Free · online · verified
CVE-free container images
OCImend gives you CVE-free container images for free: any Docker or OCI image goes in, every known vulnerability that has a fixed package comes out fixed, and the new image is rescanned and started side by side with the original before it is published. Pull the ready ones below, or paste your own image and get it back fixed in minutes, no sign-up.
Make my image CVE-free → Browse the registry
Why OCImend
Same image, fixed
Your image, not a rebuild on a different base: the vulnerable packages are upgraded to the versions that fix them and compiled Go programs are rebuilt with fixed releases.
Verified, not promised
Every image is rescanned (the before/after CVE count is on its report) and started next to the original to make sure it still runs.
Honest about what is left
A CVE with no fix released anywhere is listed as such, with the measured ways out: a newer base, a hardened image.
Yours to keep
Pull from ocimend.io, promote by digest into your own registry, or take the Dockerfile and rebuild it in your CI.
Ready to pull
| Image | Pull | Known CVEs before → after | Built |
|---|---|---|---|
| elasticsearch from mirror.gcr.io/library/elasticsearch:8.13.0 | docker pull ocimend.io/elasticsearch:8.13.0-fixed | 160 → 147 | 2026-10-01 |
| haproxy from mirror.gcr.io/library/haproxy:2.6-alpine3.22 | docker pull ocimend.io/haproxy:2.6-alpine3.22-fixed | 101 → 0 | 2026-10-01 |
| eclipse-temurin from mirror.gcr.io/library/eclipse-temurin:17.0.20.1_1-jdk | docker pull ocimend.io/eclipse-temurin:17.0.20.1_1-jdk-fixed | 357 → 354 | 2026-10-01 |
| mongo from mirror.gcr.io/library/mongo:bionic | docker pull ocimend.io/mongo:bionic-fixed | 282 → 120 | 2026-10-01 |
| alpine from mirror.gcr.io/library/alpine:3.17.7 | docker pull ocimend.io/alpine:3.17.7-fixed | 20 → 0 | 2026-10-01 |
| golang from mirror.gcr.io/library/golang:1.21-alpine3.19 | docker pull ocimend.io/golang:1.21-alpine3.19-fixed | 60 → 58 | 2026-10-01 |
| python from mirror.gcr.io/library/python:3.13.0a1-alpine3.17 | docker pull ocimend.io/python:3.13.0a1-alpine3.17-fixed | 48 → 0 | 2026-10-01 |
| redis from mirror.gcr.io/library/redis:7.0.14-alpine3.18 | docker pull ocimend.io/redis:7.0.14-alpine3.18-fixed | 26 → 0 | 2026-10-01 |
| ubuntu from mirror.gcr.io/library/ubuntu:resolute-20260108 | docker pull ocimend.io/ubuntu:resolute-20260108-fixed | 220 → 92 | 2026-09-30 |
| rabbitmq from mirror.gcr.io/library/rabbitmq:3.7-alpine | docker pull ocimend.io/rabbitmq:3.7-alpine-fixed | 50 → 0 | 2026-09-30 |
| node from mirror.gcr.io/library/node:26.0.0-alpine | docker pull ocimend.io/node:26.0.0-alpine-fixed | 76 → 26 | 2026-09-30 |
| ruby from mirror.gcr.io/library/ruby:3.3.9-alpine | docker pull ocimend.io/ruby:3.3.9-alpine-fixed | 100 → 0 | 2026-09-29 |
| mariadb from mirror.gcr.io/library/mariadb:10.6.16 | docker pull ocimend.io/mariadb:10.6.16-fixed | 190 → 165 | 2026-09-29 |
| php from mirror.gcr.io/library/php:7.3.28-fpm | docker pull ocimend.io/php:7.3.28-fpm-fixed | 121 → 0 | 2026-09-28 |
| caddy from mirror.gcr.io/library/caddy:2.10.2-builder-alpine | docker pull ocimend.io/caddy:2.10.2-builder-alpine-fixed | 260 → 80 | 2026-09-28 |
| httpd from mirror.gcr.io/library/httpd:2.4.61 | docker pull ocimend.io/httpd:2.4.61-fixed | 107 → 89 | 2026-09-28 |
| registry.access.redhat.com/ubi9/ubi-minimal from registry.access.redhat.com/ubi9/ubi-minimal:latest | docker pull ocimend.io/registry.access.redhat.com/ubi9/ubi-minimal:latest-fixed | 1 → 0 | 2026-09-27 |
| traefik from mirror.gcr.io/library/traefik:v3.3.0 | docker pull ocimend.io/traefik:v3.3.0-fixed | 210 → 134 | 2026-09-27 |
| postgres from mirror.gcr.io/library/postgres:16.12-alpine3.22 | docker pull ocimend.io/postgres:16.12-alpine3.22-fixed | 123 → 46 | 2026-09-27 |
| nginx from mirror.gcr.io/library/nginx:1.19.5-alpine-perl | docker pull ocimend.io/nginx:1.19.5-alpine-perl-fixed | 98 → 0 | 2026-09-27 |
| mysql from mirror.gcr.io/library/mysql:8.0.17 | docker pull ocimend.io/mysql:8.0.17-fixed | 67 → 0 | 2026-09-27 |
Questions
Is a CVE-free image really zero CVEs?
Is it free?
Does it work for my private image?
How do I stay CVE-free?
Also on OCImend
FIPS-enabled images · Free online CVE fix · Hardened images · Image CVE reports · Guides · For platform teams