jkg_python:1.1.1 — vulnerability report

6 critical · 28 high · 11 medium · 1 low · 47 total (deduped by CVE) · 14 reviewed not-affected

Image datagrok/jkg_python:1.1.1 · digest sha256:4e19c8793eafb7a1db78dc55d86cdba34aabcda5bee8ed3288a78ec5a407df07

Open findings

OpenVEX status affected (an upstream fix exists — the action is to apply it) or under_investigation (no upstream fix is available yet; a version match alone does not establish exploitability).

VulnerabilityStatusSeverityPackage InstalledFixed inCVSSDescription
CVE-2026-18924affectedCRITICALcurl8.21.0-r08.22.0-r09.1CVE-2026-18924
CVE-2026-19931affectedCRITICALcurl8.21.0-r08.22.0-r09.8CVE-2026-19931
CVE-2026-63073affectedCRITICALopenssl3.5.7-r03.5.8-r09.8CVE-2026-63073
CVE-2026-75803affectedCRITICALopenssl3.5.7-r03.5.8-r09.1CVE-2026-75803
CVE-2026-79657affectedCRITICALnltk3.10.23.10.39.3CVE-2026-79657
CVE-2026-79675affectedCRITICALnltk3.10.23.10.39.3CVE-2026-79675
CVE-2026-13608affectedHIGHcurl8.21.0-r08.22.0-r07.4CVE-2026-13608
CVE-2026-14456affectedHIGHopenssl3.5.7-r03.5.8-r07.5CVE-2026-14456
CVE-2026-14457affectedHIGHopenssl3.5.7-r03.5.8-r07.5CVE-2026-14457
CVE-2026-18798affectedHIGHopenssl3.5.7-r03.5.8-r07.5CVE-2026-18798
CVE-2026-54284affectedHIGHsqlparse0.5.50.68.7CVE-2026-54284
CVE-2026-54874affectedHIGHopenssl3.5.7-r03.5.8-r07.5CVE-2026-54874
CVE-2026-59893affectedHIGHsqlparse0.5.50.67.5CVE-2026-59893
CVE-2026-63072affectedHIGHopenssl3.5.7-r03.5.8-r07.5CVE-2026-63072
CVE-2026-63075affectedHIGHopenssl3.5.7-r03.5.8-r07.5CVE-2026-63075
CVE-2026-63076affectedHIGHopenssl3.5.7-r03.5.8-r07.5CVE-2026-63076
CVE-2026-69247affectedHIGHcryptography48.0.1508.2CVE-2026-69247
CVE-2026-69249affectedHIGHcryptography48.0.1498.7CVE-2026-69249
CVE-2026-71211under_investigationHIGHmlflow3.15.1—CVE-2026-71211
CVE-2026-71491affectedHIGHsqlparse0.5.50.68.7CVE-2026-71491
CVE-2026-71513affectedHIGHnltk3.10.23.10.38.7CVE-2026-71513
CVE-2026-78680affectedHIGHnltk3.10.23.10.38.5CVE-2026-78680
CVE-2026-78681affectedHIGHnltk3.10.23.10.38.7CVE-2026-78681
CVE-2026-78682affectedHIGHnltk3.10.23.10.38.7CVE-2026-78682
CVE-2026-79674affectedHIGHnltk3.10.23.10.38.8CVE-2026-79674
CVE-2026-79676affectedHIGHnltk3.10.23.10.38.2CVE-2026-79676
CVE-2026-80206affectedHIGHnltk3.10.23.10.38.2CVE-2026-80206
CVE-2026-80229affectedHIGHcurl8.21.0-r08.22.0-r07.5CVE-2026-80229
CVE-2026-80230affectedHIGHcurl8.21.0-r08.22.0-r07.5CVE-2026-80230
CVE-2026-80231affectedHIGHcurl8.21.0-r08.22.0-r07.5CVE-2026-80231
CVE-2026-80255affectedHIGHcurl8.21.0-r08.22.0-r07.5CVE-2026-80255
CVE-2026-81726under_investigationHIGHnltk3.10.2—8.3CVE-2026-81726
CVE-2026-82208affectedHIGHcurl8.21.0-r08.22.0-r07.5CVE-2026-82208
CVE-2026-82209affectedHIGHcurl8.21.0-r08.22.0-r08.2CVE-2026-82209
CVE-2026-12570affectedMEDIUMkeras2.153.15CVE-2026-12570
CVE-2026-12876affectedMEDIUMnltk3.10.23.10.3CVE-2026-12876
CVE-2026-59894affectedMEDIUMsqlparse0.5.50.66.2CVE-2026-59894
CVE-2026-63074affectedMEDIUMopenssl3.5.7-r03.5.8-r05.9CVE-2026-63074
CVE-2026-69248affectedMEDIUMcryptography48.0.1496.9CVE-2026-69248
CVE-2026-81722affectedMEDIUMnltk3.10.23.10.38.7CVE-2026-81722
CVE-2026-81723affectedMEDIUMnltk3.10.23.10.36.3CVE-2026-81723
CVE-2026-81724affectedMEDIUMnltk3.10.23.10.36.9CVE-2026-81724
CVE-2026-81725affectedMEDIUMnltk3.10.23.10.36.3CVE-2026-81725
CVE-2026-81727affectedMEDIUMnltk3.10.23.10.36.9CVE-2026-81727
CVE-2026-84305affectedMEDIUMsqlparse0.5.50.65.1CVE-2026-84305
CVE-2026-71514affectedLOWnltk3.10.23.10.33.3CVE-2026-71514
CVE-2026-80256affectedUNKNOWNcurl8.21.0-r08.22.0-r0CVE-2026-80256

Reviewed findings — not affected

Manually reviewed findings with OpenVEX status not_affected. Each row carries the spec justification label and the evidence for why the vulnerable code does not affect this image's functionality (and where that was verified). Excluded from the severity counts above; present as full statements in the OpenVEX document.

VulnerabilitySeverityPackageInstalled JustificationEvidence / where
CVE-2025-3000LOWtorch2.10vulnerable_code_cannot_be_controlled_by_adversarytorch: memory corruption in torch.jit.script (GHSA-rrmf-rvhw-rf47), patched in 2.13.0. The kernel is held at 2.10 because every conda-forge pytorch from 2.11 up declares 'setuptools <82', which cannot coexist with the setuptools>=83 floor that closes CVE-2026-59890 (MEDIUM 6.1) — the two are mutually exclusive on conda-forge, and this one is LOW (CVSS4 1.9) and local-only. Triggering it means running crafted code through torch.jit.script inside a kernel whose script author already executes arbitrary code in that process by design — same rationale as CVE-2024-55459. Drop this entry and raise the floor once pytorch lifts the setuptools cap. Verified 2026-08-25.
CVE-2024-55459MEDIUMkeras2.15vulnerable_code_cannot_be_controlled_by_adversarykeras 2.15 is the last Keras-2 release; every fix for this advisory is Keras-3-only, and the kernel keeps Keras 2 while efficientnet and tf.keras (Keras-2 API) user scripts depend on it. Exploitation requires the kernel to load an attacker-supplied model/config file — in this image the only actor able to do that is the script author, who already executes arbitrary code in the same kernel process by design (server-side scripting), so no privilege boundary is crossed.
CVE-2025-12058MEDIUMkeras2.15vulnerable_code_cannot_be_controlled_by_adversaryKeras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459.
CVE-2025-12060HIGHkeras2.15vulnerable_code_cannot_be_controlled_by_adversaryKeras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459.
CVE-2025-9906HIGHkeras2.15vulnerable_code_cannot_be_controlled_by_adversaryKeras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459.
CVE-2026-11816HIGHkeras2.15vulnerable_code_cannot_be_controlled_by_adversaryKeras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459.
CVE-2026-12479MEDIUMkeras2.15vulnerable_code_cannot_be_controlled_by_adversaryKeras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459.
CVE-2026-12480MEDIUMkeras2.15vulnerable_code_cannot_be_controlled_by_adversaryKeras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459.
CVE-2026-12481HIGHkeras2.15vulnerable_code_cannot_be_controlled_by_adversaryKeras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459.
CVE-2026-12482LOWkeras2.15vulnerable_code_cannot_be_controlled_by_adversaryKeras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459.
CVE-2026-12484HIGHkeras2.15vulnerable_code_cannot_be_controlled_by_adversaryKeras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459.
CVE-2026-1462HIGHkeras2.15vulnerable_code_cannot_be_controlled_by_adversaryKeras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459.
CVE-2026-9335MEDIUMkeras2.15vulnerable_code_cannot_be_controlled_by_adversaryKeras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459.
CVE-2026-0994HIGHprotobuf4.25.9vulnerable_code_cannot_be_controlled_by_adversarypython-protobuf is capped <5 by tensorflow 2.15 (kept for the Keras-2 API). The parse-time resource exhaustion can only be triggered by input the script author feeds their own kernel process, which they can already terminate directly; no other principal parses protobuf here.