Image reports › ghcr.io/canonical/static-rock/static
ghcr.io/canonical/static-rock/static — vulnerabilities, FIPS 140-3 and fixes
ghcr.io/canonical/static-rock/static · Ubuntu 26.04.1 LTS
Latest: ghcr.io/canonical/static-rock/static:26.04-26.04_edge · checked 2026-09-28
Not FIPS-ready
No. static:26.04-26.04_edge relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: Grade C: 8 known vulnerabilities
8 known vulnerabilities in 1 package (1 critical, 5 high); 8 can be fixed by upgrading 1 package. Start with stdlib: upgrade 1.26.5 → 1.26.6 (fixes 8).
Open the full report → Get a fixed image Get a FIPS image Scan your own image
Fix plan for 26.04-26.04_edge
| Package | Installed | Upgrade to | Fixes |
|---|---|---|---|
| stdlib | 1.26.5 | 1.26.6 | 8 |
Critical, high and exploited vulnerabilities in 26.04-26.04_edge
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| critical | GO-2026-5026 | stdlib 1.26.5 | 1.26.6 | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna |
| high | GO-2026-5942 | stdlib 1.26.5 | 1.26.6 | Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage |
| high | GO-2026-5972 | stdlib 1.26.5 | 1.26.6 | Enforce maximum recursion depth in encoding/asn1 |
| high | GO-2026-6088 | stdlib 1.26.5 | 1.26.6 | Add recursion depth guard during decode in encoding/xml |
| high | GO-2026-6089 | stdlib 1.26.5 | 1.26.6 | Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http |
| high | GO-2026-6090 | stdlib 1.26.5 | 1.26.6 | Limit handshake messages we are willing to accept post-handshake in crypto/tls |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| 26.04-26.04_edge | Not FIPS-ready | C 8 1 critical | 2026-09-28 | ReportFix |