elasticsearch

Patched
Databases & Caching from mirror.gcr.io/library/elasticsearch
Pull Reference
ghcr.io/verity-org/library/elasticsearch
docker pull ghcr.io/verity-org/library/elasticsearch
Available Versions
9.4.1 latest 2 CVEs fixed 161 remaining
9.4.0 4 CVEs fixed 217 remaining
9.3.4 2 CVEs fixed 195 remaining
Copa-Patched Image

Patched in-place from the upstream image using Copa . OS-level vulnerabilities are fixed without rebuilding \u2014 same layers, same behavior, fewer CVEs.

Signed SLSA L3 SBOM Rekor
Verify this artifact
Cosign signature
cosign verify \
  --certificate-identity-regexp "https://github.com/verity-org/verity/.github/workflows/" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  ghcr.io/verity-org/library/elasticsearch:9.4.1
Build provenance
gh attestation verify \
  oci://ghcr.io/verity-org/library/elasticsearch:9.4.1 \
  --owner verity-org

Vulnerability Scan

Found 163 vulnerabilit ies in the original image. 2 fixed by Copa. 161 remaining after patching.

5HIGH98MEDIUM60LOW

Fix available — pending patch

These vulnerabilities have upstream fixes but could not be automatically patched.

IDPackageInstalledFixedSeverity
GHSA-72hv-8253-57qqcom.fasterxml.jackson.core:jackson-core2.15.02.21.1, 2.18.6 MEDIUM
GHSA-72hv-8253-57qqcom.fasterxml.jackson.core:jackson-core2.15.02.21.1, 2.18.6 MEDIUM
GHSA-72hv-8253-57qqcom.fasterxml.jackson.core:jackson-core2.15.02.21.1, 2.18.6 MEDIUM
GHSA-72hv-8253-57qqcom.fasterxml.jackson.core:jackson-core2.15.02.21.1, 2.18.6 MEDIUM
GHSA-72hv-8253-57qqcom.fasterxml.jackson.core:jackson-core2.15.02.21.1, 2.18.6 MEDIUM
GHSA-72hv-8253-57qqcom.fasterxml.jackson.core:jackson-core2.15.02.21.1, 2.18.6 MEDIUM
GHSA-72hv-8253-57qqcom.fasterxml.jackson.core:jackson-core2.15.02.21.1, 2.18.6 MEDIUM
GHSA-72hv-8253-57qqcom.fasterxml.jackson.core:jackson-core2.15.02.21.1, 2.18.6 MEDIUM
GHSA-72hv-8253-57qqcom.fasterxml.jackson.core:jackson-core2.15.02.21.1, 2.18.6 MEDIUM
GHSA-72hv-8253-57qqcom.fasterxml.jackson.core:jackson-core2.15.02.21.1, 2.18.6 MEDIUM
GHSA-72hv-8253-57qqcom.fasterxml.jackson.core:jackson-core2.17.22.21.1, 2.18.6 MEDIUM
GHSA-72hv-8253-57qqcom.fasterxml.jackson.core:jackson-core2.17.22.21.1, 2.18.6 MEDIUM
GHSA-72hv-8253-57qqcom.fasterxml.jackson.core:jackson-core2.19.22.21.1, 2.18.6 MEDIUM
GHSA-72hv-8253-57qqcom.fasterxml.jackson.core:jackson-core2.19.22.21.1, 2.18.6 MEDIUM
CVE-2026-45292io.opentelemetry:opentelemetry-api1.47.01.62.0 MEDIUM
CVE-2026-45292io.opentelemetry:opentelemetry-api1.47.01.62.0 MEDIUM
CVE-2026-45292io.opentelemetry:opentelemetry-api1.60.11.62.0 MEDIUM
CVE-2025-22227io.projectreactor.netty:reactor-netty-http1.0.451.3.0-M5, 1.2.8 MEDIUM
CVE-2025-22227io.projectreactor.netty:reactor-netty-http1.0.451.3.0-M5, 1.2.8 MEDIUM
CVE-2025-22227io.projectreactor.netty:reactor-netty-http1.0.451.3.0-M5, 1.2.8 MEDIUM
CVE-2025-48924org.apache.commons:commons-lang33.14.03.18.0 MEDIUM
CVE-2025-48924org.apache.commons:commons-lang33.93.18.0 MEDIUM
CVE-2025-48924org.apache.commons:commons-lang33.93.18.0 MEDIUM
CVE-2026-34479org.apache.logging.log4j:log4j-1.2-api2.19.02.25.4 MEDIUM
CVE-2026-34479org.apache.logging.log4j:log4j-1.2-api2.19.02.25.4 MEDIUM
CVE-2026-34479org.apache.logging.log4j:log4j-1.2-api2.19.02.25.4 MEDIUM
CVE-2025-68161org.apache.logging.log4j:log4j-core2.19.02.25.3 MEDIUM
CVE-2026-34477org.apache.logging.log4j:log4j-core2.19.02.25.4 MEDIUM
CVE-2026-34480org.apache.logging.log4j:log4j-core2.19.02.25.4 MEDIUM

Awaiting upstream fix

No fix is available yet for these vulnerabilities.

IDPackageInstalledFixedSeverity
CVE-2026-33845gnutls3.8.3-10.el9_7 HIGH
CVE-2026-33846gnutls3.8.3-10.el9_7 HIGH
CVE-2026-42009gnutls3.8.3-10.el9_7 HIGH
CVE-2026-42010gnutls3.8.3-10.el9_7 HIGH
CVE-2026-40356krb5-libs1.21.1-9.el9_7 HIGH
CVE-2025-5278coreutils-single8.32-39.el9 MEDIUM
CVE-2025-13034curl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2025-14017curl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-1965curl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-3783curl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-3784curl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-3805curl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-4873curl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-5545curl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-5773curl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-6253curl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-6429curl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-1484glib22.68.4-18.el9_7.2 MEDIUM
CVE-2026-1489glib22.68.4-18.el9_7.2 MEDIUM
CVE-2026-4046glibc2.34-231.el9_7.10 MEDIUM
CVE-2026-4437glibc2.34-231.el9_7.10 MEDIUM
CVE-2026-5435glibc2.34-231.el9_7.10 MEDIUM
CVE-2026-5450glibc2.34-231.el9_7.10 MEDIUM
CVE-2026-5928glibc2.34-231.el9_7.10 MEDIUM
CVE-2026-4046glibc-common2.34-231.el9_7.10 MEDIUM
CVE-2026-4437glibc-common2.34-231.el9_7.10 MEDIUM
CVE-2026-5435glibc-common2.34-231.el9_7.10 MEDIUM
CVE-2026-5450glibc-common2.34-231.el9_7.10 MEDIUM
CVE-2026-5928glibc-common2.34-231.el9_7.10 MEDIUM
CVE-2026-4046glibc-minimal-langpack2.34-231.el9_7.10 MEDIUM
CVE-2026-4437glibc-minimal-langpack2.34-231.el9_7.10 MEDIUM
CVE-2026-5435glibc-minimal-langpack2.34-231.el9_7.10 MEDIUM
CVE-2026-5450glibc-minimal-langpack2.34-231.el9_7.10 MEDIUM
CVE-2026-5928glibc-minimal-langpack2.34-231.el9_7.10 MEDIUM
CVE-2025-68972gnupg22.3.3-5.el9_7 MEDIUM
CVE-2026-3833gnutls3.8.3-10.el9_7 MEDIUM
CVE-2026-42011gnutls3.8.3-10.el9_7 MEDIUM
CVE-2026-40355krb5-libs1.21.1-9.el9_7 MEDIUM
CVE-2023-30571libarchive3.5.3-9.el9_7 MEDIUM
CVE-2025-60753libarchive3.5.3-9.el9_7 MEDIUM
CVE-2026-4426libarchive3.5.3-9.el9_7 MEDIUM
CVE-2026-5745libarchive3.5.3-9.el9_7 MEDIUM
CVE-2026-27456libblkid2.37.4-21.el9_7 MEDIUM
CVE-2025-13034libcurl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2025-14017libcurl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-1965libcurl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-3783libcurl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-3784libcurl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-3805libcurl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-4873libcurl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-5545libcurl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-5773libcurl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-6253libcurl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-6429libcurl-minimal7.76.1-35.el9_7.3 MEDIUM
CVE-2026-41989libgcrypt1.10.0-11.el9 MEDIUM
CVE-2026-27456libmount2.37.4-21.el9_7 MEDIUM
CVE-2026-27456libsmartcols2.37.4-21.el9_7 MEDIUM
CVE-2026-27456libuuid2.37.4-21.el9_7 MEDIUM
CVE-2026-0990libxml22.9.13-14.el9_7 MEDIUM
CVE-2026-1757libxml22.9.13-14.el9_7 MEDIUM
CVE-2026-6732libxml22.9.13-14.el9_7 MEDIUM
CVE-2026-22185openldap2.6.8-4.el9 MEDIUM
CVE-2026-2673openssl-fips-provider3.0.7-8.el9 MEDIUM
CVE-2026-31790openssl-fips-provider3.0.7-8.el9 MEDIUM
CVE-2026-2673openssl-fips-provider-so3.0.7-8.el9 MEDIUM
CVE-2026-31790openssl-fips-provider-so3.0.7-8.el9 MEDIUM
CVE-2026-2673openssl-libs1:3.5.1-7.el9_7 MEDIUM
CVE-2026-28386openssl-libs1:3.5.1-7.el9_7 MEDIUM
CVE-2026-28390openssl-libs1:3.5.1-7.el9_7 MEDIUM
CVE-2026-31790openssl-libs1:3.5.1-7.el9_7 MEDIUM
CVE-2026-4105systemd-libs252-55.el9_7.9 MEDIUM
CVE-2026-34743xz-libs5.2.5-8.el9_0 MEDIUM
CVE-2024-11053curl-minimal7.76.1-35.el9_7.3 LOW
CVE-2024-7264curl-minimal7.76.1-35.el9_7.3 LOW
CVE-2024-9681curl-minimal7.76.1-35.el9_7.3 LOW
CVE-2025-14524curl-minimal7.76.1-35.el9_7.3 LOW
CVE-2025-15079curl-minimal7.76.1-35.el9_7.3 LOW
CVE-2025-15224curl-minimal7.76.1-35.el9_7.3 LOW
CVE-2026-6276curl-minimal7.76.1-35.el9_7.3 LOW
CVE-2023-4156gawk5.1.0-6.el9 LOW
CVE-2023-32636glib22.68.4-18.el9_7.2 LOW
CVE-2025-3360glib22.68.4-18.el9_7.2 LOW
CVE-2025-7039glib22.68.4-18.el9_7.2 LOW
CVE-2026-0988glib22.68.4-18.el9_7.2 LOW
CVE-2026-1485glib22.68.4-18.el9_7.2 LOW
CVE-2026-4438glibc2.34-231.el9_7.10 LOW
CVE-2026-4438glibc-common2.34-231.el9_7.10 LOW
CVE-2026-4438glibc-minimal-langpack2.34-231.el9_7.10 LOW
CVE-2022-3219gnupg22.3.3-5.el9_7 LOW
CVE-2025-30258gnupg22.3.3-5.el9_7 LOW
CVE-2026-24883gnupg22.3.3-5.el9_7 LOW
CVE-2026-3832gnutls3.8.3-10.el9_7 LOW
CVE-2025-1632libarchive3.5.3-9.el9_7 LOW
CVE-2025-5915libarchive3.5.3-9.el9_7 LOW
CVE-2025-5916libarchive3.5.3-9.el9_7 LOW
CVE-2025-5917libarchive3.5.3-9.el9_7 LOW
CVE-2025-5918libarchive3.5.3-9.el9_7 LOW
CVE-2024-11053libcurl-minimal7.76.1-35.el9_7.3 LOW
CVE-2024-7264libcurl-minimal7.76.1-35.el9_7.3 LOW
CVE-2024-9681libcurl-minimal7.76.1-35.el9_7.3 LOW
CVE-2025-14524libcurl-minimal7.76.1-35.el9_7.3 LOW
CVE-2025-15079libcurl-minimal7.76.1-35.el9_7.3 LOW
CVE-2025-15224libcurl-minimal7.76.1-35.el9_7.3 LOW
CVE-2026-6276libcurl-minimal7.76.1-35.el9_7.3 LOW
CVE-2022-27943libgcc11.5.0-11.el9 LOW
CVE-2026-41990libgcrypt1.10.0-11.el9 LOW
CVE-2025-11961libpcap14:1.10.0-4.el9 LOW
CVE-2022-27943libstdc++11.5.0-11.el9 LOW
CVE-2025-13151libtasn14.16.0-9.el9 LOW
CVE-2023-45322libxml22.9.13-14.el9_7 LOW
CVE-2024-34459libxml22.9.13-14.el9_7 LOW
CVE-2025-27113libxml22.9.13-14.el9_7 LOW
CVE-2025-6170libxml22.9.13-14.el9_7 LOW
CVE-2026-0989libxml22.9.13-14.el9_7 LOW
CVE-2026-0992libxml22.9.13-14.el9_7 LOW
CVE-2023-50495ncurses-base6.2-12.20210508.el9 LOW
CVE-2023-50495ncurses-libs6.2-12.20210508.el9 LOW
CVE-2024-13176openssl-libs1:3.5.1-7.el9_7 LOW
CVE-2024-41996openssl-libs1:3.5.1-7.el9_7 LOW
CVE-2025-9232openssl-libs1:3.5.1-7.el9_7 LOW
CVE-2026-28387openssl-libs1:3.5.1-7.el9_7 LOW
CVE-2026-28388openssl-libs1:3.5.1-7.el9_7 LOW
CVE-2026-28389openssl-libs1:3.5.1-7.el9_7 LOW
CVE-2026-31789openssl-libs1:3.5.1-7.el9_7 LOW
CVE-2022-41409pcre210.40-6.el9 LOW
CVE-2022-41409pcre2-syntax10.40-6.el9 LOW
CVE-2024-0232sqlite-libs3.34.1-9.el9_7 LOW
CVE-2025-70873sqlite-libs3.34.1-9.el9_7 LOW
CVE-2021-4217unzip6.0-59.el9 LOW
CVE-2022-0529unzip6.0-59.el9 LOW
CVE-2022-0530unzip6.0-59.el9 LOW
CVE-2026-27171zlib1.2.11-40.el9 LOW
Source
Copa (in-place patch)
Platforms
linux/amd64, linux/arm64
Registry
ghcr.io/verity-org
Upstream
mirror.gcr.io/library/elasticsearch
Version
9.4.1