jkg_r:1.1.1 — vulnerability report

4 critical · 14 high · 1 medium · 0 low · 20 total (deduped by CVE) · 3 reviewed not-affected

Image datagrok/jkg_r:1.1.1 · digest sha256:af3370504e92631b43deb2fcd21a4269da93558def0f07c66751c3a69b8ce394

Open findings

OpenVEX status affected (an upstream fix exists — the action is to apply it) or under_investigation (no upstream fix is available yet; a version match alone does not establish exploitability).

VulnerabilityStatusSeverityPackage InstalledFixed inCVSSDescription
CVE-2026-18924affectedCRITICALcurl8.21.0-r08.22.0-r09.1CVE-2026-18924
CVE-2026-19931affectedCRITICALcurl8.21.0-r08.22.0-r09.8CVE-2026-19931
CVE-2026-63073affectedCRITICALopenssl3.5.7-r03.5.8-r09.8CVE-2026-63073
CVE-2026-75803affectedCRITICALopenssl3.5.7-r03.5.8-r09.1CVE-2026-75803
CVE-2026-13608affectedHIGHcurl8.21.0-r08.22.0-r07.4CVE-2026-13608
CVE-2026-14456affectedHIGHopenssl3.5.7-r03.5.8-r07.5CVE-2026-14456
CVE-2026-14457affectedHIGHopenssl3.5.7-r03.5.8-r07.5CVE-2026-14457
CVE-2026-18798affectedHIGHopenssl3.5.7-r03.5.8-r07.5CVE-2026-18798
CVE-2026-54874affectedHIGHopenssl3.5.7-r03.5.8-r07.5CVE-2026-54874
CVE-2026-63072affectedHIGHopenssl3.5.7-r03.5.8-r07.5CVE-2026-63072
CVE-2026-63075affectedHIGHopenssl3.5.7-r03.5.8-r07.5CVE-2026-63075
CVE-2026-63076affectedHIGHopenssl3.5.7-r03.5.8-r07.5CVE-2026-63076
CVE-2026-80229affectedHIGHcurl8.21.0-r08.22.0-r07.5CVE-2026-80229
CVE-2026-80230affectedHIGHcurl8.21.0-r08.22.0-r07.5CVE-2026-80230
CVE-2026-80231affectedHIGHcurl8.21.0-r08.22.0-r07.5CVE-2026-80231
CVE-2026-80255affectedHIGHcurl8.21.0-r08.22.0-r07.5CVE-2026-80255
CVE-2026-82208affectedHIGHcurl8.21.0-r08.22.0-r07.5CVE-2026-82208
CVE-2026-82209affectedHIGHcurl8.21.0-r08.22.0-r08.2CVE-2026-82209
CVE-2026-63074affectedMEDIUMopenssl3.5.7-r03.5.8-r05.9CVE-2026-63074
CVE-2026-80256affectedUNKNOWNcurl8.21.0-r08.22.0-r0CVE-2026-80256

Reviewed findings — not affected

Manually reviewed findings with OpenVEX status not_affected. Each row carries the spec justification label and the evidence for why the vulnerable code does not affect this image's functionality (and where that was verified). Excluded from the severity counts above; present as full statements in the OpenVEX document.

VulnerabilitySeverityPackageInstalled JustificationEvidence / where
CVE-2018-10237MEDIUMcom.google.guava:guava19.0vulnerable_code_not_in_execute_pathguava 19.0 is vendored inside the r2pmml CRAN package's bundled Java converter jar (inst/java). The image ships no Java runtime, so the jar can never be loaded; r2pmml's Java conversion path is inert in this image.
CVE-2020-8908LOWcom.google.guava:guava19.0vulnerable_code_not_in_execute_pathguava 19.0 vendored in the r2pmml converter jar; no Java runtime in the image — same rationale as CVE-2018-10237.
CVE-2023-2976MEDIUMcom.google.guava:guava19.0vulnerable_code_not_in_execute_pathguava 19.0 vendored in the r2pmml converter jar; no Java runtime in the image — same rationale as CVE-2018-10237.