grok_connect:bleeding-edge — vulnerability report

0 critical · 6 high · 37 medium · 17 low · 60 total (deduped by CVE) · 8 reviewed not-affected

Image datagrok/grok_connect:bleeding-edge · digest sha256:7f60ebe5d72c1b35ad219e9c251679451921ded6149b6060a98c8adb05ebfdf9

Open findings

OpenVEX status affected (an upstream fix exists — the action is to apply it) or under_investigation (no upstream fix is available yet; a version match alone does not establish exploitability).

VulnerabilityStatusSeverityPackage InstalledFixed inCVSSDescription
CVE-2026-68497affectedHIGHcom.fasterxml.jackson.core:jackson-databind2.18.92.18.10CVE-2026-68497
CVE-2026-68497affectedHIGHcom.fasterxml.jackson.core:jackson-databind2.21.52.21.6CVE-2026-68497
CVE-2026-84782affectedHIGHopenssl3.0.2-0ubuntu1.293.0.2-0ubuntu1.308.2CVE-2026-84782
CVE-2026-89407affectedHIGHcom.fasterxml.jackson.core:jackson-core2.21.52.21.7CVE-2026-89407
CVE-2026-89425affectedHIGHcom.fasterxml.jackson.core:jackson-core2.21.52.21.7CVE-2026-89425
CVE-2026-91776affectedHIGHcom.fasterxml.jackson.core:jackson-databind2.18.92.18.11CVE-2026-91776
CVE-2026-91776affectedHIGHcom.fasterxml.jackson.core:jackson-databind2.21.52.21.7CVE-2026-91776
CVE-2026-91777affectedHIGHcom.fasterxml.jackson.core:jackson-databind2.18.92.18.11CVE-2026-91777
CVE-2026-91777affectedHIGHcom.fasterxml.jackson.core:jackson-databind2.21.52.21.7CVE-2026-91777
CVE-2023-31486under_investigationMEDIUMperl5.34.0-3ubuntu1.9—8.1CVE-2023-31486
CVE-2024-10041under_investigationMEDIUMpam1.4.0-11ubuntu2.8—4.7CVE-2024-10041
CVE-2025-15649under_investigationMEDIUMperl5.34.0-3ubuntu1.9—5.5CVE-2025-15649
CVE-2026-102010under_investigationMEDIUMgcc-1212.3.0-1ubuntu1~22.04.3—7CVE-2026-102010
CVE-2026-102473under_investigationMEDIUMdash0.5.11+git20210903+057cd650a4ed-3build1—5.5CVE-2026-102473
CVE-2026-102474under_investigationMEDIUMdash0.5.11+git20210903+057cd650a4ed-3build1—4CVE-2026-102474
CVE-2026-103111under_investigationMEDIUMpcre210.39-3ubuntu0.1—CVE-2026-103111
CVE-2026-18374under_investigationMEDIUMglibc2.35-0ubuntu3.15—CVE-2026-18374
CVE-2026-19032affectedMEDIUMcom.fasterxml.jackson.core:jackson-databind2.18.92.18.10CVE-2026-19032
CVE-2026-19032affectedMEDIUMcom.fasterxml.jackson.core:jackson-databind2.21.52.21.6CVE-2026-19032
CVE-2026-42497under_investigationMEDIUMperl5.34.0-3ubuntu1.9—7.5CVE-2026-42497
CVE-2026-48959under_investigationMEDIUMperl5.34.0-3ubuntu1.9—7.5CVE-2026-48959
CVE-2026-48961under_investigationMEDIUMperl5.34.0-3ubuntu1.9—7.3CVE-2026-48961
CVE-2026-48962under_investigationMEDIUMperl5.34.0-3ubuntu1.9—7.3CVE-2026-48962
CVE-2026-54369under_investigationMEDIUMacl2.3.1-1—8.4CVE-2026-54369
CVE-2026-54370under_investigationMEDIUMacl2.3.1-1—7.2CVE-2026-54370
CVE-2026-59949affectedMEDIUMat.yawk.lz4:lz4-java1.10.11.11.16.5CVE-2026-59949
CVE-2026-7017under_investigationMEDIUMperl5.34.0-3ubuntu1.9—7.1CVE-2026-7017
CVE-2026-76642under_investigationMEDIUMutil-linux2.37.2-4ubuntu3.6—8.5CVE-2026-76642
CVE-2026-78408under_investigationMEDIUMutil-linux2.37.2-4ubuntu3.6—7.9CVE-2026-78408
CVE-2026-78409under_investigationMEDIUMutil-linux2.37.2-4ubuntu3.6—7CVE-2026-78409
CVE-2026-78410under_investigationMEDIUMutil-linux2.37.2-4ubuntu3.6—7.8CVE-2026-78410
CVE-2026-82560under_investigationMEDIUMperl5.34.0-3ubuntu1.9—7.5CVE-2026-82560
CVE-2026-83557affectedMEDIUMcom.fasterxml.jackson.core:jackson-databind2.18.92.18.10CVE-2026-83557
CVE-2026-83557affectedMEDIUMcom.fasterxml.jackson.core:jackson-databind2.21.52.21.6CVE-2026-83557
CVE-2026-85091under_investigationMEDIUMzlib1:1.2.11.dfsg-2ubuntu9.2—8.3CVE-2026-85091
CVE-2026-86145under_investigationMEDIUMpcre210.39-3ubuntu0.1—CVE-2026-86145
CVE-2026-8674under_investigationMEDIUMglibc2.35-0ubuntu3.15—CVE-2026-8674
CVE-2026-86805under_investigationMEDIUMglibc2.35-0ubuntu3.15—CVE-2026-86805
CVE-2026-89092under_investigationMEDIUMglibc2.35-0ubuntu3.15—CVE-2026-89092
CVE-2026-89156under_investigationMEDIUMpcre210.39-3ubuntu0.1—5.9CVE-2026-89156
CVE-2026-89157under_investigationMEDIUMpcre210.39-3ubuntu0.1—7.4CVE-2026-89157
CVE-2026-89158under_investigationMEDIUMpcre210.39-3ubuntu0.1—6.5CVE-2026-89158
CVE-2026-89160under_investigationMEDIUMpcre210.39-3ubuntu0.1—6.5CVE-2026-89160
CVE-2026-89161under_investigationMEDIUMpcre210.39-3ubuntu0.1—7.8CVE-2026-89161
CVE-2026-9538under_investigationMEDIUMperl5.34.0-3ubuntu1.9—7.5CVE-2026-9538
CVE-2026-95619under_investigationMEDIUMgcc-1212.3.0-1ubuntu1~22.04.3—7.7CVE-2026-95619
CVE-2026-95818under_investigationMEDIUMglibc2.35-0ubuntu3.15—CVE-2026-95818
CVE-2026-97399under_investigationMEDIUMglibc2.35-0ubuntu3.15—CVE-2026-97399
CVE-2016-2781under_investigationLOWcoreutils8.32-4.1ubuntu1.4—6.5CVE-2016-2781
CVE-2022-27943under_investigationLOWgcc-1212.3.0-1ubuntu1~22.04.3—5.5CVE-2022-27943
CVE-2022-3219under_investigationLOWgnupg22.2.27-3ubuntu2.5—3.3CVE-2022-3219
CVE-2022-41409under_investigationLOWpcre210.39-3ubuntu0.1—7.5CVE-2022-41409
CVE-2022-4899under_investigationLOWlibzstd1.4.8+dfsg-3build1—7.5CVE-2022-4899
CVE-2023-29383under_investigationLOWshadow1:4.8.1-2ubuntu2.2—3.3CVE-2023-29383
CVE-2023-50495under_investigationLOWncurses6.3-2ubuntu0.3—6.5CVE-2023-50495
CVE-2024-56433under_investigationLOWshadow1:4.8.1-2ubuntu2.2—CVE-2024-56433
CVE-2026-35189affectedLOWopenssl3.0.2-0ubuntu1.293.0.2-0ubuntu1.305.3CVE-2026-35189
CVE-2026-54872affectedLOWopenssl3.0.2-0ubuntu1.293.0.2-0ubuntu1.303.7CVE-2026-54872
CVE-2026-75805affectedLOWopenssl3.0.2-0ubuntu1.293.0.2-0ubuntu1.305.3CVE-2026-75805
CVE-2026-75806affectedLOWopenssl3.0.2-0ubuntu1.293.0.2-0ubuntu1.305.3CVE-2026-75806
CVE-2026-77696affectedLOWopenssl3.0.2-0ubuntu1.293.0.2-0ubuntu1.303.7CVE-2026-77696
CVE-2016-20013under_investigationMINIMALglibc2.35-0ubuntu3.15—7.5CVE-2016-20013
CVE-2017-11164under_investigationMINIMALpcre32:8.39-13ubuntu0.22.04.1—7.5CVE-2017-11164
CVE-2018-5709under_investigationMINIMALkrb51.19.2-2ubuntu0.10—7.5CVE-2018-5709
CVE-2023-47039under_investigationMINIMALperl5.34.0-3ubuntu1.9—7.8CVE-2023-47039

Reviewed findings — not affected

Manually reviewed findings with OpenVEX status not_affected. Each row carries the spec justification label and the evidence for why the vulnerable code does not affect this image's functionality (and where that was verified). Excluded from the severity counts above; present as full statements in the OpenVEX document.

VulnerabilitySeverityPackageInstalled JustificationEvidence / where
CVE-2025-59250HIGHcom.microsoft.sqlserver:mssql-jdbc12.10.2vulnerable_code_not_presentmssql-jdbc 12.10.2.jre8 (previously 12.8.2.jre8) is well past the fix wave; scanners mis-order the bare '12.10.2' from the jar's pom.properties against the '12.8.2.jre11' fixed-version string because the .jreN suffix breaks their version comparators (known Trivy/Grype issue: aquasecurity/trivy#9745, anchore/grype#3042). The jre11 artifact cannot be used on the Java-8 runtime. Applies to any X.Y.Z.jre8 >= 12.8.2.
CVE-2026-2332HIGHorg.eclipse.jetty:jetty-http9.4.58.v20250814vulnerable_code_cannot_be_controlled_by_adversaryjetty-http request smuggling via chunk-extension quoted-string parsing. No OSS fix exists on the Java-8-compatible jetty 9.4 line (9.4.58.v20250814 is the newest on Maven Central and is in the affected range; the advisory's 9.4.60 fix ships only in the HeroDevs NES fork; jetty 10+ needs Java 11). Not adversary-controllable in our topology: grok_connect listens cluster-internally on :1234 with datlas as its ONLY client, connecting directly with no HTTP intermediary (proxy/LB/cache) in between — request smuggling requires a parsing-differential between two HTTP hops, and user input reaches grok_connect solely inside JSON bodies of datlas-composed requests, never as raw protocol elements. Re-review if grok_connect is ever exposed through an ingress/proxy or the spark-java/jetty stack changes. Verified 2026-08-12.
CVE-2026-10050HIGHorg.eclipse.jetty:jetty-security9.4.58.v20250814vulnerable_code_not_in_execute_pathjetty-security Digest-authentication bypass (ISO-8859-1 encoding collision). Fixed only in jetty 12.0.36/12.1.10; 9.4 is EOL (NES-only backport) and jetty 10+ needs Java 11. Not in the execute path: grok_connect configures NO HTTP authentication — spark-java 2.9.4 wires no SecurityHandler/LoginService, so jetty's DigestAuthenticator is never instantiated; the service is cluster-internal with datlas as its only client. Re-review if HTTP auth is ever added or the spark/jetty stack changes. Verified 2026-08-12.
CVE-2024-6763MEDIUMorg.eclipse.jetty:jetty-http9.4.58.v20250814vulnerable_code_not_in_execute_pathjetty-http HttpURI lenient authority parsing affects applications that use the HttpURI class programmatically for URI validation/redirect construction. Neither spark-java 2.9.4 route handling nor grok_connect code calls HttpURI (no redirects are ever issued); the fix exists only in jetty 12 (Java 17). Verified 2026-08-13.
CVE-2026-6790MEDIUMorg.eclipse.jetty:jetty-server9.4.58.v20250814vulnerable_code_cannot_be_controlled_by_adversaryjetty-server Host/authority desynchronization matters where authority selects behavior: virtual hosts, redirects, caches, reverse-proxy routing, request-log trust. grok_connect has none of these (single spark-java route set, no vhosts, no redirects, no cache) and is cluster-internal with datlas as its only client, connecting directly with no proxy hop whose routing could be confused. No fix on the Java-8-compatible jetty 9.4 line (9.4.58 is the newest on Maven Central; later 9.4.x numbers are the commercial NES fork). Verified 2026-08-13.
CVE-2026-10532LOWch.qos.logback:logback-core1.3.16vulnerable_code_not_in_execute_pathSame surface as CVE-2026-9828: object injection via the SimpleSocketServer/SimpleSSLSocketServer receivers, which grok_connect never runs (appender-only logback.xml, no receiver/server components). Fixed only in 1.5.34 (Java 11+). Verified 2026-08-13.
CVE-2026-9828LOWch.qos.logback:logback-core1.3.16vulnerable_code_not_in_execute_pathlogback-core HardenedObjectInputStream object-injection is reachable only through the SimpleSocketServer/SimpleSSLSocketServer serialized-event receivers. grok_connect never instantiates them: logback.xml configures only ConsoleAppender, AsyncAppender and the in-process QueryStreamAppender (verified src/main/resources/logback.xml). Fixed only in 1.5.33 (Java 11+). Verified 2026-08-13.
CVE-2026-1225LOWch.qos.logback:logback-core1.3.16vulnerable_code_cannot_be_controlled_by_adversarylogback-core config-processing ACE requires an attacker to MODIFY the logback configuration file. grok_connect's logback.xml is compiled into the read-only shaded jar (src/main/resources/logback.xml), the process runs as the non-root 'grok' user, and the entrypoint sets no -Dlogback.configurationFile override — there is no writable or externally-supplied config path. Fixed only in logback 1.5.25 (Java 11+); 1.3.x is the Java-8 ceiling. Verified 2026-08-13.