LOW3.15
java-17-openjdk-devel
1:17.0.19.0.10-1.el8
fixed in 1:17.0.20.0.8-1.1.el8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-47010LOW3.15
java-17-openjdk-headless
1:17.0.19.0.10-1.el8
fixed in 1:17.0.20.0.8-1.1.el8
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-47059LOW3.15
java-17-openjdk-headless
1:17.0.19.0.10-1.el8
fixed in 1:17.0.20.0.8-1.1.el8
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-43279LOW2.96
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.136.1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-46113LOW2.96
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.143.1.el8_10
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-45447LOW2.92
openssl
1:1.1.1k-15.el8_6
fixed in 1:1.1.1k-16.el8_6
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2026-45447LOW2.92
openssl-libs
1:1.1.1k-15.el8_6
fixed in 1:1.1.1k-16.el8_6
5.2%
Low-Moderate Risk
Post-Exploit
CVE-2025-40026LOW2.8
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.147.1.el8_10
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-31411LOW2.8
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.143.1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-46086LOW2.8
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.144.1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-58016LOW2.78
glib2
2.56.4-169.el8_10
fixed in 2.56.4-170.el8_10
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-33416LOW2.7
libpng
2:1.6.34-10.el8_10
fixed in 2:1.6.34-11.el8_10
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2026-28390LOW2.7
openssl
1:1.1.1k-15.el8_6
fixed in 1:1.1.1k-17.el8_6
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2026-28390LOW2.7
openssl-libs
1:1.1.1k-15.el8_6
fixed in 1:1.1.1k-17.el8_6
1.0%
Low-Moderate Risk
Post-Exploit
CVE-2025-10263LOW2.57
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.140.1.el8_10
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-43112LOW2.48
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.141.1.el8_10
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-48864LOW2.39
libsolv
0.7.20-6.el8
fixed in 0.7.20-7.el8_10
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-34980LOW2.29
cups-libs
1:2.2.6-67.el8_10
fixed in 1:2.2.6-68.el8_10
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-45186LOW2.29
expat
2.5.0-1.el8_10
fixed in 2.5.0-2.el8_10
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-41254LOW2.29
java-17-openjdk
1:17.0.19.0.10-1.el8
fixed in 1:17.0.20.0.8-1.1.el8
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-41254LOW2.29
java-17-openjdk-devel
1:17.0.19.0.10-1.el8
fixed in 1:17.0.20.0.8-1.1.el8
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-47063LOW2.29
java-17-openjdk-devel
1:17.0.19.0.10-1.el8
fixed in 1:17.0.20.0.8-1.1.el8
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-41254LOW2.29
java-17-openjdk-headless
1:17.0.19.0.10-1.el8
fixed in 1:17.0.20.0.8-1.1.el8
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-53266LOW2.29
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.143.1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-54369LOW2.17
libacl
2.2.53-3.el8
fixed in 2.4.0-1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2025-13151LOW2.12
libtasn1
4.13-5.el8_10
fixed in 4.13-6.el8_10
1.1%
Low-Moderate Risk
Post-Exploit
CVE-2025-6170LOW2.12
libxml2
2.9.7-21.el8_10.4
fixed in 2.9.7-21.el8_10.6
0.2%
Theoretical Threat
Directly Exposed
CVE-2024-4741LOW2.02
openssl
1:1.1.1k-15.el8_6
fixed in 1:1.1.1k-16.el8_6
2.9%
Low-Moderate Risk
Post-Exploit
CVE-2024-4741LOW2.02
openssl-libs
1:1.1.1k-15.el8_6
fixed in 1:1.1.1k-16.el8_6
2.9%
Low-Moderate Risk
Post-Exploit
CVE-2026-6238LOW1.99
glibc
2.28-251.el8_10.37
fixed in 2.28-251.el8_10.40
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-60147LOW1.99
java-17-openjdk-devel
1:17.0.19.0.10-1.el8
fixed in 1:17.0.20.0.8-1.1.el8
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-39822NONE0
stdlib
v1.26.2
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Not Applicable
CVE-2026-27145NONE0
stdlib
v1.26.2
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Not Applicable
CVE-2026-33811NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Not Applicable
CVE-2026-33814NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Not Applicable
CVE-2026-39820NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Not Applicable
CVE-2026-39836NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42499NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Not Applicable
CVE-2026-42504NONE0
stdlib
v1.26.2
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Not Applicable
CVE-2026-39825NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-39823NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39826NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42505NONE0
stdlib
v1.26.2
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.3%
Theoretical Threat
Not Applicable
CVE-2026-42507NONE0
stdlib
v1.26.2
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Not Applicable
CVE-2026-59949NONE0
at.yawk.lz4:lz4-java
1.11.0
fixed in 1.11.1
Not Applicable
CVE-2026-59889NONE0
com.fasterxml.jackson.core:jackson-databind
2.21.4
fixed in 2.21.5, 2.18.9, 2.22.1
0.3%
Theoretical Threat
Not Applicable
GHSA-mhm7-754m-9p8wNONE0
com.fasterxml.jackson.core:jackson-databind
2.21.4
fixed in 2.18.9, 2.21.5
Not Applicable
CVE-2026-34237NONE0
io.modelcontextprotocol.sdk:mcp-core
0.18.2
fixed in 1.0.1, 1.1.1, 0.18.3
0.2%
Theoretical Threat
Not Applicable
CVE-2026-46600NONE0
golang.org/x/net
v0.55.0
fixed in 0.56.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-56852NONE0
golang.org/x/text
v0.37.0
fixed in 0.39.0
0.4%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.