Vulnerability Reportvespaengine/vespa:8

vespaengine/vespa:latestvespaengine/vespa:8vespaengine/vespa:8.710.53
DIGESTsha256:9e0759666b2e9c89244b31494fc4cf088f4b7b4d182d7619660bff37ee35957e

Executive Summary

Threat Score
25/100NEEDS ATTENTION
Reputation
RELIABLE

This image is acceptable for production, but remediating the identified vulnerabilities is recommended to reduce the attack surface. While there are 6 exposed vulnerabilities, only one (CVE-2026-45447) has a severity above 6.0, and it affects a rarely used OpenSSL function (PKCS7_verify) that is unlikely to be triggered in typical Vespa operation. Therefore, the practical risk is low, but updating the base image is advised.

Vulnerabilities

Vulnerability Log

28 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-45447MEDIUM6.48
openssl-libs
1:1.1.1k-15.el8_6
fixed in 1:1.1.1k-16.el8_6
2.3%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2024-34459MEDIUM5.5
libxml2
2.9.7-21.el8_10.4
fixed in 2.9.7-21.el8_10.5
2.3%
Low-Moderate Risk
Directly Exposed
CVE-2026-45186MEDIUM5.1
expat
2.5.0-1.el8_10
fixed in 2.5.0-2.el8_10
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-35568MEDIUM4.84
io.modelcontextprotocol.sdk:mcp-core
0.18.2
fixed in 1.0.0
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-31488LOW3.98
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.136.1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-46331LOW3.98
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.136.1.el8_10
0.3%
Theoretical Threat
Post-Exploit
CVE-2026-43056LOW3.62
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.136.1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-46135LOW3.62
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.136.1.el8_10
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-35177LOW3.62
vim-minimal
2:8.0.1763-22.el8_10.3
fixed in 2:8.0.1763-23.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-31419LOW3.57
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.136.1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-46090LOW3.57
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.136.1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-46145LOW3.57
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.136.1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2024-4741LOW3.36
openssl-libs
1:1.1.1k-15.el8_6
fixed in 1:1.1.1k-16.el8_6
2.9%
Low-Moderate Risk
Directly Exposed
CVE-2026-43279LOW2.96
perf
4.18.0-553.134.1.el8_10
fixed in 4.18.0-553.136.1.el8_10
0.1%
Theoretical Threat
Post-Exploit
CVE-2026-45447LOW2.92
openssl
1:1.1.1k-15.el8_6
fixed in 1:1.1.1k-16.el8_6
2.3%
Low-Moderate Risk
Post-Exploit
CVE-2024-4741LOW2.02
openssl
1:1.1.1k-15.el8_6
fixed in 1:1.1.1k-16.el8_6
2.9%
Low-Moderate Risk
Post-Exploit
CVE-2026-33811NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-33814NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-39820NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.5%
Theoretical Threat
Not Applicable
CVE-2026-39836NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-39826NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42507NONE0
stdlib
v1.26.2
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Not Applicable
CVE-2026-34237NONE0
io.modelcontextprotocol.sdk:mcp-core
0.18.2
fixed in 1.0.1, 1.1.1, 0.18.3
0.2%
Theoretical Threat
Not Applicable
CVE-2026-27145NONE0
stdlib
v1.26.2
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Not Applicable
CVE-2026-39823NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39825NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Not Applicable
CVE-2026-42499NONE0
stdlib
v1.26.2
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Not Applicable
CVE-2026-42504NONE0
stdlib
v1.26.2
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Not Applicable