home / Solr / solr:9.11.0-slim docker pull solr:9.11.0-slim click to select
Image metadata PULL COUNT
—
repository-level (not per-tag)
RUNS AS
non-root
image config.User
LAST PUSHED
3d ago
2026-10-07 00:58:53
MANIFEST DIGEST
sha256:c8a5ad7d951c…
from registry manifest
Latest scan 2026-10-09 22:41:42 UTC · today OPEN CVES BY SEVERITY
Grype DB 2026-10-09T06:32:32.000Z
· rubric cerodeo-v1
RUBRIC BREAKDOWN (8 signals that moved the score) -25 · Critical CVEs (fixable) -70 · High CVEs (fixable) -9 · Medium CVEs (fixable) +10 · Runs as non-root +10 · Rebuilt in last 90 days +3 · OCI standard labels (≥4) +3 · Multi-arch +2 · readme_has_example
Raw data
Every signal above decomposes to arithmetic from inputs you can verify. Nothing in these downloads is derived or
massaged — they're the raw grype matches and the raw snapshot history exactly as our scanner wrote them.
Reproduce this score yourself
We don't use judgement to score — every signal is deterministic from the image, the manifest, and a pinned CVE DB.
Run the script below on any host with skopeo, syft,
grype, cosign, and jq installed — it fetches the versioned rubric spec, computes the same breakdown, and prints the same grade. Pin the Grype DB with --grype-db to reproduce bit-for-bit identical results.
curl -fsSLO https://ce.rodeo/verify-score.sh && chmod +x verify-score.sh
./verify-score.sh solr:9.11.0-slim \
--rubric cerodeo-v1 \
--grype-db 2026-10-09T06:32:32.000Z
All open CVEs (139) sorted by severity, then CVSS score CVE ID SEV CVSS PACKAGE FIX
CVE-2026-84782 HIGH — libssl3 3.0.2-0ubuntu1.29 fixed in 3.0.2-0ubuntu1.30 CVE-2024-10041 MEDIUM — libpam-runtime 1.4.0-11ubuntu2.8 no fix available CVE-2024-10041 MEDIUM — libpam-modules-bin 1.4.0-11ubuntu2.8 no fix available CVE-2024-10041 MEDIUM — libpam-modules 1.4.0-11ubuntu2.8 no fix available CVE-2026-102010 MEDIUM — libstdc++6 12.3.0-1ubuntu1~22.04.3 no fix available CVE-2026-102010 MEDIUM — libgcc-s1 12.3.0-1ubuntu1~22.04.3 no fix available CVE-2026-102010 MEDIUM — gcc-12-base 12.3.0-1ubuntu1~22.04.3 no fix available CVE-2026-102473 MEDIUM — dash 0.5.11+git20210903+057cd650a4ed-3build1 no fix available CVE-2026-102474 MEDIUM — dash 0.5.11+git20210903+057cd650a4ed-3build1 no fix available CVE-2026-18477 MEDIUM — tar 1.34+dfsg-1ubuntu0.1.22.04.6 no fix available CVE-2026-18508 MEDIUM — tar 1.34+dfsg-1ubuntu0.1.22.04.6 no fix available CVE-2026-46675 MEDIUM — libpng16-16 1.6.37-3ubuntu0.6 no fix available CVE-2026-7017 MEDIUM — perl-base 5.34.0-3ubuntu1.9 no fix available CVE-2026-76642 MEDIUM — libsmartcols1 2.37.2-4ubuntu3.6 no fix available CVE-2026-78408 MEDIUM — libsmartcols1 2.37.2-4ubuntu3.6 no fix available CVE-2026-78409 MEDIUM — libsmartcols1 2.37.2-4ubuntu3.6 no fix available CVE-2026-78410 MEDIUM — libsmartcols1 2.37.2-4ubuntu3.6 no fix available CVE-2026-85091 MEDIUM — zlib1g 1:1.2.11.dfsg-2ubuntu9.2 no fix available CVE-2026-86145 MEDIUM — libpcre2-8-0 10.39-3ubuntu0.1 no fix available CVE-2026-8674 MEDIUM — libc-bin 2.35-0ubuntu3.15 no fix available CVE-2026-89156 MEDIUM — libpcre2-8-0 10.39-3ubuntu0.1 no fix available CVE-2026-89157 MEDIUM — libpcre2-8-0 10.39-3ubuntu0.1 no fix available CVE-2026-89158 MEDIUM — libpcre2-8-0 10.39-3ubuntu0.1 no fix available CVE-2026-89160 MEDIUM — libpcre2-8-0 10.39-3ubuntu0.1 no fix available CVE-2026-89161 MEDIUM — libpcre2-8-0 10.39-3ubuntu0.1 no fix available CVE-2026-89162 MEDIUM — libpcre2-8-0 10.39-3ubuntu0.1 no fix available CVE-2026-9538 MEDIUM — perl-base 5.34.0-3ubuntu1.9 no fix available CVE-2026-95512 MEDIUM — libfreetype6 2.11.1+dfsg-1ubuntu0.3 fixed in 2.11.1+dfsg-1ubuntu0.4 CVE-2026-95619 MEDIUM — libgcc-s1 12.3.0-1ubuntu1~22.04.3 no fix available CVE-2026-95619 MEDIUM — gcc-12-base 12.3.0-1ubuntu1~22.04.3 no fix available CVE-2026-95619 MEDIUM — libstdc++6 12.3.0-1ubuntu1~22.04.3 no fix available CVE-2022-27943 LOW — gcc-12-base 12.3.0-1ubuntu1~22.04.3 no fix available CVE-2022-27943 LOW — libgcc-s1 12.3.0-1ubuntu1~22.04.3 no fix available CVE-2022-27943 LOW — libstdc++6 12.3.0-1ubuntu1~22.04.3 no fix available CVE-2026-35189 LOW — libssl3 3.0.2-0ubuntu1.29 fixed in 3.0.2-0ubuntu1.30 CVE-2026-54872 LOW — libssl3 3.0.2-0ubuntu1.29 fixed in 3.0.2-0ubuntu1.30 CVE-2026-75805 LOW — libssl3 3.0.2-0ubuntu1.29 fixed in 3.0.2-0ubuntu1.30 CVE-2026-75806 LOW — libssl3 3.0.2-0ubuntu1.29 fixed in 3.0.2-0ubuntu1.30 CVE-2026-77696 LOW — libssl3 3.0.2-0ubuntu1.29 fixed in 3.0.2-0ubuntu1.30 CVE-2016-20013 NEGLIGIBLE — libc-bin 2.35-0ubuntu3.15 no fix available CVE-2017-11164 NEGLIGIBLE — libpcre3 2:8.39-13ubuntu0.22.04.1 no fix available CVE-2018-5709 NEGLIGIBLE — libk5crypto3 1.19.2-2ubuntu0.10 no fix available CVE-2018-5709 NEGLIGIBLE — libkrb5-3 1.19.2-2ubuntu0.10 no fix available CVE-2018-5709 NEGLIGIBLE — libkrb5support0 1.19.2-2ubuntu0.10 no fix available CVE-2018-5709 NEGLIGIBLE — libgssapi-krb5-2 1.19.2-2ubuntu0.10 no fix available CVE-2023-47039 NEGLIGIBLE — perl-base 5.34.0-3ubuntu1.9 no fix available
Scan history 1 total · first today SCANNED AT GRADE SCORE CRIT HIGH MED GRYPE DB
today F 24 1 7 95 2026-10-09T06:32:32.000Z
Methodology:
This image is re-matched against the fresh Grype vulnerability DB every hour. Snapshot rows marked
(same SBOM) reuse the prior scan's content via a pointer — about
90% of hourly cycles do. New CVE disclosures land in a new content row and bump the grade on the next match.
Full rubric at /about/grades ; for publishers wanting to
raise their grade, see /about/for-publishers .