Ocimendby CloudTrace

Image reports › nginx

nginx — vulnerabilities, FIPS 140-3 and fixes

docker.io/library/nginx · Debian GNU/Linux 12 (bookworm)

Latest: nginx:1.27 · checked 2026-09-26

Not FIPS-ready

No. nginx:1.27 relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: Grade A: 113 known vulnerabilities

113 known vulnerabilities in 54 packages (4 critical, 13 high); none has a fix available yet.

Open the full interactive report → Scan your own image

Critical, high and exploited vulnerabilities in 1.27

SeverityIDPackageFixed inSummary
criticalCVE-2024-5535libssl3 3.0.16-1~deb12u1no fix yetIssue summary: Calling the OpenSSL API function SSL_select_next_proto with an
criticalCVE-2024-5535openssl 3.0.16-1~deb12u1no fix yetIssue summary: Calling the OpenSSL API function SSL_select_next_proto with an
criticalCVE-2023-45853zlib1g 1:1.2.13.dfsg-1no fix yetMiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affe
criticalCVE-2023-6879libaom3 3.6.0-1+deb12u1no fix yetIncreasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().
highCVE-2023-52356libtiff6 4.5.0-6+deb12u2no fix yetA segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a remote attacker to cause a heap-buffer overflow, leading to a denial of service.
highCVE-2023-2953libldap-2.5-0 2.5.13+dfsg-5no fix yetA vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
highCVE-2023-52355libtiff6 4.5.0-6+deb12u2no fix yetAn out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.
highCVE-2023-52425libexpat1 2.5.0-1+deb12u1no fix yetlibexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed.
highCVE-2023-31484perl-base 5.36.0-7+deb12u2no fix yetCPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
highCVE-2024-7006libtiff6 4.5.0-6+deb12u2no fix yetA null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain means, such as restricting the heap space size or injecting faults, causing a segmentation fault. This can cause an application crash, even
highCVE-2024-25062libxml2 2.9.14+dfsg-1.3~deb12u1no fix yetAn issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.
highCVE-2024-26461libgssapi-krb5-2 1.20.1-2+deb12u3no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
highCVE-2024-26461libk5crypto3 1.20.1-2+deb12u3no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
highCVE-2024-26461libkrb5-3 1.20.1-2+deb12u3no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
highCVE-2024-26461libkrb5support0 1.20.1-2+deb12u3no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.

All checked tags

TagFIPSKnown vulnerabilitiesChecked
1.27Not FIPS-readyA 113 4 critical2026-09-26Full report