Vulnerability Reportvespaengine/vespa:8.706.52

vespaengine/vespa:8.706.52
DIGESTsha256:89365f7a1dd1f53aa44541ae27c907ae5ecdf96213e6826a27e2a27a9cb1ee6b

Executive Summary

Threat Score
25/100NEEDS ATTENTION
Reputation
RELIABLE

This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. The most notable vulnerability is CVE-2026-45186 in libexpat, which could allow a denial of service if the container processes crafted XML input; upgrading libexpat to 2.8.1 or later fully mitigates this. CVE-2026-45447 in openssl-libs requires PKCS#7 message processing, which is not typical for Vespa. The remaining vulnerabilities are lower severity and unlikely to be exploited in this context.

Vulnerabilities

Vulnerability Log

28 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-45447MEDIUM6.48
openssl-libs
1:1.1.1k-15.el8_6
fixed in 1:1.1.1k-16.el8_6
1.4%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-45186MEDIUM6.38
expat
2.5.0-1.el8_10
fixed in 2.5.0-2.el8_10
0.5%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2024-34459MEDIUM5.5
libxml2
2.9.7-21.el8_10.4
fixed in 2.9.7-21.el8_10.5
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-35568MEDIUM4.84
io.modelcontextprotocol.sdk:mcp-core
0.18.2
fixed in 1.0.0
0.1%
Theoretical Threat
Directly Exposed
CVE-2024-4741MEDIUM4.48
openssl-libs
1:1.1.1k-15.el8_6
fixed in 1:1.1.1k-16.el8_6
2.9%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-31787LOW3.98
perf
4.18.0-553.132.1.el8_10
fixed in 4.18.0-553.134.1.el8_10
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-31669LOW3.82
perf
4.18.0-553.132.1.el8_10
fixed in 4.18.0-553.134.1.el8_10
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-43110LOW3.82
perf
4.18.0-553.132.1.el8_10
fixed in 4.18.0-553.134.1.el8_10
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-31786LOW3.62
perf
4.18.0-553.132.1.el8_10
fixed in 4.18.0-553.134.1.el8_10
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-46056LOW3.62
perf
4.18.0-553.132.1.el8_10
fixed in 4.18.0-553.134.1.el8_10
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-35177LOW3.62
vim-minimal
2:8.0.1763-22.el8_10.3
fixed in 2:8.0.1763-23.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-43329LOW3.57
perf
4.18.0-553.132.1.el8_10
fixed in 4.18.0-553.134.1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-46125LOW3.57
perf
4.18.0-553.132.1.el8_10
fixed in 4.18.0-553.134.1.el8_10
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-46152LOW3.57
perf
4.18.0-553.132.1.el8_10
fixed in 4.18.0-553.134.1.el8_10
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-45447LOW2.92
openssl
1:1.1.1k-15.el8_6
fixed in 1:1.1.1k-16.el8_6
1.4%
Low-Moderate Risk
Post-Exploit
CVE-2024-4741LOW2.02
openssl
1:1.1.1k-15.el8_6
fixed in 1:1.1.1k-16.el8_6
2.9%
Low-Moderate Risk
Post-Exploit
CVE-2026-33811NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.5%
Theoretical Threat
Not Applicable
CVE-2026-33814NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-39820NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-39836NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-39826NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42507NONE0
stdlib
v1.26.2
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable
CVE-2026-34237NONE0
io.modelcontextprotocol.sdk:mcp-core
0.18.2
fixed in 1.0.1, 1.1.1, 0.18.3
0.2%
Theoretical Threat
Not Applicable
CVE-2026-39823NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39825NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42499NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42504NONE0
stdlib
v1.26.2
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Not Applicable
CVE-2026-27145NONE0
stdlib
v1.26.2
fixed in 1.25.11, 1.26.4
0.3%
Theoretical Threat
Not Applicable