Container Image CVE Comparison — Trivy vs Grype
Generated 2026-08-14 12:40 UTC · images scanned with Grype and Trivy · counts are unique CVEs (deduplicated by CVE ID)
Charts
Severity Comparison — Grype vs Trivy
Critical High Medium Low
| Grype | Trivy | Unique | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Image | Total | Crit | High | Med | Low | Total | Crit | High | Med | Low | Unique in Grype | Unique in Trivy |
| debian:13-slim | 71 | 6 | 15 | 19 | 3 | 75 | 4 | 8 | 27 | 31 | – | 4 |
| debian:13 | 71 | 6 | 15 | 19 | 3 | 75 | 4 | 8 | 27 | 31 | – | 4 |
| hello-conference:native-debian-slim | 71 | 6 | 15 | 19 | 3 | 75 | 4 | 8 | 27 | 31 | – | 4 |
| hello-conference:jre-temurin | 103 | 2 | 5 | 85 | 7 | 54 | 2 | 6 | 36 | 4 | 52 | 3 |
| almalinux/10-base | 261 | – | 17 | 145 | 99 | 45 | – | 29 | 13 | 3 | 216 | – |
| hello-conference:jlink-netty-distroless-base | 41 | 3 | 12 | 18 | 1 | 41 | 2 | 10 | 22 | 7 | – | – |
| eclipse-temurin:25-jdk | 105 | – | 1 | 84 | 16 | 40 | – | 2 | 27 | 5 | 68 | 3 |
| eclipse-temurin:25-jre | 88 | – | 1 | 76 | 7 | 39 | – | 2 | 27 | 4 | 52 | 3 |
| almalinux:10-minimal | 140 | – | 8 | 80 | 52 | 32 | – | 18 | 11 | 3 | 108 | – |
| hello-conference:crac-azul-distroless-base | 29 | 3 | 6 | 12 | 1 | 29 | 2 | 4 | 16 | 7 | – | – |
| hello-conference:jlink-cds-distroless-base | 29 | 3 | 6 | 12 | 1 | 29 | 2 | 4 | 16 | 7 | – | – |
| hello-conference:jlink-distroless-base | 29 | 3 | 6 | 12 | 1 | 29 | 2 | 4 | 16 | 7 | – | – |
| hello-conference:jlink-full-distroless-base | 29 | 3 | 6 | 12 | 1 | 29 | 2 | 4 | 16 | 7 | – | – |
| hello-conference:jlink-tuned-distroless-base | 29 | 3 | 6 | 12 | 1 | 29 | 2 | 4 | 16 | 7 | – | – |
| azul/zulu-openjdk:25-jdk-crac | 63 | – | – | 45 | 14 | 22 | – | – | 14 | 8 | 41 | – |
| eclipse-temurin:25-jdk-alpine | 30 | – | 6 | 24 | – | 14 | – | 2 | 12 | – | 16 | – |
| gcr.io/distroless/base-debian13 | 14 | 1 | 2 | 3 | 1 | 14 | – | – | 7 | 7 | – | – |
| amazoncorretto:25-jdk | 5 | – | 4 | 1 | – | 9 | – | 8 | 1 | – | – | 4 |
| almalinux/10-micro | 15 | – | 1 | 13 | 1 | 7 | – | 2 | 5 | – | 8 | – |
| amazoncorretto:25-alpine-jdk | 1 | – | – | 1 | – | 0 | – | – | – | – | 1 | – |
| azul/zulu-openjdk-alpine:25-latest | 1 | – | – | 1 | – | 0 | – | – | – | – | 1 | – |
| gcr.io/distroless/static-debian13 | 0 | – | – | – | – | 0 | – | – | – | – | – | – |
| ghcr.io/graalvm/native-image-community:25i2 | 9 | – | 4 | 3 | 2 | 0 | – | – | – | – | 9 | – |
| hello-conference:native-minimal-distroless-static | 0 | – | – | – | – | 0 | – | – | – | – | – | – |
| hello-conference:native-netty-scratch | 0 | – | – | – | – | 0 | – | – | – | – | – | – |
| hello-conference:native-scratch | 0 | – | – | – | – | 0 | – | – | – | – | – | – |
Full Report
OS-level vs application-level breakdown, coverage diff, OWASP Dependency-Check — click to expand
╔══════════════════════════════════════════════════════════════════════════════════════════════════════════════════╗
║ VIEW 1: Severity Count Comparison — Grype vs Trivy ║
╚══════════════════════════════════════════════════════════════════════════════════════════════════════════════════╝
IMAGE │ GRYPE (Tot/C/H/M/L/U) │ TRIVY (Tot/C/H/M/L/U) │ Unique Grype │ Unique Trivy
───────────────────────────────────────────────────┼────────────────────────────────┼────────────────────────────────┼──────────────┼──────────────
eclipse-temurin:25-jdk │ 105 0 1 84 16 4 │ 40 0 2 27 5 6 │ 68 │ 3
eclipse-temurin:25-jdk-alpine │ 30 0 6 24 0 0 │ 14 0 2 12 0 0 │ 16 │ -
eclipse-temurin:25-jre │ 88 0 1 76 7 4 │ 39 0 2 27 4 6 │ 52 │ 3
azul/zulu-openjdk:25-jdk-crac │ 63 0 0 45 14 4 │ 22 0 0 14 8 0 │ 41 │ -
azul/zulu-openjdk-alpine:25-latest │ 1 0 0 1 0 0 │ 0 0 0 0 0 0 │ 1 │ -
amazoncorretto:25-jdk │ 5 0 4 1 0 0 │ 9 0 8 1 0 0 │ - │ -
amazoncorretto:25-alpine-jdk │ 1 0 0 1 0 0 │ 0 0 0 0 0 0 │ 1 │ -
debian:13 │ 71 6 15 19 3 28 │ 75 4 8 27 31 5 │ - │ 4
debian:13-slim │ 71 6 15 19 3 28 │ 75 4 8 27 31 5 │ - │ 4
gcr.io/distroless/base-debian13 │ 14 1 2 3 1 7 │ 14 0 0 7 7 0 │ - │ -
gcr.io/distroless/static-debian13 │ 0 0 0 0 0 0 │ 0 0 0 0 0 0 │ - │ -
almalinux/10-base │ 261 0 17 145 99 0 │ 45 0 29 13 3 0 │ 216 │ -
almalinux:10-minimal │ 140 0 8 80 52 0 │ 32 0 18 11 3 0 │ 108 │ -
almalinux/10-micro │ 15 0 1 13 1 0 │ 7 0 2 5 0 0 │ 8 │ -
ghcr.io/graalvm/native-image-community:25i2 │ 9 0 4 3 2 0 │ 0 0 0 0 0 0 │ 36 │ -
hello-conference:jre-temurin │ 103 2 5 85 7 4 │ 54 2 6 36 4 6 │ 52 │ 3
hello-conference:jlink-full-distroless-base │ 29 3 6 12 1 7 │ 29 2 4 16 7 0 │ - │ -
hello-conference:jlink-distroless-base │ 29 3 6 12 1 7 │ 29 2 4 16 7 0 │ - │ -
hello-conference:jlink-netty-distroless-base │ 41 3 12 18 1 7 │ 41 2 10 22 7 0 │ - │ -
hello-conference:jlink-cds-distroless-base │ 29 3 6 12 1 7 │ 29 2 4 16 7 0 │ - │ -
hello-conference:jlink-tuned-distroless-base │ 29 3 6 12 1 7 │ 29 2 4 16 7 0 │ - │ -
hello-conference:crac-azul-distroless-base │ 29 3 6 12 1 7 │ 29 2 4 16 7 0 │ - │ -
hello-conference:native-debian-slim │ 71 6 15 19 3 28 │ 75 4 8 27 31 5 │ - │ 4
hello-conference:native-minimal-distroless-static │ 0 0 0 0 0 0 │ 0 0 0 0 0 0 │ - │ -
hello-conference:native-scratch │ 0 0 0 0 0 0 │ 0 0 0 0 0 0 │ - │ -
hello-conference:native-netty-scratch │ 0 0 0 0 0 0 │ 0 0 0 0 0 0 │ - │ -
Legend: Tot=Total C=Critical H=High M=Medium L=Low U=Unknown
All counts are unique CVEs (deduplicated by CVE ID, with Grype's GHSA ids resolved to their NVD CVE alias
via relatedVulnerabilities so the same finding under two different id schemes isn't double-counted)
'-' = scan not run, or no unique findings
Unique Grype = CVEs found by Grype but NOT by Trivy Unique Trivy = CVEs found by Trivy but NOT by Grype
⚠ Trivy may show 0 for Oracle Linux 10 images (e.g. GraalVM) — its vuln DB lacks OL10 coverage
╔══════════════════════════════════════════════════════════════════════════════════════════════════════════════════╗
║ VIEW 2: OS Packages vs Application Dependencies — Vulnerability Breakdown ║
╚══════════════════════════════════════════════════════════════════════════════════════════════════════════════════╝
── OS-level vulnerabilities (packages from the base image) ──
IMAGE │ GRYPE (Tot/C/H/M/L/U) │ TRIVY (Tot/C/H/M/L/U)
───────────────────────────────────────────────────┼────────────────────────────────┼────────────────────────────────
eclipse-temurin:25-jdk │ 100 0 0 84 16 0 │ 32 0 0 27 5 0
eclipse-temurin:25-jdk-alpine │ 30 0 6 24 0 0 │ 14 0 2 12 0 0
eclipse-temurin:25-jre │ 83 0 0 76 7 0 │ 31 0 0 27 4 0
azul/zulu-openjdk:25-jdk-crac │ 63 0 0 45 14 4 │ 22 0 0 14 8 0
azul/zulu-openjdk-alpine:25-latest │ 1 0 0 1 0 0 │ 0 0 0 0 0 0
amazoncorretto:25-jdk │ 5 0 4 1 0 0 │ 9 0 8 1 0 0
amazoncorretto:25-alpine-jdk │ 1 0 0 1 0 0 │ 0 0 0 0 0 0
debian:13 │ 71 6 15 19 3 28 │ 75 4 8 27 31 5
debian:13-slim │ 71 6 15 19 3 28 │ 75 4 8 27 31 5
gcr.io/distroless/base-debian13 │ 14 1 2 3 1 7 │ 14 0 0 7 7 0
gcr.io/distroless/static-debian13 │ 0 0 0 0 0 0 │ 0 0 0 0 0 0
almalinux/10-base │ 261 0 17 145 99 0 │ 45 0 29 13 3 0
almalinux:10-minimal │ 140 0 8 80 52 0 │ 32 0 18 11 3 0
almalinux/10-micro │ 15 0 1 13 1 0 │ 7 0 2 5 0 0
ghcr.io/graalvm/native-image-community:25i2 │ 9 0 4 3 2 0 │ 0 0 0 0 0 0
hello-conference:jre-temurin │ 83 0 0 76 7 0 │ 31 0 0 27 4 0
hello-conference:jlink-full-distroless-base │ 14 1 2 3 1 7 │ 14 0 0 7 7 0
hello-conference:jlink-distroless-base │ 14 1 2 3 1 7 │ 14 0 0 7 7 0
hello-conference:jlink-netty-distroless-base │ 14 1 2 3 1 7 │ 14 0 0 7 7 0
hello-conference:jlink-cds-distroless-base │ 14 1 2 3 1 7 │ 14 0 0 7 7 0
hello-conference:jlink-tuned-distroless-base │ 14 1 2 3 1 7 │ 14 0 0 7 7 0
hello-conference:crac-azul-distroless-base │ 14 1 2 3 1 7 │ 14 0 0 7 7 0
hello-conference:native-debian-slim │ 71 6 15 19 3 28 │ 75 4 8 27 31 5
hello-conference:native-minimal-distroless-static │ 0 0 0 0 0 0 │ 0 0 0 0 0 0
hello-conference:native-scratch │ 0 0 0 0 0 0 │ 0 0 0 0 0 0
hello-conference:native-netty-scratch │ 0 0 0 0 0 0 │ 0 0 0 0 0 0
── Application-level vulnerabilities (JAR/language dependencies) ──
⚠ OWASP scans a different project (demo with intentionally vulnerable deps)
IMAGE │ GRYPE (Tot/C/H/M/L/U) │ TRIVY (Tot/C/H/M/L/U) │ OWASP (Tot/C/H/M/L/U)
───────────────────────────────────────────────────┼────────────────────────────────┼────────────────────────────────┼────────────────────────────────
hello-conference:jre-temurin │ 20 2 5 9 0 4 │ 23 2 6 9 0 6 │ - - - - - -
hello-conference:jlink-full-distroless-base │ 15 2 4 9 0 0 │ 15 2 4 9 0 0 │ - - - - - -
hello-conference:jlink-distroless-base │ 15 2 4 9 0 0 │ 15 2 4 9 0 0 │ - - - - - -
hello-conference:jlink-netty-distroless-base │ 27 2 10 15 0 0 │ 27 2 10 15 0 0 │ - - - - - -
hello-conference:jlink-cds-distroless-base │ 15 2 4 9 0 0 │ 15 2 4 9 0 0 │ - - - - - -
hello-conference:jlink-tuned-distroless-base │ 15 2 4 9 0 0 │ 15 2 4 9 0 0 │ - - - - - -
hello-conference:crac-azul-distroless-base │ 15 2 4 9 0 0 │ 15 2 4 9 0 0 │ - - - - - -
hello-conference:native-debian-slim │ 0 0 0 0 0 0 │ 0 0 0 0 0 0 │ - - - - - -
hello-conference:native-minimal-distroless-static │ 0 0 0 0 0 0 │ 0 0 0 0 0 0 │ - - - - - -
hello-conference:native-scratch │ 0 0 0 0 0 0 │ 0 0 0 0 0 0 │ - - - - - -
hello-conference:native-netty-scratch │ 0 0 0 0 0 0 │ 0 0 0 0 0 0 │ - - - - - -
╔══════════════════════════════════════════════════════════════════════════════════════════════════════════════════╗
║ Key Takeaways ║
╠══════════════════════════════════════════════════════════════════════════════════════════════════════════════════╣
║ • All counts show unique CVEs (deduplicated) — not raw vulnerability entries ║
║ • OS-level: vulnerabilities in distro packages (apt/rpm) — reduced by distroless/scratch images ║
║ • App-level: vulnerabilities in JARs/dependencies — same across images (same app) ║
║ • ⚠ OWASP scans a DIFFERENT project (demo with intentionally vulnerable deps like log4j 2.0, ║
║ jackson-databind 2.9.10, Spring Boot 2.7) — NOT the hello-conference app that Trivy/Grype scan ║
║ • Unique Grype/Trivy = CVEs only that tool found — use both tools for best coverage ║
╚══════════════════════════════════════════════════════════════════════════════════════════════════════════════════╝