1 critical · 30 high · 29 medium · 145 low · 206 total (deduped by CVE) · 1 reviewed not-affected
Image datagrok/grok_tester:6.5.6 · digest sha256:582fb24eb1063ea435ef0df6c7d71cb299d95f72db7101b5f96e27476e0279ca
OpenVEX status affected (an upstream fix exists — the action is to
apply it) or under_investigation (no upstream fix is available yet; a version match
alone does not establish exploitability).
| Vulnerability | Status | Severity | Package | Installed | Fixed in | CVSS | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-53791 | under_investigation | CRITICAL | rsync | 3.4.1+ds1-5+deb13u4 | — | 9.1 | CVE-2026-53791 |
| CVE-2026-14257 | affected | HIGH | brace-expansion | 5.0.7 | 5.0.8 | CVE-2026-14257 | |
| CVE-2026-14456 | under_investigation | HIGH | openssl | 3.5.6-1~deb13u2 | — | 7.5 | CVE-2026-14456 |
| CVE-2026-34980 | under_investigation | HIGH | cups | 2.4.10-3+deb13u2 | — | 7.5 | CVE-2026-34980 |
| CVE-2026-53783 | under_investigation | HIGH | rsync | 3.4.1+ds1-5+deb13u4 | — | 8.6 | CVE-2026-53783 |
| CVE-2026-53784 | under_investigation | HIGH | rsync | 3.4.1+ds1-5+deb13u4 | — | 8.4 | CVE-2026-53784 |
| CVE-2026-53785 | under_investigation | HIGH | rsync | 3.4.1+ds1-5+deb13u4 | — | 6.9 | CVE-2026-53785 |
| CVE-2026-53790 | under_investigation | HIGH | rsync | 3.4.1+ds1-5+deb13u4 | — | 9.2 | CVE-2026-53790 |
| CVE-2026-53793 | under_investigation | HIGH | rsync | 3.4.1+ds1-5+deb13u4 | — | 9.1 | CVE-2026-53793 |
| CVE-2026-53795 | under_investigation | HIGH | rsync | 3.4.1+ds1-5+deb13u4 | — | 7.2 | CVE-2026-53795 |
| CVE-2026-53802 | under_investigation | HIGH | rsync | 3.4.1+ds1-5+deb13u4 | — | 8.4 | CVE-2026-53802 |
| CVE-2026-53803 | under_investigation | HIGH | rsync | 3.4.1+ds1-5+deb13u4 | — | 8.5 | CVE-2026-53803 |
| CVE-2026-54369 | under_investigation | HIGH | acl | 2.3.2-2 | — | 8.4 | CVE-2026-54369 |
| CVE-2026-54371 | under_investigation | HIGH | attr | 1:2.5.2-3 | — | 8.4 | CVE-2026-54371 |
| CVE-2026-56876 | under_investigation | HIGH | extract-zip | 2.0.1 | — | CVE-2026-56876 | |
| CVE-2026-58050 | under_investigation | HIGH | libssh2 | 1.11.1-1+deb13u1 | — | 7.5 | CVE-2026-58050 |
| CVE-2026-66032 | under_investigation | HIGH | libssh2 | 1.11.1-1+deb13u1 | — | 8.7 | CVE-2026-66032 |
| CVE-2026-66034 | under_investigation | HIGH | libssh2 | 1.11.1-1+deb13u1 | — | 7.7 | CVE-2026-66034 |
| CVE-2026-69152 | affected | HIGH | brace-expansion | 5.0.7 | 5.0.9 | 7.5 | CVE-2026-69152 |
| CVE-2026-69192 | affected | HIGH | ip-address | 10.2.0 | 10.3.1 | 7.7 | CVE-2026-69192 |
| CVE-2026-70452 | under_investigation | HIGH | rsync | 3.4.1+ds1-5+deb13u4 | — | 9.1 | CVE-2026-70452 |
| CVE-2026-70453 | under_investigation | HIGH | rsync | 3.4.1+ds1-5+deb13u4 | — | 8.7 | CVE-2026-70453 |
| CVE-2026-70454 | under_investigation | HIGH | rsync | 3.4.1+ds1-5+deb13u4 | — | 7.6 | CVE-2026-70454 |
| CVE-2026-70455 | under_investigation | HIGH | rsync | 3.4.1+ds1-5+deb13u4 | — | 8.7 | CVE-2026-70455 |
| CVE-2026-70456 | under_investigation | HIGH | rsync | 3.4.1+ds1-5+deb13u4 | — | 8.8 | CVE-2026-70456 |
| CVE-2026-70458 | under_investigation | HIGH | rsync | 3.4.1+ds1-5+deb13u4 | — | 8.8 | CVE-2026-70458 |
| CVE-2026-70460 | under_investigation | HIGH | rsync | 3.4.1+ds1-5+deb13u4 | — | 9.2 | CVE-2026-70460 |
| CVE-2026-70461 | under_investigation | HIGH | rsync | 3.4.1+ds1-5+deb13u4 | — | 8.8 | CVE-2026-70461 |
| CVE-2026-70463 | under_investigation | HIGH | rsync | 3.4.1+ds1-5+deb13u4 | — | 8.6 | CVE-2026-70463 |
| CVE-2026-70464 | under_investigation | HIGH | rsync | 3.4.1+ds1-5+deb13u4 | — | 8.7 | CVE-2026-70464 |
| CVE-2026-73566 | affected | HIGH | tar | 7.5.19 | 7.5.21 | 7.5 | CVE-2026-73566 |
| CVE-2024-52615 | under_investigation | MEDIUM | avahi | 0.8-16 | — | 5.3 | CVE-2024-52615 |
| CVE-2024-52616 | under_investigation | MEDIUM | avahi | 0.8-16 | — | 5.3 | CVE-2024-52616 |
| CVE-2025-59529 | under_investigation | MEDIUM | avahi | 0.8-16 | — | 5.5 | CVE-2025-59529 |
| CVE-2025-66382 | under_investigation | MEDIUM | expat | 2.8.3-1~deb13u1 | — | 5.5 | CVE-2025-66382 |
| CVE-2026-15157 | affected | MEDIUM | undici | 6.27.0 | 6.28.0 | 5.4 | CVE-2026-15157 |
| CVE-2026-16728 | affected | MEDIUM | undici | 6.27.0 | 6.28.0 | 6.5 | CVE-2026-16728 |
| CVE-2026-16729 | affected | MEDIUM | undici | 6.27.0 | 6.28.0 | 6.5 | CVE-2026-16729 |
| CVE-2026-34979 | under_investigation | MEDIUM | cups | 2.4.10-3+deb13u2 | — | 5.3 | CVE-2026-34979 |
| CVE-2026-39314 | under_investigation | MEDIUM | cups | 2.4.10-3+deb13u2 | — | 6.2 | CVE-2026-39314 |
| CVE-2026-39316 | under_investigation | MEDIUM | cups | 2.4.10-3+deb13u2 | — | 6.2 | CVE-2026-39316 |
| CVE-2026-41079 | under_investigation | MEDIUM | cups | 2.4.10-3+deb13u2 | — | 5.4 | CVE-2026-41079 |
| CVE-2026-53786 | under_investigation | MEDIUM | rsync | 3.4.1+ds1-5+deb13u4 | — | 6.9 | CVE-2026-53786 |
| CVE-2026-53788 | under_investigation | MEDIUM | rsync | 3.4.1+ds1-5+deb13u4 | — | 6.9 | CVE-2026-53788 |
| CVE-2026-53789 | under_investigation | MEDIUM | rsync | 3.4.1+ds1-5+deb13u4 | — | 7.1 | CVE-2026-53789 |
| CVE-2026-53792 | under_investigation | MEDIUM | rsync | 3.4.1+ds1-5+deb13u4 | — | 7.1 | CVE-2026-53792 |
| CVE-2026-53794 | under_investigation | MEDIUM | rsync | 3.4.1+ds1-5+deb13u4 | — | 6.9 | CVE-2026-53794 |
| CVE-2026-53796 | under_investigation | MEDIUM | rsync | 3.4.1+ds1-5+deb13u4 | — | 5.8 | CVE-2026-53796 |
| CVE-2026-53797 | under_investigation | MEDIUM | rsync | 3.4.1+ds1-5+deb13u4 | — | 5.7 | CVE-2026-53797 |
| CVE-2026-53798 | under_investigation | MEDIUM | rsync | 3.4.1+ds1-5+deb13u4 | — | 6.9 | CVE-2026-53798 |
| CVE-2026-53799 | under_investigation | MEDIUM | rsync | 3.4.1+ds1-5+deb13u4 | — | 7.2 | CVE-2026-53799 |
| CVE-2026-53800 | under_investigation | MEDIUM | rsync | 3.4.1+ds1-5+deb13u4 | — | 5.7 | CVE-2026-53800 |
| CVE-2026-53801 | under_investigation | MEDIUM | rsync | 3.4.1+ds1-5+deb13u4 | — | 8.2 | CVE-2026-53801 |
| CVE-2026-54272 | affected | MEDIUM | ip-address | 10.2.0 | 10.2.1 | 6.9 | CVE-2026-54272 |
| CVE-2026-54370 | under_investigation | MEDIUM | acl | 2.3.2-2 | — | 7.2 | CVE-2026-54370 |
| CVE-2026-58051 | under_investigation | MEDIUM | libssh2 | 1.11.1-1+deb13u1 | — | 8.3 | CVE-2026-58051 |
| CVE-2026-69198 | affected | MEDIUM | ip-address | 10.2.0 | 10.2.2 | 6.9 | CVE-2026-69198 |
| CVE-2026-70457 | under_investigation | MEDIUM | rsync | 3.4.1+ds1-5+deb13u4 | — | 8.3 | CVE-2026-70457 |
| CVE-2026-70459 | under_investigation | MEDIUM | rsync | 3.4.1+ds1-5+deb13u4 | — | 6.9 | CVE-2026-70459 |
| CVE-2026-70462 | under_investigation | MEDIUM | rsync | 3.4.1+ds1-5+deb13u4 | — | 7.1 | CVE-2026-70462 |
| CVE-2017-7475 | under_investigation | LOW | cairo | 1.18.4-1 | — | 5.5 | CVE-2017-7475 |
| CVE-2021-31879 | under_investigation | LOW | wget | 1.25.0-2 | — | 6.1 | CVE-2021-31879 |
| CVE-2024-56433 | under_investigation | LOW | shadow | 1:4.17.4-2 | — | CVE-2024-56433 | |
| CVE-2025-50422 | under_investigation | LOW | cairo | 1.18.4-1 | — | CVE-2025-50422 | |
| CVE-2025-58436 | under_investigation | LOW | cups | 2.4.10-3+deb13u2 | — | 5.5 | CVE-2025-58436 |
| CVE-2025-6141 | under_investigation | LOW | ncurses | 6.5+20250216-2 | — | 4.8 | CVE-2025-6141 |
| CVE-2025-61915 | under_investigation | LOW | cups | 2.4.10-3+deb13u2 | — | 6.7 | CVE-2025-61915 |
| CVE-2025-68276 | under_investigation | LOW | avahi | 0.8-16 | — | 5.5 | CVE-2025-68276 |
| CVE-2025-68468 | under_investigation | LOW | avahi | 0.8-16 | — | 6.5 | CVE-2025-68468 |
| CVE-2025-68471 | under_investigation | LOW | avahi | 0.8-16 | — | 6.5 | CVE-2025-68471 |
| CVE-2025-69720 | under_investigation | LOW | ncurses | 6.5+20250216-2 | — | 7.8 | CVE-2025-69720 |
| CVE-2026-10536 | under_investigation | LOW | curl | 8.14.1-2+deb13u4 | — | 9.8 | CVE-2026-10536 |
| CVE-2026-11822 | under_investigation | LOW | sqlite3 | 3.46.1-7+deb13u1 | — | 8.5 | CVE-2026-11822 |
| CVE-2026-11824 | under_investigation | LOW | sqlite3 | 3.46.1-7+deb13u1 | — | 8.5 | CVE-2026-11824 |
| CVE-2026-11856 | under_investigation | LOW | curl | 8.14.1-2+deb13u4 | — | 9.8 | CVE-2026-11856 |
| CVE-2026-12064 | under_investigation | LOW | curl | 8.14.1-2+deb13u4 | — | 7.5 | CVE-2026-12064 |
| CVE-2026-13757 | under_investigation | LOW | p11-kit | 0.25.5-3 | — | 6.2 | CVE-2026-13757 |
| CVE-2026-15059 | under_investigation | LOW | systemd | 257.13-1~deb13u1 | — | CVE-2026-15059 | |
| CVE-2026-15146 | under_investigation | LOW | wget | 1.25.0-2 | — | 5.9 | CVE-2026-15146 |
| CVE-2026-15588 | under_investigation | LOW | glib2.0 | 2.84.4-3~deb13u3 | — | 5.3 | CVE-2026-15588 |
| CVE-2026-16118 | under_investigation | LOW | glib2.0 | 2.84.4-3~deb13u3 | — | 7.1 | CVE-2026-16118 |
| CVE-2026-16742 | under_investigation | LOW | systemd | 257.13-1~deb13u1 | — | CVE-2026-16742 | |
| CVE-2026-18477 | under_investigation | LOW | tar | 1.35+dfsg-3.1 | — | 4.4 | CVE-2026-18477 |
| CVE-2026-18508 | under_investigation | LOW | tar | 1.35+dfsg-3.1 | — | 4.4 | CVE-2026-18508 |
| CVE-2026-18739 | under_investigation | LOW | popt | 1.19+dfsg-2 | — | 2.5 | CVE-2026-18739 |
| CVE-2026-18839 | under_investigation | LOW | popt | 1.19+dfsg-2 | — | 2.2 | CVE-2026-18839 |
| CVE-2026-18938 | under_investigation | LOW | p11-kit | 0.25.5-3 | — | 6.2 | CVE-2026-18938 |
| CVE-2026-19542 | under_investigation | LOW | glibc | 2.41-12+deb13u3 | — | CVE-2026-19542 | |
| CVE-2026-22185 | under_investigation | LOW | openldap | 2.6.10+dfsg-1 | — | 4.6 | CVE-2026-22185 |
| CVE-2026-24401 | under_investigation | LOW | avahi | 0.8-16 | — | 6.5 | CVE-2026-24401 |
| CVE-2026-25068 | under_investigation | LOW | alsa-lib | 1.2.14-1 | — | 4.6 | CVE-2026-25068 |
| CVE-2026-27171 | under_investigation | LOW | zlib | 1:1.3.dfsg+really1.3.1-1 | — | 5.5 | CVE-2026-27171 |
| CVE-2026-27447 | under_investigation | LOW | cups | 2.4.10-3+deb13u2 | — | 6.3 | CVE-2026-27447 |
| CVE-2026-3184 | under_investigation | LOW | util-linux | 2.41.5-0+deb13u1 | — | 5.3 | CVE-2026-3184 |
| CVE-2026-34933 | under_investigation | LOW | avahi | 0.8-16 | — | 5.5 | CVE-2026-34933 |
| CVE-2026-34978 | under_investigation | LOW | cups | 2.4.10-3+deb13u2 | — | 6.5 | CVE-2026-34978 |
| CVE-2026-34990 | under_investigation | LOW | cups | 2.4.10-3+deb13u2 | — | 5 | CVE-2026-34990 |
| CVE-2026-40228 | under_investigation | LOW | systemd | 257.13-1~deb13u1 | — | 3.3 | CVE-2026-40228 |
| CVE-2026-41991 | under_investigation | LOW | gzip | 1.13-1 | — | 4.7 | CVE-2026-41991 |
| CVE-2026-41992 | under_investigation | LOW | gzip | 1.13-1 | — | 7.5 | CVE-2026-41992 |
| CVE-2026-42250 | under_investigation | LOW | bzip2 | 1.0.8-6 | — | CVE-2026-42250 | |
| CVE-2026-50812 | under_investigation | LOW | sqlite3 | 3.46.1-7+deb13u1 | — | 5.5 | CVE-2026-50812 |
| CVE-2026-50813 | under_investigation | LOW | sqlite3 | 3.46.1-7+deb13u1 | — | 5.5 | CVE-2026-50813 |
| CVE-2026-5435 | under_investigation | LOW | glibc | 2.41-12+deb13u3 | — | 7.3 | CVE-2026-5435 |
| CVE-2026-54411 | under_investigation | LOW | pam | 1.7.0-5 | — | CVE-2026-54411 | |
| CVE-2026-5450 | under_investigation | LOW | glibc | 2.41-12+deb13u3 | — | 9.8 | CVE-2026-5450 |
| CVE-2026-5704 | under_investigation | LOW | tar | 1.35+dfsg-3.1 | — | 5.5 | CVE-2026-5704 |
| CVE-2026-58010 | under_investigation | LOW | glib2.0 | 2.84.4-3~deb13u3 | — | 8.2 | CVE-2026-58010 |
| CVE-2026-58011 | under_investigation | LOW | glib2.0 | 2.84.4-3~deb13u3 | — | 7.5 | CVE-2026-58011 |
| CVE-2026-58012 | under_investigation | LOW | glib2.0 | 2.84.4-3~deb13u3 | — | 8.2 | CVE-2026-58012 |
| CVE-2026-58013 | under_investigation | LOW | glib2.0 | 2.84.4-3~deb13u3 | — | 8.2 | CVE-2026-58013 |
| CVE-2026-58014 | under_investigation | LOW | glib2.0 | 2.84.4-3~deb13u3 | — | 8.6 | CVE-2026-58014 |
| CVE-2026-58015 | under_investigation | LOW | glib2.0 | 2.84.4-3~deb13u3 | — | 7.5 | CVE-2026-58015 |
| CVE-2026-58016 | under_investigation | LOW | glib2.0 | 2.84.4-3~deb13u3 | — | 9.1 | CVE-2026-58016 |
| CVE-2026-58055 | under_investigation | LOW | nghttp2 | 1.64.0-1.1+deb13u1 | — | 6.3 | CVE-2026-58055 |
| CVE-2026-58469 | under_investigation | LOW | wget | 1.25.0-2 | — | 8.7 | CVE-2026-58469 |
| CVE-2026-58470 | under_investigation | LOW | wget | 1.25.0-2 | — | 6.9 | CVE-2026-58470 |
| CVE-2026-58471 | under_investigation | LOW | wget | 1.25.0-2 | — | 7.1 | CVE-2026-58471 |
| CVE-2026-58472 | under_investigation | LOW | wget | 1.25.0-2 | — | 7.1 | CVE-2026-58472 |
| CVE-2026-5928 | under_investigation | LOW | glibc | 2.41-12+deb13u3 | — | 7.5 | CVE-2026-5928 |
| CVE-2026-6238 | under_investigation | LOW | glibc | 2.41-12+deb13u3 | — | 6.5 | CVE-2026-6238 |
| CVE-2026-6368 | under_investigation | LOW | glibc | 2.41-12+deb13u3 | — | CVE-2026-6368 | |
| CVE-2026-66046 | under_investigation | LOW | expat | 2.8.3-1~deb13u1 | — | 7.5 | CVE-2026-66046 |
| CVE-2026-6653 | under_investigation | LOW | libxml2 | 2.12.7+dfsg+really2.9.14-2.1+deb13u3 | — | 9.8 | CVE-2026-6653 |
| CVE-2026-6791 | under_investigation | LOW | glibc | 2.41-12+deb13u3 | — | CVE-2026-6791 | |
| CVE-2026-76956 | under_investigation | LOW | expat | 2.8.3-1~deb13u1 | — | CVE-2026-76956 | |
| CVE-2026-76957 | under_investigation | LOW | expat | 2.8.3-1~deb13u1 | — | CVE-2026-76957 | |
| CVE-2026-8286 | under_investigation | LOW | curl | 8.14.1-2+deb13u4 | — | 8.1 | CVE-2026-8286 |
| CVE-2026-8458 | under_investigation | LOW | curl | 8.14.1-2+deb13u4 | — | 6.5 | CVE-2026-8458 |
| CVE-2026-8924 | under_investigation | LOW | curl | 8.14.1-2+deb13u4 | — | 9.1 | CVE-2026-8924 |
| CVE-2026-8926 | under_investigation | LOW | curl | 8.14.1-2+deb13u4 | — | 9.1 | CVE-2026-8926 |
| CVE-2026-8927 | under_investigation | LOW | curl | 8.14.1-2+deb13u4 | — | 9.1 | CVE-2026-8927 |
| CVE-2026-8932 | under_investigation | LOW | curl | 8.14.1-2+deb13u4 | — | 7.5 | CVE-2026-8932 |
| CVE-2026-9079 | under_investigation | LOW | curl | 8.14.1-2+deb13u4 | — | 9.8 | CVE-2026-9079 |
| CVE-2026-9080 | under_investigation | LOW | curl | 8.14.1-2+deb13u4 | — | 7.3 | CVE-2026-9080 |
| CVE-2026-9545 | under_investigation | LOW | curl | 8.14.1-2+deb13u4 | — | 7.5 | CVE-2026-9545 |
| CVE-2005-2541 | under_investigation | MINIMAL | tar | 1.35+dfsg-3.1 | — | 10 | CVE-2005-2541 |
| CVE-2007-5686 | under_investigation | MINIMAL | shadow | 1:4.17.4-2 | — | 4.9 | CVE-2007-5686 |
| CVE-2010-4756 | under_investigation | MINIMAL | glibc | 2.41-12+deb13u3 | — | 4 | CVE-2010-4756 |
| CVE-2011-3374 | under_investigation | MINIMAL | apt | 3.0.3 | — | 3.7 | CVE-2011-3374 |
| CVE-2011-3389 | under_investigation | MINIMAL | gnutls28 | 3.8.9-3+deb13u4 | — | 4.3 | CVE-2011-3389 |
| CVE-2012-0039 | under_investigation | MINIMAL | glib2.0 | 2.84.4-3~deb13u3 | — | 5 | CVE-2012-0039 |
| CVE-2013-4392 | under_investigation | MINIMAL | systemd | 257.13-1~deb13u1 | — | 3.3 | CVE-2013-4392 |
| CVE-2014-8166 | under_investigation | MINIMAL | cups | 2.4.10-3+deb13u2 | — | 8.8 | CVE-2014-8166 |
| CVE-2015-3276 | under_investigation | MINIMAL | openldap | 2.6.10+dfsg-1 | — | 7.5 | CVE-2015-3276 |
| CVE-2017-11695 | under_investigation | MINIMAL | nss | 2:3.110-1+deb13u4 | — | 7.8 | CVE-2017-11695 |
| CVE-2017-11696 | under_investigation | MINIMAL | nss | 2:3.110-1+deb13u4 | — | 7.8 | CVE-2017-11696 |
| CVE-2017-11697 | under_investigation | MINIMAL | nss | 2:3.110-1+deb13u4 | — | 7.8 | CVE-2017-11697 |
| CVE-2017-11698 | under_investigation | MINIMAL | nss | 2:3.110-1+deb13u4 | — | 7.8 | CVE-2017-11698 |
| CVE-2017-14159 | under_investigation | MINIMAL | openldap | 2.6.10+dfsg-1 | — | 4.7 | CVE-2017-14159 |
| CVE-2017-17740 | under_investigation | MINIMAL | openldap | 2.6.10+dfsg-1 | — | 7.5 | CVE-2017-17740 |
| CVE-2017-18018 | under_investigation | MINIMAL | coreutils | 9.7-3 | — | 4.7 | CVE-2017-18018 |
| CVE-2018-1000021 | under_investigation | MINIMAL | git | 1:2.47.3-0+deb13u1 | — | 5 | CVE-2018-1000021 |
| CVE-2018-18064 | under_investigation | MINIMAL | cairo | 1.18.4-1 | — | 6.5 | CVE-2018-18064 |
| CVE-2018-20796 | under_investigation | MINIMAL | glibc | 2.41-12+deb13u3 | — | 7.5 | CVE-2018-20796 |
| CVE-2018-5709 | under_investigation | MINIMAL | krb5 | 1.21.3-5+deb13u1 | — | 7.5 | CVE-2018-5709 |
| CVE-2019-1010022 | under_investigation | MINIMAL | glibc | 2.41-12+deb13u3 | — | 9.8 | CVE-2019-1010022 |
| CVE-2019-1010023 | under_investigation | MINIMAL | glibc | 2.41-12+deb13u3 | — | 8.8 | CVE-2019-1010023 |
| CVE-2019-1010024 | under_investigation | MINIMAL | glibc | 2.41-12+deb13u3 | — | 5.3 | CVE-2019-1010024 |
| CVE-2019-1010025 | under_investigation | MINIMAL | glibc | 2.41-12+deb13u3 | — | 5.3 | CVE-2019-1010025 |
| CVE-2019-9192 | under_investigation | MINIMAL | glibc | 2.41-12+deb13u3 | — | 7.5 | CVE-2019-9192 |
| CVE-2020-15719 | under_investigation | MINIMAL | openldap | 2.6.10+dfsg-1 | — | 4.2 | CVE-2020-15719 |
| CVE-2021-4214 | under_investigation | MINIMAL | libpng1.6 | 1.6.48-1+deb13u5 | — | 5.5 | CVE-2021-4214 |
| CVE-2021-4217 | under_investigation | MINIMAL | unzip | 6.0-29+deb13u1 | — | 3.3 | CVE-2021-4217 |
| CVE-2021-45346 | under_investigation | MINIMAL | sqlite3 | 3.46.1-7+deb13u1 | — | 4.3 | CVE-2021-45346 |
| CVE-2022-0563 | under_investigation | MINIMAL | util-linux | 2.41.5-0+deb13u1 | — | 5.5 | CVE-2022-0563 |
| CVE-2022-24975 | under_investigation | MINIMAL | git | 1:2.47.3-0+deb13u1 | — | 7.5 | CVE-2022-24975 |
| CVE-2023-31437 | under_investigation | MINIMAL | systemd | 257.13-1~deb13u1 | — | 5.3 | CVE-2023-31437 |
| CVE-2023-31438 | under_investigation | MINIMAL | systemd | 257.13-1~deb13u1 | — | 5.3 | CVE-2023-31438 |
| CVE-2023-31439 | under_investigation | MINIMAL | systemd | 257.13-1~deb13u1 | — | 5.3 | CVE-2023-31439 |
| CVE-2023-37769 | under_investigation | MINIMAL | pixman | 0.44.0-3 | — | 6.5 | CVE-2023-37769 |
| CVE-2023-45913 | under_investigation | MINIMAL | mesa | 25.0.7-2+deb13u1 | — | 6.2 | CVE-2023-45913 |
| CVE-2023-45919 | under_investigation | MINIMAL | mesa | 25.0.7-2+deb13u1 | — | 5.3 | CVE-2023-45919 |
| CVE-2023-45922 | under_investigation | MINIMAL | mesa | 25.0.7-2+deb13u1 | — | 4.3 | CVE-2023-45922 |
| CVE-2023-45931 | under_investigation | MINIMAL | mesa | 25.0.7-2+deb13u1 | — | 7.5 | CVE-2023-45931 |
| CVE-2024-25260 | under_investigation | MINIMAL | elfutils | 0.192-4 | — | 4 | CVE-2024-25260 |
| CVE-2024-26458 | under_investigation | MINIMAL | krb5 | 1.21.3-5+deb13u1 | — | 5.3 | CVE-2024-26458 |
| CVE-2024-26461 | under_investigation | MINIMAL | krb5 | 1.21.3-5+deb13u1 | — | 7.5 | CVE-2024-26461 |
| CVE-2024-52005 | under_investigation | MINIMAL | git | 1:2.47.3-0+deb13u1 | — | 8.8 | CVE-2024-52005 |
| CVE-2024-7883 | under_investigation | MINIMAL | llvm-toolchain-19 | 1:19.1.7-3 | — | CVE-2024-7883 | |
| CVE-2025-10966 | under_investigation | MINIMAL | curl | 8.14.1-2+deb13u4 | — | 4.3 | CVE-2025-10966 |
| CVE-2025-1352 | under_investigation | MINIMAL | elfutils | 0.192-4 | — | 7.5 | CVE-2025-1352 |
| CVE-2025-1365 | under_investigation | MINIMAL | elfutils | 0.192-4 | — | 7.8 | CVE-2025-1365 |
| CVE-2025-1371 | under_investigation | MINIMAL | elfutils | 0.192-4 | — | 5.5 | CVE-2025-1371 |
| CVE-2025-1372 | under_investigation | MINIMAL | elfutils | 0.192-4 | — | 7.8 | CVE-2025-1372 |
| CVE-2025-1376 | under_investigation | MINIMAL | elfutils | 0.192-4 | — | 4.7 | CVE-2025-1376 |
| CVE-2025-1377 | under_investigation | MINIMAL | elfutils | 0.192-4 | — | 5.5 | CVE-2025-1377 |
| CVE-2025-14017 | under_investigation | MINIMAL | curl | 8.14.1-2+deb13u4 | — | 6.3 | CVE-2025-14017 |
| CVE-2025-15079 | under_investigation | MINIMAL | curl | 8.14.1-2+deb13u4 | — | 5.3 | CVE-2025-15079 |
| CVE-2025-15224 | under_investigation | MINIMAL | curl | 8.14.1-2+deb13u4 | — | 3.1 | CVE-2025-15224 |
| CVE-2025-5278 | under_investigation | MINIMAL | coreutils | 9.7-3 | — | 4.4 | CVE-2025-5278 |
| CVE-2025-70873 | under_investigation | MINIMAL | sqlite3 | 3.46.1-7+deb13u1 | — | 7.5 | CVE-2025-70873 |
| CVE-2025-9403 | under_investigation | MINIMAL | jq | 1.7.1-6+deb13u3 | — | 5.5 | CVE-2025-9403 |
| CVE-2026-11850 | under_investigation | MINIMAL | krb5 | 1.21.3-5+deb13u1 | — | 5 | CVE-2026-11850 |
| CVE-2026-11979 | under_investigation | MINIMAL | libxml2 | 2.12.7+dfsg+really2.9.14-2.1+deb13u3 | — | 7.8 | CVE-2026-11979 |
| CVE-2026-13573 | under_investigation | MINIMAL | llvm-toolchain-19 | 1:19.1.7-3 | — | 1.9 | CVE-2026-13573 |
| CVE-2026-13574 | under_investigation | MINIMAL | llvm-toolchain-19 | 1:19.1.7-3 | — | 1.9 | CVE-2026-13574 |
| CVE-2026-3713 | under_investigation | MINIMAL | libpng1.6 | 1.6.48-1+deb13u5 | — | 1.9 | CVE-2026-3713 |
| CVE-2026-53910 | under_investigation | MINIMAL | diffutils | 1:3.10-4 | — | CVE-2026-53910 | |
| CVE-2026-56109 | under_investigation | MINIMAL | alsa-lib | 1.2.14-1 | — | 7 | CVE-2026-56109 |
| CVE-2026-56391 | under_investigation | MINIMAL | coreutils | 9.7-3 | — | CVE-2026-56391 | |
| CVE-2026-56392 | under_investigation | MINIMAL | coreutils | 9.7-3 | — | CVE-2026-56392 | |
| CVE-2026-66033 | under_investigation | MINIMAL | libssh2 | 1.11.1-1+deb13u1 | — | 8.7 | CVE-2026-66033 |
| CVE-2026-66035 | under_investigation | MINIMAL | libssh2 | 1.11.1-1+deb13u1 | — | 7.7 | CVE-2026-66035 |
| CVE-2026-9547 | under_investigation | MINIMAL | curl | 8.14.1-2+deb13u4 | — | 7.4 | CVE-2026-9547 |
| CVE-2026-75803 | under_investigation | UNKNOWN | openssl | 3.5.6-1~deb13u2 | — | CVE-2026-75803 |
Manually reviewed findings with OpenVEX status not_affected. Each row
carries the spec justification label and the evidence for why the vulnerable code does not affect
this image's functionality (and where that was verified). Excluded from the severity counts above;
present as full statements in the OpenVEX document.
| Vulnerability | Severity | Package | Installed | Justification | Evidence / where |
|---|---|---|---|---|---|
| CVE-2026-40393 | vulnerable_code_not_present | mesa: installed trixie 25.0.7-2+deb13u1 IS the fixed version — security-tracker.debian.org/tracker/CVE-2026-40393 lists 'trixie | 25.0.7-2+deb13u1 | fixed' (verified 2026-07-12); the scanner vulnerability DB lags the Debian tracker. Re-check on the next DB refresh and drop this entry once the row disappears on its own. |