docker.io/trinodb/trino:482
Base OS: redhat 10.2clean
Patched Image
ghcr.io/verity-org/trinodb/trino:482
Supply Chain
Full compliance detailsSignedSLSA L3SBOMRekor
Verify this artifact
Cosign signature
cosign verify \ --certificate-identity-regexp "https://github.com/verity-org/verity/.github/workflows/" \ --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \ ghcr.io/verity-org/trinodb/trino:482
Build provenance
gh attestation verify \ oci://ghcr.io/verity-org/trinodb/trino:482 \ --owner verity-org
Before patching
Found 14 vulnerabilities — none have upstream fixes available.
3 HIGH9 MEDIUM2 LOW
Fix available — pending patch
These vulnerabilities have upstream fixes but could not be automatically patched. Manual remediation may be required.
- CVE-2025-48977HIGH
- Package
- org.apache.ignite:ignite-core
- Installed
- 2.17.0
- Fixed
- 2.18.0
- CVE-2026-2332HIGH
- Package
- org.eclipse.jetty:jetty-http
- Installed
- 11.0.26
- Fixed
- 12.1.7, 12.0.33
- CVE-2026-39822HIGH
- Package
- stdlib
- Installed
- v1.26.4
- Fixed
- 1.25.12, 1.26.5, 1.27.0-rc.2
- CVE-2026-54515MEDIUM
- Package
- com.fasterxml.jackson.core:jackson-databind
- Installed
- 2.22.0
- Fixed
- 3.1.4, 2.18.9, 2.21.5, 2.22.1
- CVE-2026-54515MEDIUM
- Package
- com.fasterxml.jackson.core:jackson-databind
- Installed
- 2.22.0
- Fixed
- 3.1.4, 2.18.9, 2.21.5, 2.22.1
- CVE-2026-46718MEDIUM
- Package
- org.apache.calcite:calcite-core
- Installed
- 1.40.0
- Fixed
- 1.42.0
- CVE-2024-6763MEDIUM
- Package
- org.eclipse.jetty:jetty-http
- Installed
- 11.0.26
- Fixed
- 12.0.12
- CVE-2024-52980MEDIUM
- Package
- org.elasticsearch:elasticsearch
- Installed
- 7.17.29
- Fixed
- 8.15.1
- CVE-2025-37727MEDIUM
- Package
- org.elasticsearch:elasticsearch
- Installed
- 7.17.29
- Fixed
- 8.18.8, 8.19.5, 9.0.8, 9.1.5
- CVE-2025-37731MEDIUM
- Package
- org.elasticsearch:elasticsearch
- Installed
- 7.17.29
- Fixed
- 8.19.8, 9.1.8, 9.2.2
- CVE-2026-42505MEDIUM
- Package
- stdlib
- Installed
- v1.26.4
- Fixed
- 1.25.12, 1.26.5, 1.27.0-rc.2
- CVE-2026-10532LOW
- Package
- ch.qos.logback:logback-core
- Installed
- 1.5.34
- Fixed
- 1.5.35
- CVE-2025-11143LOW
- Package
- org.eclipse.jetty:jetty-http
- Installed
- 11.0.26
- Fixed
- 12.0.31, 12.1.5
| ID | Package | Installed | Fixed | Severity |
|---|---|---|---|---|
| CVE-2025-48977 | org.apache.ignite:ignite-core | 2.17.0 | 2.18.0 | HIGH |
| CVE-2026-2332 | org.eclipse.jetty:jetty-http | 11.0.26 | 12.1.7, 12.0.33 | HIGH |
| CVE-2026-39822 | stdlib | v1.26.4 | 1.25.12, 1.26.5, 1.27.0-rc.2 | HIGH |
| CVE-2026-54515 | com.fasterxml.jackson.core:jackson-databind | 2.22.0 | 3.1.4, 2.18.9, 2.21.5, 2.22.1 | MEDIUM |
| CVE-2026-54515 | com.fasterxml.jackson.core:jackson-databind | 2.22.0 | 3.1.4, 2.18.9, 2.21.5, 2.22.1 | MEDIUM |
| CVE-2026-46718 | org.apache.calcite:calcite-core | 1.40.0 | 1.42.0 | MEDIUM |
| CVE-2024-6763 | org.eclipse.jetty:jetty-http | 11.0.26 | 12.0.12 | MEDIUM |
| CVE-2024-52980 | org.elasticsearch:elasticsearch | 7.17.29 | 8.15.1 | MEDIUM |
| CVE-2025-37727 | org.elasticsearch:elasticsearch | 7.17.29 | 8.18.8, 8.19.5, 9.0.8, 9.1.5 | MEDIUM |
| CVE-2025-37731 | org.elasticsearch:elasticsearch | 7.17.29 | 8.19.8, 9.1.8, 9.2.2 | MEDIUM |
| CVE-2026-42505 | stdlib | v1.26.4 | 1.25.12, 1.26.5, 1.27.0-rc.2 | MEDIUM |
| CVE-2026-10532 | ch.qos.logback:logback-core | 1.5.34 | 1.5.35 | LOW |
| CVE-2025-11143 | org.eclipse.jetty:jetty-http | 11.0.26 | 12.0.31, 12.1.5 | LOW |
Awaiting upstream fix
No fix is available yet for these vulnerabilities. They can be suppressed in your compliance tooling until an upstream fix is released.
- CVE-2025-48924MEDIUM
- Package
- commons-lang:commons-lang
- Installed
- 2.6
- Fixed
| ID | Package | Installed | Fixed | Severity |
|---|---|---|---|---|
| CVE-2025-48924 | commons-lang:commons-lang | 2.6 | MEDIUM |
Original image reference
docker.io/trinodb/trino:482