What Happens When You Curate RedHat UBI9 Images with RapidFort? 93.3% Fewer CVEs.
.png)
Most teams using RedHat UBI9 as their base image assume it is a reasonably secure starting point. The vulnerability counts tell a different story.
During a recent customer trial, we scanned 8 RedHat UBI9 base images in active use and compared them against their RapidFort-curated equivalents. Curation reduced total known CVEs by 93.3% across the set, from 1,621 down to 108, and removed all high-severity findings entirely. The reduction was consistent across every image type in the trial: Python, Node, and multiple JDK/JRE variants. That consistency matters. It indicates the result comes from RapidFort curation process rather than one specific image. This is a direct, customer-side data point, not a lab benchmark.
Vulnerability Comparison
Across all 8 RedHat UBI9 images in this comparison, curation cut total known CVEs by 93.3%, from 1,621 down to 108.
Vulnerabilities by Image and Severity
Left: total CVE count per image. Right: CVEs by severity, summed across all 8 images.
The left panel compares total CVE counts per image, RedHat UBI9 (red) against its RapidFort-curated equivalent (blue), across all 8 images in the trial. The right panel sums those same 8 images by severity. Both views show the same story: RapidFort curation consistently pushes CVE counts down into the low teens regardless of image type, and removes high-severity findings entirely, while the RedHat originals range from 113 to 463 total CVEs.
Per-Image Breakdown
The reduction holds in the high-80s to high-90s percent range across every image in the set: runtimes, JDKs, and the Python base alike, which points to the effect coming from RapidFort curation process itself rather than being specific to one image type.
What This Means
Every UBI9 image in this comparison drops to roughly a tenth (or less) of its original CVE count once curated, and high-severity findings are eliminated entirely in this sample.
Same functional image. A fraction of the CVE exposure.
Organizations do not have to choose between the open source software their teams have standardized on and a near-zero CVE baseline. RapidFort delivers both.
Subscribe to receive the latest blog posts to your inbox every week.
Stay in touch
Subscribe for product updates and RapidFort newsletter.
Latest posts
Eliminate Attack Vectors at the Source
Continuously eliminate up to 99.9% of CVEs without code changes
Products
Use Case
Address
440 North Wolfe Road, Sunnyvale, CA 94085
Stay in touch
Subscribe for product updates and RapidFort newsletter.
© 2026 RapidFort, Inc.
RapidFort, RAPIDFORT, and RBOM® are registered trademarks of RapidFort, Inc. All other marks and names mentioned herein may be trademarks of their respective companies.





