Image reports › docker.io/vllm/vllm-openai
docker.io/vllm/vllm-openai — vulnerabilities, FIPS 140-3 and fixes
docker.io/vllm/vllm-openai · Ubuntu 24.04.3 LTS
Latest: docker.io/vllm/vllm-openai:latest · checked 2026-09-27
Not FIPS-ready
No. vllm-openai:latest relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: Grade D: 299 known vulnerabilities
299 known vulnerabilities in 81 packages (15 critical, 153 high); 33 can be fixed by upgrading 9 packages. Start with cryptography: upgrade 41.0.7 → 49.0.0 (fixes 9). Rebuilding on the latest base image picks up most OS fixes at once.
Open the full report → Get a fixed image Get a FIPS image Scan your own image
Fix plan for latest
| Package | Installed | Upgrade to | Fixes |
|---|---|---|---|
| cryptography | 41.0.7 | 49.0.0 | 9 |
| httplib2 | 0.20.4 | 0.32.0 | 1 |
| PyJWT | 2.7.0 | 2.13.0 | 4 |
| stdlib | 1.25.10 | 1.25.13 | 12 |
| go.etcd.io/etcd/client/pkg/v3 | 3.5.21 | 3.5.33 | 1 |
| google.golang.org/grpc | 1.82.1 | 1.83.1 | 3 |
| golang.org/x/net | 0.55.0 | 0.56.0 | 1 |
| golang.org/x/text | 0.37.0 | 0.39.0 | 1 |
Critical, high and exploited vulnerabilities in latest
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| critical | PYSEC-2026-3553 | cryptography 41.0.7 | 49.0.0 | python-cryptography: Duplicate self-signed intermediates can cause exponential path-building |
| critical | PYSEC-2026-3554 | cryptography 41.0.7 | 49.0.0 | python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees |
| high | UBUNTU-CVE-2016-20013 | libc6 2.39-0ubuntu8.9 | no fix yet | sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password. |
| high | PYSEC-2026-1283 | cryptography 41.0.7 | 42.0.0 | Python Cryptography package vulnerable to Bleichenbacher timing oracle attack |
| high | PYSEC-2024-225 | cryptography 41.0.7 | 42.0.4 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Starting in version 38.0.0 and prior to version 42.0.4, if `pkcs12.serialize_key_and_certificates` is called with both a certificate whose public key did not match the provided private key and an |
| high | PYSEC-2026-3444 | httplib2 0.20.4 | 0.32.0 | httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allowing a malicious or compromised HTTP server to return a small c |
| high | PYSEC-2026-179 | PyJWT 2.7.0 | 2.13.0 | PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate use of JSON Web Keys in HMAC algorithm, allowing attacker to use the issuer public key as the secret |
| high | PYSEC-2026-120 | PyJWT 2.7.0 | 2.12.0 | PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing extensions that PyJWT does not understand, the library accepts the token instead of rejecting |
| high | PYSEC-2025-183 | PyJWT 2.7.0 | no fix yet | pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length is chosen by the application that uses the library (admittedly, library users may benefit from a minimum value and a mechanism for opting in to strict enforcement). |
| high | GHSA-537c-gmf6-5ccf | cryptography 41.0.7 | 48.0.1 | Vulnerable OpenSSL included in cryptography wheels |
| critical | UBUNTU-CVE-2019-17113 | libopenmpt0t64 0.7.3-1.1build3 | no fix yet | In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and ModPlug_SampleName in libopenmpt_modplug.c do not restrict the lengths of libmodplug output-buffer strings in the C API, leading to a buffer overflow. |
| critical | UBUNTU-CVE-2021-44732 | libmbedcrypto7t64 2.28.8-1 | no fix yet | Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure. |
| critical | UBUNTU-CVE-2022-35409 | libmbedcrypto7t64 2.28.8-1 | no fix yet | An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attacker can send an invalid ClientHello message to a DTLS server that causes a heap-based buffer over-read of up to 255 bytes. This can cause a server crash or possibly information dis |
| critical | UBUNTU-CVE-2022-46393 | libmbedcrypto7t64 2.28.8-1 | no fix yet | An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-read in DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is enabled and MBEDTLS_SSL_CID_IN_LEN_MAX > 2 * MBEDTLS_SSL_CID_OUT_LEN_MAX. |
| critical | UBUNTU-CVE-2023-45199 | libmbedcrypto7t64 2.28.8-1 | no fix yet | Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution. |