home / Tomcat / tomcat:9.0.122-jre11-temurin-resolute tomcat:9.0.122-jre11-temurin-resolute docker pull tomcat:9.0.122-jre11-temurin-resolute click to select
Image metadata PULL COUNT
828.7M
repository-level (not per-tag)
RUNS AS
root
image config.User
LAST PUSHED
5d ago
2026-10-05 22:12:11
MANIFEST DIGEST
sha256:3b6e94bd5cc0…
from registry manifest
Latest scan 2026-10-10 08:33:23 UTC · today OPEN CVES BY SEVERITY
Grype DB 2026-10-09T06:32:32.000Z
· rubric cerodeo-v1
RUBRIC BREAKDOWN (4 signals that moved the score) -6 · Medium CVEs (fixable) +10 · Rebuilt in last 90 days +3 · Multi-arch +2 · readme_has_example
Raw data
Every signal above decomposes to arithmetic from inputs you can verify. Nothing in these downloads is derived or
massaged — they're the raw grype matches and the raw snapshot history exactly as our scanner wrote them.
Reproduce this score yourself
We don't use judgement to score — every signal is deterministic from the image, the manifest, and a pinned CVE DB.
Run the script below on any host with skopeo, syft,
grype, cosign, and jq installed — it fetches the versioned rubric spec, computes the same breakdown, and prints the same grade. Pin the Grype DB with --grype-db to reproduce bit-for-bit identical results.
curl -fsSLO https://ce.rodeo/verify-score.sh && chmod +x verify-score.sh
./verify-score.sh tomcat:9.0.122-jre11-temurin-resolute \
--rubric cerodeo-v1 \
--grype-db 2026-10-09T06:32:32.000Z
All open CVEs (140) sorted by severity, then CVSS score CVE ID SEV CVSS PACKAGE FIX
CVE-2026-18374 MEDIUM — libc-gconv-modules-extra 2.43-2ubuntu2.4 no fix available CVE-2026-35341 MEDIUM — rust-coreutils 0.10.0-1ubuntu2~26.04.1 no fix available CVE-2026-35344 MEDIUM — rust-coreutils 0.10.0-1ubuntu2~26.04.1 no fix available CVE-2026-35345 MEDIUM — rust-coreutils 0.10.0-1ubuntu2~26.04.1 no fix available CVE-2026-35348 MEDIUM — rust-coreutils 0.10.0-1ubuntu2~26.04.1 no fix available CVE-2026-35350 MEDIUM — rust-coreutils 0.10.0-1ubuntu2~26.04.1 no fix available CVE-2026-35351 MEDIUM — rust-coreutils 0.10.0-1ubuntu2~26.04.1 no fix available CVE-2026-35352 MEDIUM — rust-coreutils 0.10.0-1ubuntu2~26.04.1 no fix available CVE-2026-35354 MEDIUM — rust-coreutils 0.10.0-1ubuntu2~26.04.1 no fix available CVE-2026-35357 MEDIUM — rust-coreutils 0.10.0-1ubuntu2~26.04.1 no fix available CVE-2026-35359 MEDIUM — rust-coreutils 0.10.0-1ubuntu2~26.04.1 no fix available CVE-2026-35360 MEDIUM — rust-coreutils 0.10.0-1ubuntu2~26.04.1 no fix available CVE-2026-35363 MEDIUM — rust-coreutils 0.10.0-1ubuntu2~26.04.1 no fix available CVE-2026-35364 MEDIUM — rust-coreutils 0.10.0-1ubuntu2~26.04.1 no fix available CVE-2026-35367 MEDIUM — rust-coreutils 0.10.0-1ubuntu2~26.04.1 no fix available CVE-2026-35368 MEDIUM — rust-coreutils 0.10.0-1ubuntu2~26.04.1 no fix available CVE-2026-35370 MEDIUM — rust-coreutils 0.10.0-1ubuntu2~26.04.1 no fix available CVE-2026-35371 MEDIUM — rust-coreutils 0.10.0-1ubuntu2~26.04.1 no fix available CVE-2026-35373 MEDIUM — rust-coreutils 0.10.0-1ubuntu2~26.04.1 no fix available CVE-2026-35374 MEDIUM — rust-coreutils 0.10.0-1ubuntu2~26.04.1 no fix available CVE-2026-35377 MEDIUM — rust-coreutils 0.10.0-1ubuntu2~26.04.1 no fix available CVE-2026-56391 MEDIUM — coreutils 9.5-1ubuntu2+0.0.0~ubuntu25 fixed in 9.7-3ubuntu2.1 CVE-2026-7017 MEDIUM — perl-base 5.40.1-7ubuntu0.3 no fix available CVE-2026-76642 MEDIUM — libsmartcols1 2.41.3-3ubuntu2.2 no fix available CVE-2026-76642 MEDIUM — login 1:4.16.0-2+really2.41.3-3ubuntu2.2 no fix available CVE-2026-78408 MEDIUM — libsmartcols1 2.41.3-3ubuntu2.2 no fix available CVE-2026-78408 MEDIUM — login 1:4.16.0-2+really2.41.3-3ubuntu2.2 no fix available CVE-2026-78409 MEDIUM — libsmartcols1 2.41.3-3ubuntu2.2 no fix available CVE-2026-78409 MEDIUM — login 1:4.16.0-2+really2.41.3-3ubuntu2.2 no fix available CVE-2026-78410 MEDIUM — login 1:4.16.0-2+really2.41.3-3ubuntu2.2 no fix available CVE-2026-78410 MEDIUM — libsmartcols1 2.41.3-3ubuntu2.2 no fix available CVE-2026-85091 MEDIUM — zlib1g 1:1.3.dfsg+really1.3.1-1ubuntu3.1 no fix available CVE-2026-8674 MEDIUM — libc-gconv-modules-extra 2.43-2ubuntu2.4 no fix available CVE-2026-86805 MEDIUM — libc-gconv-modules-extra 2.43-2ubuntu2.4 no fix available CVE-2026-89092 MEDIUM — libc-gconv-modules-extra 2.43-2ubuntu2.4 no fix available CVE-2026-93658 MEDIUM — rust-coreutils 0.10.0-1ubuntu2~26.04.1 no fix available CVE-2026-9538 MEDIUM — perl-base 5.40.1-7ubuntu0.3 no fix available CVE-2026-95512 MEDIUM — libfreetype6 2.14.2+dfsg-1ubuntu0.1 fixed in 2.14.2+dfsg-1ubuntu0.2 CVE-2026-95818 MEDIUM — libc-gconv-modules-extra 2.43-2ubuntu2.4 no fix available CVE-2026-97399 MEDIUM — libc-gconv-modules-extra 2.43-2ubuntu2.4 no fix available CVE-2025-5278 LOW — coreutils 9.5-1ubuntu2+0.0.0~ubuntu25 fixed in 9.7-3ubuntu2.1
Scan history 1 total · first today SCANNED AT GRADE SCORE CRIT HIGH MED GRYPE DB
today A 100 0 0 114 2026-10-09T06:32:32.000Z
Methodology:
This image is re-matched against the fresh Grype vulnerability DB every hour. Snapshot rows marked
(same SBOM) reuse the prior scan's content via a pointer — about
90% of hourly cycles do. New CVE disclosures land in a new content row and bump the grade on the next match.
Full rubric at /about/grades ; for publishers wanting to
raise their grade, see /about/for-publishers .