elasticsearch

Patched
Databases & Caching from mirror.gcr.io/library/elasticsearch
Pull Reference
ghcr.io/verity-org/library/elasticsearch
docker pull ghcr.io/verity-org/library/elasticsearch
Copa-Patched Image

Patched in-place from the upstream image using Copa . OS-level vulnerabilities are fixed without rebuilding \u2014 same layers, same behavior, fewer CVEs.

Signed SLSA L3 SBOM Rekor
Verify this artifact
Cosign signature
cosign verify \
  --certificate-identity-regexp "https://github.com/verity-org/verity/.github/workflows/" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  ghcr.io/verity-org/library/elasticsearch:9.3.0
Build provenance
gh attestation verify \
  oci://ghcr.io/verity-org/library/elasticsearch:9.3.0 \
  --owner verity-org

Vulnerability Scan

Found 107 vulnerabilit ies in the original image. 3 fixed by Copa. 104 remaining after patching.

9HIGH48MEDIUM50LOW

Fix available — pending patch

These vulnerabilities have upstream fixes but could not be automatically patched.

IDPackageInstalledFixedSeverity
CVE-2026-33870io.netty:netty-codec-http4.1.130.Final4.1.132.Final, 4.2.10.Final HIGH
CVE-2026-33870io.netty:netty-codec-http4.1.130.Final4.1.132.Final, 4.2.10.Final HIGH
CVE-2026-33870io.netty:netty-codec-http4.1.130.Final4.1.132.Final, 4.2.10.Final HIGH
CVE-2026-33870io.netty:netty-codec-http4.1.130.Final4.1.132.Final, 4.2.10.Final HIGH
CVE-2026-33871io.netty:netty-codec-http24.1.130.Final4.1.132.Final, 4.2.11.Final HIGH
CVE-2026-33871io.netty:netty-codec-http24.1.130.Final4.1.132.Final, 4.2.11.Final HIGH
GHSA-72hv-8253-57qqcom.fasterxml.jackson.core:jackson-core2.15.02.18.6, 2.21.1, 3.1.0 MEDIUM
GHSA-72hv-8253-57qqcom.fasterxml.jackson.core:jackson-core2.15.02.18.6, 2.21.1, 3.1.0 MEDIUM
GHSA-72hv-8253-57qqcom.fasterxml.jackson.core:jackson-core2.15.02.18.6, 2.21.1, 3.1.0 MEDIUM
GHSA-72hv-8253-57qqcom.fasterxml.jackson.core:jackson-core2.15.02.18.6, 2.21.1, 3.1.0 MEDIUM
GHSA-72hv-8253-57qqcom.fasterxml.jackson.core:jackson-core2.15.02.18.6, 2.21.1, 3.1.0 MEDIUM
GHSA-72hv-8253-57qqcom.fasterxml.jackson.core:jackson-core2.15.02.18.6, 2.21.1, 3.1.0 MEDIUM
GHSA-72hv-8253-57qqcom.fasterxml.jackson.core:jackson-core2.15.02.18.6, 2.21.1, 3.1.0 MEDIUM
GHSA-72hv-8253-57qqcom.fasterxml.jackson.core:jackson-core2.15.02.18.6, 2.21.1, 3.1.0 MEDIUM
GHSA-72hv-8253-57qqcom.fasterxml.jackson.core:jackson-core2.15.02.18.6, 2.21.1, 3.1.0 MEDIUM
GHSA-72hv-8253-57qqcom.fasterxml.jackson.core:jackson-core2.15.02.18.6, 2.21.1, 3.1.0 MEDIUM
GHSA-72hv-8253-57qqcom.fasterxml.jackson.core:jackson-core2.17.22.18.6, 2.21.1, 3.1.0 MEDIUM
GHSA-72hv-8253-57qqcom.fasterxml.jackson.core:jackson-core2.17.22.18.6, 2.21.1, 3.1.0 MEDIUM
CVE-2025-22227io.projectreactor.netty:reactor-netty-http1.0.451.3.0-M5, 1.2.8 MEDIUM
CVE-2025-48924org.apache.commons:commons-lang33.93.18.0 MEDIUM
CVE-2025-48924org.apache.commons:commons-lang33.93.18.0 MEDIUM
CVE-2025-68161org.apache.logging.log4j:log4j-core2.19.02.25.3 MEDIUM
CVE-2025-68161org.apache.logging.log4j:log4j-core2.25.02.25.3 MEDIUM

Awaiting upstream fix

No fix is available yet for these vulnerabilities.

IDPackageInstalledFixedSeverity
CVE-2026-4424libarchive3.5.3-7.el9_7 HIGH
CVE-2026-27135libnghttp21.43.0-6.el9 HIGH
CVE-2025-5278coreutils-single8.32-39.el9 MEDIUM
CVE-2025-14017curl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-1965curl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-3783curl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-3784curl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-3805curl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2025-14087glib22.68.4-18.el9_7.1 MEDIUM
CVE-2025-14512glib22.68.4-18.el9_7.1 MEDIUM
CVE-2026-1484glib22.68.4-18.el9_7.1 MEDIUM
CVE-2026-1489glib22.68.4-18.el9_7.1 MEDIUM
CVE-2026-4437glibc2.34-231.el9_7.10 MEDIUM
CVE-2026-4437glibc-common2.34-231.el9_7.10 MEDIUM
CVE-2026-4437glibc-minimal-langpack2.34-231.el9_7.10 MEDIUM
CVE-2025-68972gnupg22.3.3-5.el9_7 MEDIUM
CVE-2023-30571libarchive3.5.3-7.el9_7 MEDIUM
CVE-2025-60753libarchive3.5.3-7.el9_7 MEDIUM
CVE-2026-4426libarchive3.5.3-7.el9_7 MEDIUM
CVE-2026-5121libarchive3.5.3-7.el9_7 MEDIUM
CVE-2025-14017libcurl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-1965libcurl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-3783libcurl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-3784libcurl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-3805libcurl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-0990libxml22.9.13-14.el9_7 MEDIUM
CVE-2026-1757libxml22.9.13-14.el9_7 MEDIUM
CVE-2026-22185openldap2.6.8-4.el9 MEDIUM
CVE-2026-2100p11-kit0.25.3-3.el9_5 MEDIUM
CVE-2026-2100p11-kit-trust0.25.3-3.el9_5 MEDIUM
CVE-2026-29111systemd-libs252-55.el9_7.7 MEDIUM
CVE-2026-4105systemd-libs252-55.el9_7.7 MEDIUM
CVE-2024-11053curl-minimal7.76.1-35.el9_7.3 LOW
CVE-2024-7264curl-minimal7.76.1-35.el9_7.3 LOW
CVE-2024-9681curl-minimal7.76.1-35.el9_7.3 LOW
CVE-2023-4156gawk5.1.0-6.el9 LOW
CVE-2023-32636glib22.68.4-18.el9_7.1 LOW
CVE-2025-3360glib22.68.4-18.el9_7.1 LOW
CVE-2025-7039glib22.68.4-18.el9_7.1 LOW
CVE-2026-0988glib22.68.4-18.el9_7.1 LOW
CVE-2026-1485glib22.68.4-18.el9_7.1 LOW
CVE-2026-4438glibc2.34-231.el9_7.10 LOW
CVE-2026-4438glibc-common2.34-231.el9_7.10 LOW
CVE-2026-4438glibc-minimal-langpack2.34-231.el9_7.10 LOW
CVE-2022-3219gnupg22.3.3-5.el9_7 LOW
CVE-2025-30258gnupg22.3.3-5.el9_7 LOW
CVE-2026-24883gnupg22.3.3-5.el9_7 LOW
CVE-2025-1632libarchive3.5.3-7.el9_7 LOW
CVE-2025-5915libarchive3.5.3-7.el9_7 LOW
CVE-2025-5916libarchive3.5.3-7.el9_7 LOW
CVE-2025-5917libarchive3.5.3-7.el9_7 LOW
CVE-2025-5918libarchive3.5.3-7.el9_7 LOW
CVE-2024-11053libcurl-minimal7.76.1-35.el9_7.3 LOW
CVE-2024-7264libcurl-minimal7.76.1-35.el9_7.3 LOW
CVE-2024-9681libcurl-minimal7.76.1-35.el9_7.3 LOW
CVE-2022-27943libgcc11.5.0-11.el9 LOW
CVE-2025-11961libpcap14:1.10.0-4.el9 LOW
CVE-2022-27943libstdc++11.5.0-11.el9 LOW
CVE-2025-13151libtasn14.16.0-9.el9 LOW
CVE-2023-45322libxml22.9.13-14.el9_7 LOW
CVE-2024-34459libxml22.9.13-14.el9_7 LOW
CVE-2025-27113libxml22.9.13-14.el9_7 LOW
CVE-2025-6170libxml22.9.13-14.el9_7 LOW
CVE-2026-0989libxml22.9.13-14.el9_7 LOW
CVE-2026-0992libxml22.9.13-14.el9_7 LOW
CVE-2023-50495ncurses-base6.2-12.20210508.el9 LOW
CVE-2023-50495ncurses-libs6.2-12.20210508.el9 LOW
CVE-2026-2673openssl-fips-provider3.0.7-8.el9 LOW
CVE-2026-2673openssl-fips-provider-so3.0.7-8.el9 LOW
CVE-2024-13176openssl-libs1:3.5.1-7.el9_7 LOW
CVE-2024-41996openssl-libs1:3.5.1-7.el9_7 LOW
CVE-2025-9232openssl-libs1:3.5.1-7.el9_7 LOW
CVE-2026-2673openssl-libs1:3.5.1-7.el9_7 LOW
CVE-2022-41409pcre210.40-6.el9 LOW
CVE-2022-41409pcre2-syntax10.40-6.el9 LOW
CVE-2024-0232sqlite-libs3.34.1-9.el9_7 LOW
CVE-2025-70873sqlite-libs3.34.1-9.el9_7 LOW
CVE-2021-4217unzip6.0-59.el9 LOW
CVE-2022-0529unzip6.0-59.el9 LOW
CVE-2022-0530unzip6.0-59.el9 LOW
CVE-2026-27171zlib1.2.11-40.el9 LOW
Source
Copa (in-place patch)
Platforms
linux/amd64, linux/arm64
Registry
ghcr.io/verity-org
Upstream
mirror.gcr.io/library/elasticsearch