Image reports › nginx
nginx — vulnerabilities, FIPS 140-3 and fixes
docker.io/library/nginx · Debian GNU/Linux 12 (bookworm)
Latest: nginx:1.27 · checked 2026-09-26
Not FIPS-ready
No. nginx:1.27 relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: Grade A: 113 known vulnerabilities
113 known vulnerabilities in 54 packages (4 critical, 13 high); none has a fix available yet.
Critical, high and exploited vulnerabilities in 1.27
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| critical | CVE-2024-5535 | libssl3 3.0.16-1~deb12u1 | no fix yet | Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an |
| critical | CVE-2024-5535 | openssl 3.0.16-1~deb12u1 | no fix yet | Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an |
| critical | CVE-2023-45853 | zlib1g 1:1.2.13.dfsg-1 | no fix yet | MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affe |
| critical | CVE-2023-6879 | libaom3 3.6.0-1+deb12u1 | no fix yet | Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc(). |
| high | CVE-2023-52356 | libtiff6 4.5.0-6+deb12u2 | no fix yet | A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a remote attacker to cause a heap-buffer overflow, leading to a denial of service. |
| high | CVE-2023-2953 | libldap-2.5-0 2.5.13+dfsg-5 | no fix yet | A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function. |
| high | CVE-2023-52355 | libtiff6 4.5.0-6+deb12u2 | no fix yet | An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB. |
| high | CVE-2023-52425 | libexpat1 2.5.0-1+deb12u1 | no fix yet | libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed. |
| high | CVE-2023-31484 | perl-base 5.36.0-7+deb12u2 | no fix yet | CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS. |
| high | CVE-2024-7006 | libtiff6 4.5.0-6+deb12u2 | no fix yet | A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain means, such as restricting the heap space size or injecting faults, causing a segmentation fault. This can cause an application crash, even |
| high | CVE-2024-25062 | libxml2 2.9.14+dfsg-1.3~deb12u1 | no fix yet | An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free. |
| high | CVE-2024-26461 | libgssapi-krb5-2 1.20.1-2+deb12u3 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| high | CVE-2024-26461 | libk5crypto3 1.20.1-2+deb12u3 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| high | CVE-2024-26461 | libkrb5-3 1.20.1-2+deb12u3 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| high | CVE-2024-26461 | libkrb5support0 1.20.1-2+deb12u3 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| 1.27 | Not FIPS-ready | A 113 4 critical | 2026-09-26 | Full report |