sonatype/nexus3:3.96.4-alpine

by sonatype ← project: Nexus
SCOUT
F
score 0
Pull →
docker pull sonatype/nexus3:3.96.4-alpine click to select

Image metadata

PULL COUNT
202.9M
repository-level (not per-tag)
SIZE (COMPRESSED)
484 MB
ARCHITECTURES
2
RUNS AS
non-root
image config.User
LAST PUSHED
10d ago
2026-09-30 06:21:47
MANIFEST DIGEST
sha256:5f48f9085096…
from registry manifest

Latest scan

2026-10-09 23:48:28 UTC · today

OPEN CVES BY SEVERITY

0
CRITICAL
24
HIGH
29
MEDIUM
13
LOW/NEG
Grype DB 2026-10-09T06:32:32.000Z · rubric cerodeo-v1

RUBRIC BREAKDOWN (7 signals that moved the score)

-110 · High CVEs (fixable) -9 · Medium CVEs (fixable) -39 · High CVEs (no fix) +10 · Runs as non-root +10 · Rebuilt in last 90 days +2 · Multi-arch +2 · readme_has_example

Raw data

Every signal above decomposes to arithmetic from inputs you can verify. Nothing in these downloads is derived or massaged — they're the raw grype matches and the raw snapshot history exactly as our scanner wrote them.

Latest scan JSON (CVE matches) Full scan history JSON (1 snapshots)

Reproduce this score yourself

We don't use judgement to score — every signal is deterministic from the image, the manifest, and a pinned CVE DB. Run the script below on any host with skopeo, syft, grype, cosign, and jq installed — it fetches the versioned rubric spec, computes the same breakdown, and prints the same grade. Pin the Grype DB with --grype-db to reproduce bit-for-bit identical results.

curl -fsSLO https://ce.rodeo/verify-score.sh && chmod +x verify-score.sh ./verify-score.sh sonatype/nexus3:3.96.4-alpine \ --rubric cerodeo-v1 \ --grype-db 2026-10-09T06:32:32.000Z
verify-score.sh rubric spec (cerodeo-v1.json)

All open CVEs (66)

sorted by severity, then CVSS score
CVE ID SEV CVSS PACKAGE FIX
CVE-2026-85091 HIGH 8.3 zlib 1.3.2-r0 fixed in 1.3.2-r1
CVE-2026-84782 HIGH 8.2 libcrypto3 3.5.8-r0 no fix available
CVE-2026-84782 HIGH 8.2 openssl 3.5.8-r0 no fix available
CVE-2026-84782 HIGH 8.2 libssl3 3.5.8-r0 no fix available
CVE-2026-54873 HIGH 7.5 openssl 3.5.8-r0 no fix available
CVE-2026-54873 HIGH 7.5 libcrypto3 3.5.8-r0 no fix available
CVE-2026-54873 HIGH 7.5 libssl3 3.5.8-r0 no fix available
CVE-2026-72897 HIGH 7.5 libssl3 3.5.8-r0 no fix available
CVE-2026-72897 HIGH 7.5 openssl 3.5.8-r0 no fix available
CVE-2026-72897 HIGH 7.5 libcrypto3 3.5.8-r0 no fix available
CVE-2026-84784 HIGH 7.5 openssl 3.5.8-r0 no fix available
CVE-2026-84784 HIGH 7.5 libcrypto3 3.5.8-r0 no fix available
CVE-2026-84784 HIGH 7.5 libssl3 3.5.8-r0 no fix available
GHSA-65r4-943x-97jj HIGH 7.5 jsoup 1.23.1 fixed in 1.23.2
GHSA-7hhh-6rmp-j9qf HIGH 7.5 jackson-core 2.22.2 fixed in 2.22.3
GHSA-7hhh-6rmp-j9qf HIGH 7.5 jackson-core 3.2.1 fixed in 3.2.3
GHSA-cxp5-3px4-pw24 HIGH 7.5 jackson-databind 2.22.2 fixed in 2.22.3
GHSA-cxp5-3px4-pw24 HIGH 7.5 jackson-databind 3.2.1 fixed in 3.2.3
GHSA-p6pp-m3f8-5c89 HIGH 7.5 jackson-core 2.22.2 fixed in 2.22.3
GHSA-p6pp-m3f8-5c89 HIGH 7.5 jackson-core 3.2.1 fixed in 3.2.2
GHSA-q4xh-88c3-wmh7 HIGH 7.5 jackson-databind 3.2.1 fixed in 3.2.2
GHSA-wv8q-qhhj-9h54 HIGH 7.5 jackson-databind 2.22.2 fixed in 2.22.3
GHSA-wv8q-qhhj-9h54 HIGH 7.5 jackson-databind 3.2.1 fixed in 3.2.3
CVE-2026-56109 HIGH 7.0 alsa-lib 1.2.15.3-r0 no fix available
CVE-2026-61308 MEDIUM 6.8 openjdk21 21.0.12_p8-r0 no fix available
CVE-2025-60876 MEDIUM 6.5 ssl_client 1.37.0-r31 no fix available
CVE-2025-60876 MEDIUM 6.5 busybox 1.37.0-r31 no fix available
CVE-2025-60876 MEDIUM 6.5 busybox-binsh 1.37.0-r31 no fix available
CVE-2026-58055 MEDIUM 6.3 nghttp2-libs 1.69.0-r0 fixed in 1.70.0-r0
GHSA-gx83-3vf8-gh7j MEDIUM 5.6 jackson-databind 3.2.1 fixed in 3.2.2
CVE-2026-5704 MEDIUM 5.5 tar 1.35-r5 no fix available
CVE-2026-35189 MEDIUM 5.3 libssl3 3.5.8-r0 no fix available
CVE-2026-35189 MEDIUM 5.3 libcrypto3 3.5.8-r0 no fix available
CVE-2026-35189 MEDIUM 5.3 openssl 3.5.8-r0 no fix available
CVE-2026-42772 MEDIUM 5.3 libssl3 3.5.8-r0 no fix available
CVE-2026-42772 MEDIUM 5.3 libcrypto3 3.5.8-r0 no fix available
CVE-2026-42772 MEDIUM 5.3 openssl 3.5.8-r0 no fix available
CVE-2026-70907 MEDIUM 5.3 openjdk21 21.0.12_p8-r0 no fix available
CVE-2026-75804 MEDIUM 5.3 openssl 3.5.8-r0 no fix available
CVE-2026-75804 MEDIUM 5.3 libssl3 3.5.8-r0 no fix available
CVE-2026-75804 MEDIUM 5.3 libcrypto3 3.5.8-r0 no fix available
CVE-2026-75805 MEDIUM 5.3 openssl 3.5.8-r0 no fix available
CVE-2026-75805 MEDIUM 5.3 libcrypto3 3.5.8-r0 no fix available
CVE-2026-75805 MEDIUM 5.3 libssl3 3.5.8-r0 no fix available
CVE-2026-75806 MEDIUM 5.3 openssl 3.5.8-r0 no fix available
CVE-2026-75806 MEDIUM 5.3 libcrypto3 3.5.8-r0 no fix available
CVE-2026-75806 MEDIUM 5.3 libssl3 3.5.8-r0 no fix available
GHSA-wjgm-6hv5-3cvf MEDIUM 5.3 jackson-databind 3.2.1 fixed in 3.2.2
CVE-2026-90781 MEDIUM 4.8 alsa-lib 1.2.15.3-r0 no fix available
CVE-2026-96674 MEDIUM 4.8 alsa-lib 1.2.15.3-r0 no fix available
CVE-2026-96675 MEDIUM 4.8 alsa-lib 1.2.15.3-r0 no fix available
CVE-2026-18477 MEDIUM 4.4 tar 1.35-r5 no fix available
CVE-2026-18508 MEDIUM 4.4 tar 1.35-r5 no fix available
CVE-2026-35191 LOW 3.7 openssl 3.5.8-r0 no fix available
CVE-2026-35191 LOW 3.7 libcrypto3 3.5.8-r0 no fix available
CVE-2026-35191 LOW 3.7 libssl3 3.5.8-r0 no fix available
CVE-2026-54872 LOW 3.7 libcrypto3 3.5.8-r0 no fix available
CVE-2026-54872 LOW 3.7 libssl3 3.5.8-r0 no fix available
CVE-2026-54872 LOW 3.7 openssl 3.5.8-r0 no fix available
CVE-2026-54875 LOW 3.7 libssl3 3.5.8-r0 no fix available
CVE-2026-54875 LOW 3.7 openssl 3.5.8-r0 no fix available
CVE-2026-54875 LOW 3.7 libcrypto3 3.5.8-r0 no fix available
CVE-2026-60589 LOW 3.7 openjdk21 21.0.12_p8-r0 no fix available
CVE-2026-77696 LOW 3.7 openssl 3.5.8-r0 no fix available
CVE-2026-77696 LOW 3.7 libssl3 3.5.8-r0 no fix available
CVE-2026-77696 LOW 3.7 libcrypto3 3.5.8-r0 no fix available

Scan history

1 total · first today
SCANNED AT GRADE SCORE CRIT HIGH MED GRYPE DB
today F 0 0 24 29 2026-10-09T06:32:32.000Z