4 critical · 14 high · 1 medium · 0 low · 20 total (deduped by CVE) · 3 reviewed not-affected
Image datagrok/jkg_r:1.1.1 · digest sha256:af3370504e92631b43deb2fcd21a4269da93558def0f07c66751c3a69b8ce394
OpenVEX status affected (an upstream fix exists — the action is to
apply it) or under_investigation (no upstream fix is available yet; a version match
alone does not establish exploitability).
| Vulnerability | Status | Severity | Package | Installed | Fixed in | CVSS | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-18924 | affected | CRITICAL | curl | 8.21.0-r0 | 8.22.0-r0 | 9.1 | CVE-2026-18924 |
| CVE-2026-19931 | affected | CRITICAL | curl | 8.21.0-r0 | 8.22.0-r0 | 9.8 | CVE-2026-19931 |
| CVE-2026-63073 | affected | CRITICAL | openssl | 3.5.7-r0 | 3.5.8-r0 | 9.8 | CVE-2026-63073 |
| CVE-2026-75803 | affected | CRITICAL | openssl | 3.5.7-r0 | 3.5.8-r0 | 9.1 | CVE-2026-75803 |
| CVE-2026-13608 | affected | HIGH | curl | 8.21.0-r0 | 8.22.0-r0 | 7.4 | CVE-2026-13608 |
| CVE-2026-14456 | affected | HIGH | openssl | 3.5.7-r0 | 3.5.8-r0 | 7.5 | CVE-2026-14456 |
| CVE-2026-14457 | affected | HIGH | openssl | 3.5.7-r0 | 3.5.8-r0 | 7.5 | CVE-2026-14457 |
| CVE-2026-18798 | affected | HIGH | openssl | 3.5.7-r0 | 3.5.8-r0 | 7.5 | CVE-2026-18798 |
| CVE-2026-54874 | affected | HIGH | openssl | 3.5.7-r0 | 3.5.8-r0 | 7.5 | CVE-2026-54874 |
| CVE-2026-63072 | affected | HIGH | openssl | 3.5.7-r0 | 3.5.8-r0 | 7.5 | CVE-2026-63072 |
| CVE-2026-63075 | affected | HIGH | openssl | 3.5.7-r0 | 3.5.8-r0 | 7.5 | CVE-2026-63075 |
| CVE-2026-63076 | affected | HIGH | openssl | 3.5.7-r0 | 3.5.8-r0 | 7.5 | CVE-2026-63076 |
| CVE-2026-80229 | affected | HIGH | curl | 8.21.0-r0 | 8.22.0-r0 | 7.5 | CVE-2026-80229 |
| CVE-2026-80230 | affected | HIGH | curl | 8.21.0-r0 | 8.22.0-r0 | 7.5 | CVE-2026-80230 |
| CVE-2026-80231 | affected | HIGH | curl | 8.21.0-r0 | 8.22.0-r0 | 7.5 | CVE-2026-80231 |
| CVE-2026-80255 | affected | HIGH | curl | 8.21.0-r0 | 8.22.0-r0 | 7.5 | CVE-2026-80255 |
| CVE-2026-82208 | affected | HIGH | curl | 8.21.0-r0 | 8.22.0-r0 | 7.5 | CVE-2026-82208 |
| CVE-2026-82209 | affected | HIGH | curl | 8.21.0-r0 | 8.22.0-r0 | 8.2 | CVE-2026-82209 |
| CVE-2026-63074 | affected | MEDIUM | openssl | 3.5.7-r0 | 3.5.8-r0 | 5.9 | CVE-2026-63074 |
| CVE-2026-80256 | affected | UNKNOWN | curl | 8.21.0-r0 | 8.22.0-r0 | CVE-2026-80256 |
Manually reviewed findings with OpenVEX status not_affected. Each row
carries the spec justification label and the evidence for why the vulnerable code does not affect
this image's functionality (and where that was verified). Excluded from the severity counts above;
present as full statements in the OpenVEX document.
| Vulnerability | Severity | Package | Installed | Justification | Evidence / where |
|---|---|---|---|---|---|
| CVE-2018-10237 | MEDIUM | com.google.guava:guava | 19.0 | vulnerable_code_not_in_execute_path | guava 19.0 is vendored inside the r2pmml CRAN package's bundled Java converter jar (inst/java). The image ships no Java runtime, so the jar can never be loaded; r2pmml's Java conversion path is inert in this image. |
| CVE-2020-8908 | LOW | com.google.guava:guava | 19.0 | vulnerable_code_not_in_execute_path | guava 19.0 vendored in the r2pmml converter jar; no Java runtime in the image — same rationale as CVE-2018-10237. |
| CVE-2023-2976 | MEDIUM | com.google.guava:guava | 19.0 | vulnerable_code_not_in_execute_path | guava 19.0 vendored in the r2pmml converter jar; no Java runtime in the image — same rationale as CVE-2018-10237. |