Vulnerabilities (CVEs) found in APMIA 26.5.x Docker Image
search cancel

Vulnerabilities (CVEs) found in APMIA 26.5.x Docker Image

book

Article ID: 448063

calendar_today

Updated On:

Products

DX SaaS

Issue/Introduction

A security scan (e.g., Prisma Cloud, Blackduck) of the DX APM Universal Monitoring Agent (APMIA) docker image version 26.5.x reports multiple High and Critical vulnerabilities.

 

Affected Packages and CVEs
Commonly flagged vulnerabilities include, but are not limited to:

  • io.netty (Netty): CVE-2026-45536, CVE-2026-41417, CVE-2026-42580, CVE-2026-42587, CVE-2026-47691, CVE-2026-45673, etc.
  • org.eclipse.jetty (Jetty): CVE-2026-1605, CVE-2026-2332, CVE-2026-5795, CVE-2025-11143, CVE-2024-6763.
  • org.apache.logging.log4j (Log4j): CVE-2026-34480, CVE-2026-34481, CVE-2026-34479.
  • Spring Framework: CVE-2016-1000027, CVE-2026-41840, CVE-2026-41849, CVE-2026-41851.
  • libthrift: CVE-2026-41602 through CVE-2026-41607, CVE-2026-43868, CVE-2026-43870.
  • Other libraries: jackson-core, logback-core, mssql-jdbc, protobuf-java.

Cause

These vulnerabilities reside in third-party libraries bundled within the APMIA 26.5.x image. While APMIA itself may not use the vulnerable features of these libraries, security scanners flag the presence of the library versions in the container filesystem.

Resolution

Upgrade to the latest DX APM SaaS deliverable image:

  • Fixed Version: APMIA version 26.6.1 or higher.
  • Future Hardening: Additional fixes and continuous security updates are planned for version 26.7.1 and subsequent releases.

Customers are encouraged to stay on the most recent SaaS release to ensure they have the latest security patches.