Image reports › nvcr.io/nvidia/tritonserver
nvcr.io/nvidia/tritonserver — vulnerabilities, FIPS 140-3 and fixes
nvcr.io/nvidia/tritonserver · Ubuntu 22.04.4 LTS
Latest: nvcr.io/nvidia/tritonserver:24.08-vllm-python-py3 · checked 2026-09-30
Not FIPS-ready
No. tritonserver:24.08-vllm-python-py3 relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: Grade A: 541 known vulnerabilities, 2 actively exploited
541 known vulnerabilities in 171 packages (38 critical, 191 high); 2 are being actively exploited in the wild; 240 can be fixed by upgrading 60 packages. Start with ray: upgrade 2.34.0 → 2.56.0 (fixes 4). Rebuilding on the latest base image picks up most OS fixes at once.
Open the full report → Get a fixed image Get a FIPS image Scan your own image
Fix plan for 24.08-vllm-python-py3
| Package | Installed | Upgrade to | Fixes |
|---|---|---|---|
| ray | 2.34.0 | 2.56.0 | 4 |
| starlette | 0.38.2 | 1.3.1 | 7 |
| cryptography | 3.4.8 | 49.0.0 | 13 |
| libssl3 | 3.0.2-0ubuntu1.17 | 3.0.2-0ubuntu1.18 | 1 |
| openssl | 3.0.2-0ubuntu1.17 | 3.0.2-0ubuntu1.18 | 1 |
| transformers | 4.44.1 | 5.10.0 | 17 |
| torch | 2.3.1 | 2.10.0 | 12 |
| libexpat1 | 2.4.7-1ubuntu0.3 | 2.4.7-1ubuntu0.4 | 1 |
Critical, high and exploited vulnerabilities in 24.08-vllm-python-py3
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| critical exploited | PYSEC-2026-520 | ray 2.34.0 | 2.52.0 | Ray is vulnerable to Critical RCE via Safari & Firefox Browsers through DNS Rebinding Attack |
| medium exploited | PYSEC-2026-161 | starlette 0.38.2 | 1.0.1 | BadHost: Missing Host header validation poisons request.url.path, bypassing path-based security checks |
| critical | PYSEC-2026-517 | ray 2.34.0 | no fix yet | Ray has arbitrary code execution via jobs submission API |
| high | USN-6986-1 | libssl3 3.0.2-0ubuntu1.17 | 3.0.2-0ubuntu1.18 | openssl vulnerability |
| high | USN-6986-1 | openssl 3.0.2-0ubuntu1.17 | 3.0.2-0ubuntu1.18 | openssl vulnerability |
| high | PYSEC-2026-800 | cryptography 3.4.8 | 39.0.1 | Vulnerable OpenSSL included in cryptography wheels |
| critical | UBUNTU-CVE-2022-36227 | libarchive-dev 3.6.0-1ubuntu1.1 | no fix yet | In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-executi |
| critical | UBUNTU-CVE-2022-36227 | libarchive13 3.6.0-1ubuntu1.1 | no fix yet | In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-executi |
| critical | UBUNTU-CVE-2021-46848 | libtasn1-6 4.18.0-4build1 | no fix yet | GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der. |
| critical | PYSEC-2025-41 | torch 2.3.1 | 2.6.0 | PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerability exists in PyTorch when loading a model using torch.load with weights_on |
| critical | UBUNTU-CVE-2022-29502 | libpmi2-0 21.08.5-2ubuntu1 | no fix yet | SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges. |
| critical | UBUNTU-CVE-2022-29502 | libpmi2-0-dev 21.08.5-2ubuntu1 | no fix yet | SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges. |
| critical | UBUNTU-CVE-2022-29502 | libslurm37 21.08.5-2ubuntu1 | no fix yet | SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges. |
| critical | USN-7000-2 | libexpat1 2.4.7-1ubuntu0.3 | 2.4.7-1ubuntu0.4 | expat vulnerabilities |
| critical | USN-7000-2 | libexpat1-dev 2.4.7-1ubuntu0.3 | 2.4.7-1ubuntu0.4 | expat vulnerabilities |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| 24.08-vllm-python-py3 | Not FIPS-ready | A 541 38 critical 2 exploited | 2026-09-30 | ReportFix |