7.9.0 common vulnerabilities and exposures
The following table lists all CVEs that don't impact EMR Serverless applications that run on recommended configurations of Amazon EMR 7.9.0. Amazon EMR is dependent on upstream open-source for availability of fixes and will provide the latest stable version as part of the Core Engine components within 90 days of Amazon EMR verifying the fixes.
This table was updated on August 21, 2026.
| CVE ID | Severity | CVE details URL |
|---|---|---|
|
CVE-2019-10202 |
CRITICAL |
|
|
CVE-2022-46337 |
CRITICAL |
|
|
CVE-2024-47561 |
CRITICAL |
|
|
CVE-2025-30065 |
CRITICAL |
|
|
CVE-2015-6420 |
HIGH |
|
|
CVE-2020-13949 |
HIGH |
|
|
CVE-2023-2976 |
HIGH |
|
|
CVE-2023-52428 |
HIGH |
|
|
CVE-2024-13009 |
HIGH |
|
|
CVE-2024-21634 |
HIGH |
|
|
CVE-2024-22201 |
HIGH |
|
|
CVE-2024-25638 |
HIGH |
|
|
CVE-2024-36114 |
HIGH |
|
|
CVE-2024-47554 |
HIGH |
|
|
CVE-2024-7254 |
HIGH |
|
|
CVE-2025-24970 |
HIGH |