timberio/vector:0.50.0-debian

Base OS: debian 13.1 45 vulnerabilities fixed
Tag Override

Original tag 0.50.0-distroless-libc was overridden to 0.50.0-debian because the original image uses a distroless/scratch base that Copa cannot patch.

Patched Image
quay.io/verity/timberio/vector:0.50.0-debian-patched
Signed SLSA L3 SBOM Rekor
Verify this artifact
Cosign signature
cosign verify \
  --certificate-identity-regexp "https://github.com/descope/verity/.github/workflows/" \
  --certificate-oidc-issuer "https://token.actions.githubusercontent.com" \
  quay.io/verity/timberio/vector:0.50.0-debian-patched
Build provenance
gh attestation verify \
  oci://quay.io/verity/timberio/vector:0.50.0-debian-patched \
  --owner descope

Pre-patch scan

Found 45 vulnerabilit ies in the original image. 45 fixed by Copa.

3CRITICAL6HIGH33MEDIUM3LOW

Vulnerability details

IDPackageInstalledFixedSeverity
CVE-2025-15467libssl3t643.5.1-13.5.4-1~deb13u2 CRITICAL
CVE-2025-15467openssl3.5.1-13.5.4-1~deb13u2 CRITICAL
CVE-2025-15467openssl-provider-legacy3.5.1-13.5.4-1~deb13u2 CRITICAL
CVE-2025-69419libssl3t643.5.1-13.5.4-1~deb13u2 HIGH
CVE-2025-69421libssl3t643.5.1-13.5.4-1~deb13u2 HIGH
CVE-2025-69419openssl3.5.1-13.5.4-1~deb13u2 HIGH
CVE-2025-69421openssl3.5.1-13.5.4-1~deb13u2 HIGH
CVE-2025-69419openssl-provider-legacy3.5.1-13.5.4-1~deb13u2 HIGH
CVE-2025-69421openssl-provider-legacy3.5.1-13.5.4-1~deb13u2 HIGH
CVE-2025-11187libssl3t643.5.1-13.5.4-1~deb13u2 MEDIUM
CVE-2025-15468libssl3t643.5.1-13.5.4-1~deb13u2 MEDIUM
CVE-2025-15469libssl3t643.5.1-13.5.4-1~deb13u2 MEDIUM
CVE-2025-66199libssl3t643.5.1-13.5.4-1~deb13u2 MEDIUM
CVE-2025-68160libssl3t643.5.1-13.5.4-1~deb13u2 MEDIUM
CVE-2025-69418libssl3t643.5.1-13.5.4-1~deb13u2 MEDIUM
CVE-2025-69420libssl3t643.5.1-13.5.4-1~deb13u2 MEDIUM
CVE-2025-9230libssl3t643.5.1-13.5.1-1+deb13u1 MEDIUM
CVE-2025-9231libssl3t643.5.1-13.5.1-1+deb13u1 MEDIUM
CVE-2026-22795libssl3t643.5.1-13.5.4-1~deb13u2 MEDIUM
CVE-2026-22796libssl3t643.5.1-13.5.4-1~deb13u2 MEDIUM
CVE-2025-11187openssl3.5.1-13.5.4-1~deb13u2 MEDIUM
CVE-2025-15468openssl3.5.1-13.5.4-1~deb13u2 MEDIUM
CVE-2025-15469openssl3.5.1-13.5.4-1~deb13u2 MEDIUM
CVE-2025-66199openssl3.5.1-13.5.4-1~deb13u2 MEDIUM
CVE-2025-68160openssl3.5.1-13.5.4-1~deb13u2 MEDIUM
CVE-2025-69418openssl3.5.1-13.5.4-1~deb13u2 MEDIUM
CVE-2025-69420openssl3.5.1-13.5.4-1~deb13u2 MEDIUM
CVE-2025-9230openssl3.5.1-13.5.1-1+deb13u1 MEDIUM
CVE-2025-9231openssl3.5.1-13.5.1-1+deb13u1 MEDIUM
CVE-2026-22795openssl3.5.1-13.5.4-1~deb13u2 MEDIUM
CVE-2026-22796openssl3.5.1-13.5.4-1~deb13u2 MEDIUM
CVE-2025-11187openssl-provider-legacy3.5.1-13.5.4-1~deb13u2 MEDIUM
CVE-2025-15468openssl-provider-legacy3.5.1-13.5.4-1~deb13u2 MEDIUM
CVE-2025-15469openssl-provider-legacy3.5.1-13.5.4-1~deb13u2 MEDIUM
CVE-2025-66199openssl-provider-legacy3.5.1-13.5.4-1~deb13u2 MEDIUM
CVE-2025-68160openssl-provider-legacy3.5.1-13.5.4-1~deb13u2 MEDIUM
CVE-2025-69418openssl-provider-legacy3.5.1-13.5.4-1~deb13u2 MEDIUM
CVE-2025-69420openssl-provider-legacy3.5.1-13.5.4-1~deb13u2 MEDIUM
CVE-2025-9230openssl-provider-legacy3.5.1-13.5.1-1+deb13u1 MEDIUM
CVE-2025-9231openssl-provider-legacy3.5.1-13.5.1-1+deb13u1 MEDIUM
CVE-2026-22795openssl-provider-legacy3.5.1-13.5.4-1~deb13u2 MEDIUM
CVE-2026-22796openssl-provider-legacy3.5.1-13.5.4-1~deb13u2 MEDIUM
CVE-2025-9232libssl3t643.5.1-13.5.1-1+deb13u1 LOW
CVE-2025-9232openssl3.5.1-13.5.1-1+deb13u1 LOW
CVE-2025-9232openssl-provider-legacy3.5.1-13.5.1-1+deb13u1 LOW
Original image reference
timberio/vector:0.50.0-debian