grok_connect:2.8.4 — vulnerability report

0 critical · 0 high · 30 medium · 18 low · 48 total (deduped by CVE) · 8 reviewed not-affected

Image datagrok/grok_connect:2.8.4 · digest sha256:c138de383f8ff24d2b1b1be6c26f5307a25e5a39cda564a12601fe203ca403bf

Open findings

OpenVEX status affected (an upstream fix exists — the action is to apply it) or under_investigation (no upstream fix is available yet; a version match alone does not establish exploitability).

VulnerabilityStatusSeverityPackage InstalledFixed inCVSSDescription
CVE-2023-31486under_investigationMEDIUMperl5.34.0-3ubuntu1.78.1CVE-2023-31486
CVE-2024-10041under_investigationMEDIUMpam1.4.0-11ubuntu2.74.7CVE-2024-10041
CVE-2025-15649under_investigationMEDIUMperl5.34.0-3ubuntu1.75.5CVE-2025-15649
CVE-2026-12087under_investigationMEDIUMperl5.34.0-3ubuntu1.79.1CVE-2026-12087
CVE-2026-13221under_investigationMEDIUMperl5.34.0-3ubuntu1.79.1CVE-2026-13221
CVE-2026-13595under_investigationMEDIUMutil-linux2.37.2-4ubuntu3.55.3CVE-2026-13595
CVE-2026-13757under_investigationMEDIUMp11-kit0.24.0-6build16.2CVE-2026-13757
CVE-2026-15534under_investigationMEDIUMperl5.34.0-3ubuntu1.75.7CVE-2026-15534
CVE-2026-18938under_investigationMEDIUMp11-kit0.24.0-6build16.2CVE-2026-18938
CVE-2026-19487under_investigationMEDIUMperl5.34.0-3ubuntu1.75.3CVE-2026-19487
CVE-2026-27456under_investigationMEDIUMutil-linux2.37.2-4ubuntu3.54.7CVE-2026-27456
CVE-2026-42497under_investigationMEDIUMperl5.34.0-3ubuntu1.77.5CVE-2026-42497
CVE-2026-48959under_investigationMEDIUMperl5.34.0-3ubuntu1.77.5CVE-2026-48959
CVE-2026-48961under_investigationMEDIUMperl5.34.0-3ubuntu1.77.3CVE-2026-48961
CVE-2026-48962under_investigationMEDIUMperl5.34.0-3ubuntu1.77.3CVE-2026-48962
CVE-2026-53613under_investigationMEDIUMutil-linux2.37.2-4ubuntu3.5CVE-2026-53613
CVE-2026-53615under_investigationMEDIUMutil-linux2.37.2-4ubuntu3.5CVE-2026-53615
CVE-2026-53910under_investigationMEDIUMdiffutils1:3.8-0ubuntu2CVE-2026-53910
CVE-2026-54369under_investigationMEDIUMacl2.3.1-18.4CVE-2026-54369
CVE-2026-54370under_investigationMEDIUMacl2.3.1-17.2CVE-2026-54370
CVE-2026-54371under_investigationMEDIUMattr1:2.5.1-1build18.4CVE-2026-54371
CVE-2026-56391under_investigationMEDIUMcoreutils8.32-4.1ubuntu1.3CVE-2026-56391
CVE-2026-56392under_investigationMEDIUMcoreutils8.32-4.1ubuntu1.3CVE-2026-56392
CVE-2026-57432under_investigationMEDIUMperl5.34.0-3ubuntu1.78.4CVE-2026-57432
CVE-2026-57433under_investigationMEDIUMperl5.34.0-3ubuntu1.79.8CVE-2026-57433
CVE-2026-59949affectedMEDIUMat.yawk.lz4:lz4-java1.10.11.11.16.5CVE-2026-59949
CVE-2026-6368under_investigationMEDIUMglibc2.35-0ubuntu3.14CVE-2026-6368
CVE-2026-6791under_investigationMEDIUMglibc2.35-0ubuntu3.14CVE-2026-6791
CVE-2026-7017under_investigationMEDIUMperl5.34.0-3ubuntu1.77.1CVE-2026-7017
CVE-2026-9538under_investigationMEDIUMperl5.34.0-3ubuntu1.77.5CVE-2026-9538
CVE-2016-2781under_investigationLOWcoreutils8.32-4.1ubuntu1.36.5CVE-2016-2781
CVE-2022-27943under_investigationLOWgcc-1212.3.0-1ubuntu1~22.04.35.5CVE-2022-27943
CVE-2022-3219under_investigationLOWgnupg22.2.27-3ubuntu2.53.3CVE-2022-3219
CVE-2022-41409under_investigationLOWpcre210.39-3ubuntu0.17.5CVE-2022-41409
CVE-2022-4899under_investigationLOWlibzstd1.4.8+dfsg-3build17.5CVE-2022-4899
CVE-2023-29383under_investigationLOWshadow1:4.8.1-2ubuntu2.23.3CVE-2023-29383
CVE-2023-50495under_investigationLOWncurses6.3-2ubuntu0.26.5CVE-2023-50495
CVE-2024-2236under_investigationLOWlibgcrypt201.9.4-3ubuntu3.25.9CVE-2024-2236
CVE-2024-56433under_investigationLOWshadow1:4.8.1-2ubuntu2.2CVE-2024-56433
CVE-2025-5278under_investigationLOWcoreutils8.32-4.1ubuntu1.34.4CVE-2025-5278
CVE-2025-6141under_investigationLOWncurses6.3-2ubuntu0.24.8CVE-2025-6141
CVE-2026-42250under_investigationLOWbzip21.0.8-5build1CVE-2026-42250
CVE-2026-57062under_investigationLOWgnupg22.2.27-3ubuntu2.5CVE-2026-57062
CVE-2026-75803under_investigationLOWopenssl3.0.2-0ubuntu1.26CVE-2026-75803
CVE-2016-20013under_investigationMINIMALglibc2.35-0ubuntu3.147.5CVE-2016-20013
CVE-2017-11164under_investigationMINIMALpcre32:8.39-13ubuntu0.22.04.17.5CVE-2017-11164
CVE-2018-5709under_investigationMINIMALkrb51.19.2-2ubuntu0.87.5CVE-2018-5709
CVE-2023-47039under_investigationMINIMALperl5.34.0-3ubuntu1.77.8CVE-2023-47039

Reviewed findings — not affected

Manually reviewed findings with OpenVEX status not_affected. Each row carries the spec justification label and the evidence for why the vulnerable code does not affect this image's functionality (and where that was verified). Excluded from the severity counts above; present as full statements in the OpenVEX document.

VulnerabilitySeverityPackageInstalled JustificationEvidence / where
CVE-2025-59250HIGHcom.microsoft.sqlserver:mssql-jdbc12.10.2vulnerable_code_not_presentmssql-jdbc 12.10.2.jre8 (previously 12.8.2.jre8) is well past the fix wave; scanners mis-order the bare '12.10.2' from the jar's pom.properties against the '12.8.2.jre11' fixed-version string because the .jreN suffix breaks their version comparators (known Trivy/Grype issue: aquasecurity/trivy#9745, anchore/grype#3042). The jre11 artifact cannot be used on the Java-8 runtime. Applies to any X.Y.Z.jre8 >= 12.8.2.
CVE-2026-2332HIGHorg.eclipse.jetty:jetty-http9.4.58.v20250814vulnerable_code_cannot_be_controlled_by_adversaryjetty-http request smuggling via chunk-extension quoted-string parsing. No OSS fix exists on the Java-8-compatible jetty 9.4 line (9.4.58.v20250814 is the newest on Maven Central and is in the affected range; the advisory's 9.4.60 fix ships only in the HeroDevs NES fork; jetty 10+ needs Java 11). Not adversary-controllable in our topology: grok_connect listens cluster-internally on :1234 with datlas as its ONLY client, connecting directly with no HTTP intermediary (proxy/LB/cache) in between — request smuggling requires a parsing-differential between two HTTP hops, and user input reaches grok_connect solely inside JSON bodies of datlas-composed requests, never as raw protocol elements. Re-review if grok_connect is ever exposed through an ingress/proxy or the spark-java/jetty stack changes. Verified 2026-08-12.
CVE-2026-10050HIGHorg.eclipse.jetty:jetty-security9.4.58.v20250814vulnerable_code_not_in_execute_pathjetty-security Digest-authentication bypass (ISO-8859-1 encoding collision). Fixed only in jetty 12.0.36/12.1.10; 9.4 is EOL (NES-only backport) and jetty 10+ needs Java 11. Not in the execute path: grok_connect configures NO HTTP authentication — spark-java 2.9.4 wires no SecurityHandler/LoginService, so jetty's DigestAuthenticator is never instantiated; the service is cluster-internal with datlas as its only client. Re-review if HTTP auth is ever added or the spark/jetty stack changes. Verified 2026-08-12.
CVE-2024-6763MEDIUMorg.eclipse.jetty:jetty-http9.4.58.v20250814vulnerable_code_not_in_execute_pathjetty-http HttpURI lenient authority parsing affects applications that use the HttpURI class programmatically for URI validation/redirect construction. Neither spark-java 2.9.4 route handling nor grok_connect code calls HttpURI (no redirects are ever issued); the fix exists only in jetty 12 (Java 17). Verified 2026-08-13.
CVE-2026-6790MEDIUMorg.eclipse.jetty:jetty-server9.4.58.v20250814vulnerable_code_cannot_be_controlled_by_adversaryjetty-server Host/authority desynchronization matters where authority selects behavior: virtual hosts, redirects, caches, reverse-proxy routing, request-log trust. grok_connect has none of these (single spark-java route set, no vhosts, no redirects, no cache) and is cluster-internal with datlas as its only client, connecting directly with no proxy hop whose routing could be confused. No fix on the Java-8-compatible jetty 9.4 line (9.4.58 is the newest on Maven Central; later 9.4.x numbers are the commercial NES fork). Verified 2026-08-13.
CVE-2026-10532LOWch.qos.logback:logback-core1.3.16vulnerable_code_not_in_execute_pathSame surface as CVE-2026-9828: object injection via the SimpleSocketServer/SimpleSSLSocketServer receivers, which grok_connect never runs (appender-only logback.xml, no receiver/server components). Fixed only in 1.5.34 (Java 11+). Verified 2026-08-13.
CVE-2026-9828LOWch.qos.logback:logback-core1.3.16vulnerable_code_not_in_execute_pathlogback-core HardenedObjectInputStream object-injection is reachable only through the SimpleSocketServer/SimpleSSLSocketServer serialized-event receivers. grok_connect never instantiates them: logback.xml configures only ConsoleAppender, AsyncAppender and the in-process QueryStreamAppender (verified src/main/resources/logback.xml). Fixed only in 1.5.33 (Java 11+). Verified 2026-08-13.
CVE-2026-1225LOWch.qos.logback:logback-core1.3.16vulnerable_code_cannot_be_controlled_by_adversarylogback-core config-processing ACE requires an attacker to MODIFY the logback configuration file. grok_connect's logback.xml is compiled into the read-only shaded jar (src/main/resources/logback.xml), the process runs as the non-root 'grok' user, and the entrypoint sets no -Dlogback.configurationFile override — there is no writable or externally-supplied config path. Fixed only in logback 1.5.25 (Java 11+); 1.3.x is the Java-8 ceiling. Verified 2026-08-13.