What Happens When You Curate RedHat UBI9 Images with RapidFort? 93.3% Fewer CVEs.

Written by
Matthew Oliver-Mayho
-
Senior Solutions Engineer
,
Published on
July 23, 2026

Most teams using RedHat UBI9 as their base image assume it is a reasonably secure starting point. The vulnerability counts tell a different story.

During a recent customer trial, we scanned 8 RedHat UBI9 base images in active use and compared them against their RapidFort-curated equivalents. Curation reduced total known CVEs by 93.3% across the set, from 1,621 down to 108, and removed all high-severity findings entirely. The reduction was consistent across every image type in the trial: Python, Node, and multiple JDK/JRE variants. That consistency matters. It indicates the result comes from RapidFort curation process rather than one specific image. This is a direct, customer-side data point, not a lab benchmark.

93.3%
reduction in total known CVEs across all 8 images
1,621→108
total CVEs before and after curation
100%
of high-severity findings eliminated

Vulnerability Comparison

Across all 8 RedHat UBI9 images in this comparison, curation cut total known CVEs by 93.3%, from 1,621 down to 108.

SEVERITY REDHAT UBI9 RAPIDFORT CURATED REDUCTION
Critical 0 0 n/a (none present)
High 125 0 100%
Medium 907 83 90.8%
Low 589 25 95.8%
Total 1,621 108 93.3%

Vulnerabilities by Image and Severity

Bar charts comparing total CVE counts per image (RedHat UBI9 vs. RapidFort curated) and vulnerabilities by severity summed across all 8 images

Left: total CVE count per image. Right: CVEs by severity, summed across all 8 images.

The left panel compares total CVE counts per image, RedHat UBI9 (red) against its RapidFort-curated equivalent (blue), across all 8 images in the trial. The right panel sums those same 8 images by severity. Both views show the same story: RapidFort curation consistently pushes CVE counts down into the low teens regardless of image type, and removes high-severity findings entirely, while the RedHat originals range from 113 to 463 total CVEs.

Per-Image Breakdown

REDHAT UBI9 IMAGE CVEs RAPIDFORT CURATED IMAGE CVEs REDUCTION
python-312:9.8 463 python:3.12.13-ubi9-rfcurated 13 97.2%
openjdk-21:1.24 190 jdk-corretto:21.0.11-ubi9-rfcurated 13 93.2%
openjdk-17:1.24 188 jdk-corretto:17.0.19-ubi9-rfcurated 15 92.0%
openjdk-25:1.24 185 jdk-corretto:25.0.3-ubi9-rfcurated 13 93.0%
openjdk-21-runtime:1.24 163 jre-corretto:21.0.11-ubi9-rfcurated 13 92.0%
openjdk-17-runtime:1.24 161 jre-corretto:17.0.19-ubi9-rfcurated 14 91.3%
openjdk-25-runtime:1.24 158 jre-corretto:25.0.3-ubi9-rfcurated 13 91.8%
nodejs-24-minimal:9.8 113 node:24.18.0-ubi9-minimal-rfcurated 14 87.6%
python-312:9.8 → python:3.12.13-ubi9-rfcurated
RedHat CVEs463
RapidFort CVEs13
Reduction97.2%
openjdk-21:1.24 → jdk-corretto:21.0.11-ubi9-rfcurated
RedHat CVEs190
RapidFort CVEs13
Reduction93.2%
openjdk-17:1.24 → jdk-corretto:17.0.19-ubi9-rfcurated
RedHat CVEs188
RapidFort CVEs15
Reduction92.0%
openjdk-25:1.24 → jdk-corretto:25.0.3-ubi9-rfcurated
RedHat CVEs185
RapidFort CVEs13
Reduction93.0%
openjdk-21-runtime:1.24 → jre-corretto:21.0.11-ubi9-rfcurated
RedHat CVEs163
RapidFort CVEs13
Reduction92.0%
openjdk-17-runtime:1.24 → jre-corretto:17.0.19-ubi9-rfcurated
RedHat CVEs161
RapidFort CVEs14
Reduction91.3%
openjdk-25-runtime:1.24 → jre-corretto:25.0.3-ubi9-rfcurated
RedHat CVEs158
RapidFort CVEs13
Reduction91.8%
nodejs-24-minimal:9.8 → node:24.18.0-ubi9-minimal-rfcurated
RedHat CVEs113
RapidFort CVEs14
Reduction87.6%

The reduction holds in the high-80s to high-90s percent range across every image in the set: runtimes, JDKs, and the Python base alike, which points to the effect coming from RapidFort curation process itself rather than being specific to one image type.

What This Means

Every UBI9 image in this comparison drops to roughly a tenth (or less) of its original CVE count once curated, and high-severity findings are eliminated entirely in this sample.

The core proof point

Same functional image. A fraction of the CVE exposure.

Organizations do not have to choose between the open source software their teams have standardized on and a near-zero CVE baseline. RapidFort delivers both.

See what curation does for your images
Explore RapidFort Curated Images, near-zero CVE equivalents for the open source images your teams already use, or schedule a call to see it against your own stack.
Explore Curated Images Schedule a Call
Subscribe to newsletter

Subscribe to receive the latest blog posts to your inbox every week.

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Latest posts

2026 Gartner® Magic Quadrant™

for Software Supply Chain Security

Get the Report