0 critical · 0 high · 30 medium · 18 low · 48 total (deduped by CVE) · 8 reviewed not-affected
Image datagrok/grok_connect:bleeding-edge · digest sha256:289468ed9c3ba50cb43c837a21727627ffaef76e555cd1bcc1275b9fec2ef9f1
OpenVEX status affected (an upstream fix exists — the action is to
apply it) or under_investigation (no upstream fix is available yet; a version match
alone does not establish exploitability).
| Vulnerability | Status | Severity | Package | Installed | Fixed in | CVSS | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-31486 | under_investigation | MEDIUM | perl | 5.34.0-3ubuntu1.7 | — | 8.1 | CVE-2023-31486 |
| CVE-2024-10041 | under_investigation | MEDIUM | pam | 1.4.0-11ubuntu2.7 | — | 4.7 | CVE-2024-10041 |
| CVE-2025-15649 | under_investigation | MEDIUM | perl | 5.34.0-3ubuntu1.7 | — | 5.5 | CVE-2025-15649 |
| CVE-2026-12087 | under_investigation | MEDIUM | perl | 5.34.0-3ubuntu1.7 | — | 9.1 | CVE-2026-12087 |
| CVE-2026-13221 | under_investigation | MEDIUM | perl | 5.34.0-3ubuntu1.7 | — | 9.1 | CVE-2026-13221 |
| CVE-2026-13595 | under_investigation | MEDIUM | util-linux | 2.37.2-4ubuntu3.5 | — | 5.3 | CVE-2026-13595 |
| CVE-2026-13757 | under_investigation | MEDIUM | p11-kit | 0.24.0-6build1 | — | 6.2 | CVE-2026-13757 |
| CVE-2026-15534 | under_investigation | MEDIUM | perl | 5.34.0-3ubuntu1.7 | — | 5.7 | CVE-2026-15534 |
| CVE-2026-18938 | under_investigation | MEDIUM | p11-kit | 0.24.0-6build1 | — | 6.2 | CVE-2026-18938 |
| CVE-2026-19487 | under_investigation | MEDIUM | perl | 5.34.0-3ubuntu1.7 | — | 5.3 | CVE-2026-19487 |
| CVE-2026-27456 | under_investigation | MEDIUM | util-linux | 2.37.2-4ubuntu3.5 | — | 4.7 | CVE-2026-27456 |
| CVE-2026-42497 | under_investigation | MEDIUM | perl | 5.34.0-3ubuntu1.7 | — | 7.5 | CVE-2026-42497 |
| CVE-2026-48959 | under_investigation | MEDIUM | perl | 5.34.0-3ubuntu1.7 | — | 7.5 | CVE-2026-48959 |
| CVE-2026-48961 | under_investigation | MEDIUM | perl | 5.34.0-3ubuntu1.7 | — | 7.3 | CVE-2026-48961 |
| CVE-2026-48962 | under_investigation | MEDIUM | perl | 5.34.0-3ubuntu1.7 | — | 7.3 | CVE-2026-48962 |
| CVE-2026-53613 | under_investigation | MEDIUM | util-linux | 2.37.2-4ubuntu3.5 | — | CVE-2026-53613 | |
| CVE-2026-53615 | under_investigation | MEDIUM | util-linux | 2.37.2-4ubuntu3.5 | — | CVE-2026-53615 | |
| CVE-2026-53910 | under_investigation | MEDIUM | diffutils | 1:3.8-0ubuntu2 | — | CVE-2026-53910 | |
| CVE-2026-54369 | under_investigation | MEDIUM | acl | 2.3.1-1 | — | 8.4 | CVE-2026-54369 |
| CVE-2026-54370 | under_investigation | MEDIUM | acl | 2.3.1-1 | — | 7.2 | CVE-2026-54370 |
| CVE-2026-54371 | under_investigation | MEDIUM | attr | 1:2.5.1-1build1 | — | 8.4 | CVE-2026-54371 |
| CVE-2026-56391 | under_investigation | MEDIUM | coreutils | 8.32-4.1ubuntu1.3 | — | CVE-2026-56391 | |
| CVE-2026-56392 | under_investigation | MEDIUM | coreutils | 8.32-4.1ubuntu1.3 | — | CVE-2026-56392 | |
| CVE-2026-57432 | under_investigation | MEDIUM | perl | 5.34.0-3ubuntu1.7 | — | 8.4 | CVE-2026-57432 |
| CVE-2026-57433 | under_investigation | MEDIUM | perl | 5.34.0-3ubuntu1.7 | — | 9.8 | CVE-2026-57433 |
| CVE-2026-59949 | affected | MEDIUM | at.yawk.lz4:lz4-java | 1.10.1 | 1.11.1 | 6.5 | CVE-2026-59949 |
| CVE-2026-6368 | under_investigation | MEDIUM | glibc | 2.35-0ubuntu3.14 | — | CVE-2026-6368 | |
| CVE-2026-6791 | under_investigation | MEDIUM | glibc | 2.35-0ubuntu3.14 | — | CVE-2026-6791 | |
| CVE-2026-7017 | under_investigation | MEDIUM | perl | 5.34.0-3ubuntu1.7 | — | 7.1 | CVE-2026-7017 |
| CVE-2026-9538 | under_investigation | MEDIUM | perl | 5.34.0-3ubuntu1.7 | — | 7.5 | CVE-2026-9538 |
| CVE-2016-2781 | under_investigation | LOW | coreutils | 8.32-4.1ubuntu1.3 | — | 6.5 | CVE-2016-2781 |
| CVE-2022-27943 | under_investigation | LOW | gcc-12 | 12.3.0-1ubuntu1~22.04.3 | — | 5.5 | CVE-2022-27943 |
| CVE-2022-3219 | under_investigation | LOW | gnupg2 | 2.2.27-3ubuntu2.5 | — | 3.3 | CVE-2022-3219 |
| CVE-2022-41409 | under_investigation | LOW | pcre2 | 10.39-3ubuntu0.1 | — | 7.5 | CVE-2022-41409 |
| CVE-2022-4899 | under_investigation | LOW | libzstd | 1.4.8+dfsg-3build1 | — | 7.5 | CVE-2022-4899 |
| CVE-2023-29383 | under_investigation | LOW | shadow | 1:4.8.1-2ubuntu2.2 | — | 3.3 | CVE-2023-29383 |
| CVE-2023-50495 | under_investigation | LOW | ncurses | 6.3-2ubuntu0.2 | — | 6.5 | CVE-2023-50495 |
| CVE-2024-2236 | under_investigation | LOW | libgcrypt20 | 1.9.4-3ubuntu3.2 | — | 5.9 | CVE-2024-2236 |
| CVE-2024-56433 | under_investigation | LOW | shadow | 1:4.8.1-2ubuntu2.2 | — | CVE-2024-56433 | |
| CVE-2025-5278 | under_investigation | LOW | coreutils | 8.32-4.1ubuntu1.3 | — | 4.4 | CVE-2025-5278 |
| CVE-2025-6141 | under_investigation | LOW | ncurses | 6.3-2ubuntu0.2 | — | 4.8 | CVE-2025-6141 |
| CVE-2026-42250 | under_investigation | LOW | bzip2 | 1.0.8-5build1 | — | CVE-2026-42250 | |
| CVE-2026-57062 | under_investigation | LOW | gnupg2 | 2.2.27-3ubuntu2.5 | — | CVE-2026-57062 | |
| CVE-2026-75803 | under_investigation | LOW | openssl | 3.0.2-0ubuntu1.26 | — | CVE-2026-75803 | |
| CVE-2016-20013 | under_investigation | MINIMAL | glibc | 2.35-0ubuntu3.14 | — | 7.5 | CVE-2016-20013 |
| CVE-2017-11164 | under_investigation | MINIMAL | pcre3 | 2:8.39-13ubuntu0.22.04.1 | — | 7.5 | CVE-2017-11164 |
| CVE-2018-5709 | under_investigation | MINIMAL | krb5 | 1.19.2-2ubuntu0.8 | — | 7.5 | CVE-2018-5709 |
| CVE-2023-47039 | under_investigation | MINIMAL | perl | 5.34.0-3ubuntu1.7 | — | 7.8 | CVE-2023-47039 |
Manually reviewed findings with OpenVEX status not_affected. Each row
carries the spec justification label and the evidence for why the vulnerable code does not affect
this image's functionality (and where that was verified). Excluded from the severity counts above;
present as full statements in the OpenVEX document.
| Vulnerability | Severity | Package | Installed | Justification | Evidence / where |
|---|---|---|---|---|---|
| CVE-2025-59250 | HIGH | com.microsoft.sqlserver:mssql-jdbc | 12.10.2 | vulnerable_code_not_present | mssql-jdbc 12.10.2.jre8 (previously 12.8.2.jre8) is well past the fix wave; scanners mis-order the bare '12.10.2' from the jar's pom.properties against the '12.8.2.jre11' fixed-version string because the .jreN suffix breaks their version comparators (known Trivy/Grype issue: aquasecurity/trivy#9745, anchore/grype#3042). The jre11 artifact cannot be used on the Java-8 runtime. Applies to any X.Y.Z.jre8 >= 12.8.2. |
| CVE-2026-2332 | HIGH | org.eclipse.jetty:jetty-http | 9.4.58.v20250814 | vulnerable_code_cannot_be_controlled_by_adversary | jetty-http request smuggling via chunk-extension quoted-string parsing. No OSS fix exists on the Java-8-compatible jetty 9.4 line (9.4.58.v20250814 is the newest on Maven Central and is in the affected range; the advisory's 9.4.60 fix ships only in the HeroDevs NES fork; jetty 10+ needs Java 11). Not adversary-controllable in our topology: grok_connect listens cluster-internally on :1234 with datlas as its ONLY client, connecting directly with no HTTP intermediary (proxy/LB/cache) in between — request smuggling requires a parsing-differential between two HTTP hops, and user input reaches grok_connect solely inside JSON bodies of datlas-composed requests, never as raw protocol elements. Re-review if grok_connect is ever exposed through an ingress/proxy or the spark-java/jetty stack changes. Verified 2026-08-12. |
| CVE-2026-10050 | HIGH | org.eclipse.jetty:jetty-security | 9.4.58.v20250814 | vulnerable_code_not_in_execute_path | jetty-security Digest-authentication bypass (ISO-8859-1 encoding collision). Fixed only in jetty 12.0.36/12.1.10; 9.4 is EOL (NES-only backport) and jetty 10+ needs Java 11. Not in the execute path: grok_connect configures NO HTTP authentication — spark-java 2.9.4 wires no SecurityHandler/LoginService, so jetty's DigestAuthenticator is never instantiated; the service is cluster-internal with datlas as its only client. Re-review if HTTP auth is ever added or the spark/jetty stack changes. Verified 2026-08-12. |
| CVE-2024-6763 | MEDIUM | org.eclipse.jetty:jetty-http | 9.4.58.v20250814 | vulnerable_code_not_in_execute_path | jetty-http HttpURI lenient authority parsing affects applications that use the HttpURI class programmatically for URI validation/redirect construction. Neither spark-java 2.9.4 route handling nor grok_connect code calls HttpURI (no redirects are ever issued); the fix exists only in jetty 12 (Java 17). Verified 2026-08-13. |
| CVE-2026-6790 | MEDIUM | org.eclipse.jetty:jetty-server | 9.4.58.v20250814 | vulnerable_code_cannot_be_controlled_by_adversary | jetty-server Host/authority desynchronization matters where authority selects behavior: virtual hosts, redirects, caches, reverse-proxy routing, request-log trust. grok_connect has none of these (single spark-java route set, no vhosts, no redirects, no cache) and is cluster-internal with datlas as its only client, connecting directly with no proxy hop whose routing could be confused. No fix on the Java-8-compatible jetty 9.4 line (9.4.58 is the newest on Maven Central; later 9.4.x numbers are the commercial NES fork). Verified 2026-08-13. |
| CVE-2026-10532 | LOW | ch.qos.logback:logback-core | 1.3.16 | vulnerable_code_not_in_execute_path | Same surface as CVE-2026-9828: object injection via the SimpleSocketServer/SimpleSSLSocketServer receivers, which grok_connect never runs (appender-only logback.xml, no receiver/server components). Fixed only in 1.5.34 (Java 11+). Verified 2026-08-13. |
| CVE-2026-9828 | LOW | ch.qos.logback:logback-core | 1.3.16 | vulnerable_code_not_in_execute_path | logback-core HardenedObjectInputStream object-injection is reachable only through the SimpleSocketServer/SimpleSSLSocketServer serialized-event receivers. grok_connect never instantiates them: logback.xml configures only ConsoleAppender, AsyncAppender and the in-process QueryStreamAppender (verified src/main/resources/logback.xml). Fixed only in 1.5.33 (Java 11+). Verified 2026-08-13. |
| CVE-2026-1225 | LOW | ch.qos.logback:logback-core | 1.3.16 | vulnerable_code_cannot_be_controlled_by_adversary | logback-core config-processing ACE requires an attacker to MODIFY the logback configuration file. grok_connect's logback.xml is compiled into the read-only shaded jar (src/main/resources/logback.xml), the process runs as the non-root 'grok' user, and the entrypoint sets no -Dlogback.configurationFile override — there is no writable or externally-supplied config path. Fixed only in logback 1.5.25 (Java 11+); 1.3.x is the Java-8 ceiling. Verified 2026-08-13. |