OCImendby CloudTrace

Image reports › nvcr.io/nvidia/tritonserver

nvcr.io/nvidia/tritonserver — vulnerabilities, FIPS 140-3 and fixes

nvcr.io/nvidia/tritonserver · Ubuntu 22.04.4 LTS

Latest: nvcr.io/nvidia/tritonserver:24.08-vllm-python-py3 · checked 2026-09-30

Not FIPS-ready

No. tritonserver:24.08-vllm-python-py3 relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: Grade A: 541 known vulnerabilities, 2 actively exploited

541 known vulnerabilities in 171 packages (38 critical, 191 high); 2 are being actively exploited in the wild; 240 can be fixed by upgrading 60 packages. Start with ray: upgrade 2.34.0 → 2.56.0 (fixes 4). Rebuilding on the latest base image picks up most OS fixes at once.

Open the full report → Get a fixed image Get a FIPS image Scan your own image

Fix plan for 24.08-vllm-python-py3

PackageInstalledUpgrade toFixes
ray2.34.02.56.04
starlette0.38.21.3.17
cryptography3.4.849.0.013
libssl33.0.2-0ubuntu1.173.0.2-0ubuntu1.181
openssl3.0.2-0ubuntu1.173.0.2-0ubuntu1.181
transformers4.44.15.10.017
torch2.3.12.10.012
libexpat12.4.7-1ubuntu0.32.4.7-1ubuntu0.41

Critical, high and exploited vulnerabilities in 24.08-vllm-python-py3

SeverityIDPackageFixed inSummary
critical exploitedPYSEC-2026-520ray 2.34.02.52.0Ray is vulnerable to Critical RCE via Safari & Firefox Browsers through DNS Rebinding Attack
medium exploitedPYSEC-2026-161starlette 0.38.21.0.1BadHost: Missing Host header validation poisons request.url.path, bypassing path-based security checks
criticalPYSEC-2026-517ray 2.34.0no fix yetRay has arbitrary code execution via jobs submission API
highUSN-6986-1libssl3 3.0.2-0ubuntu1.173.0.2-0ubuntu1.18openssl vulnerability
highUSN-6986-1openssl 3.0.2-0ubuntu1.173.0.2-0ubuntu1.18openssl vulnerability
highPYSEC-2026-800cryptography 3.4.839.0.1Vulnerable OpenSSL included in cryptography wheels
criticalUBUNTU-CVE-2022-36227libarchive-dev 3.6.0-1ubuntu1.1no fix yetIn libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-executi
criticalUBUNTU-CVE-2022-36227libarchive13 3.6.0-1ubuntu1.1no fix yetIn libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-executi
criticalUBUNTU-CVE-2021-46848libtasn1-6 4.18.0-4build1no fix yetGNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.
criticalPYSEC-2025-41torch 2.3.12.6.0PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using torch.load with weights_on
criticalUBUNTU-CVE-2022-29502libpmi2-0 21.08.5-2ubuntu1no fix yetSchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges.
criticalUBUNTU-CVE-2022-29502libpmi2-0-dev 21.08.5-2ubuntu1no fix yetSchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges.
criticalUBUNTU-CVE-2022-29502libslurm37 21.08.5-2ubuntu1no fix yetSchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges.
criticalUSN-7000-2libexpat1 2.4.7-1ubuntu0.32.4.7-1ubuntu0.4expat vulnerabilities
criticalUSN-7000-2libexpat1-dev 2.4.7-1ubuntu0.32.4.7-1ubuntu0.4expat vulnerabilities

All checked tags

TagFIPSKnown vulnerabilitiesChecked
24.08-vllm-python-py3Not FIPS-readyA 541 38 critical 2 exploited2026-09-30ReportFix