OCImendby CloudTrace

Image reports › ghcr.io/canonical/static-rock/static

ghcr.io/canonical/static-rock/static — vulnerabilities, FIPS 140-3 and fixes

ghcr.io/canonical/static-rock/static · Ubuntu 26.04.1 LTS

Latest: ghcr.io/canonical/static-rock/static:26.04-26.04_edge · checked 2026-09-28

Not FIPS-ready

No. static:26.04-26.04_edge relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: Grade C: 8 known vulnerabilities

8 known vulnerabilities in 1 package (1 critical, 5 high); 8 can be fixed by upgrading 1 package. Start with stdlib: upgrade 1.26.5 → 1.26.6 (fixes 8).

Open the full report → Get a fixed image Get a FIPS image Scan your own image

Fix plan for 26.04-26.04_edge

PackageInstalledUpgrade toFixes
stdlib1.26.51.26.68

Critical, high and exploited vulnerabilities in 26.04-26.04_edge

SeverityIDPackageFixed inSummary
criticalGO-2026-5026stdlib 1.26.51.26.6Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
highGO-2026-5942stdlib 1.26.51.26.6Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage
highGO-2026-5972stdlib 1.26.51.26.6Enforce maximum recursion depth in encoding/asn1
highGO-2026-6088stdlib 1.26.51.26.6Add recursion depth guard during decode in encoding/xml
highGO-2026-6089stdlib 1.26.51.26.6Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http
highGO-2026-6090stdlib 1.26.51.26.6Limit handshake messages we are willing to accept post-handshake in crypto/tls

All checked tags

TagFIPSKnown vulnerabilitiesChecked
26.04-26.04_edgeNot FIPS-readyC 8 1 critical2026-09-28ReportFix