OCImendby CloudTrace

Image reports › ocimend.io/caddy

ocimend.io/caddy — vulnerabilities, FIPS 140-3 and fixes

ocimend.io/caddy · Alpine Linux v3.23

Latest: ocimend.io/caddy:latest-fips · checked 2026-09-27

Not FIPS-ready

No. caddy:latest-fips relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: Grade D: 36 known vulnerabilities

36 known vulnerabilities in 14 packages (1 critical, 16 high); 35 can be fixed by upgrading 14 packages. Start with stdlib: upgrade 1.26.3 → 1.26.6 (fixes 13). Rebuilding on the latest base image picks up most OS fixes at once.

Open the full report → Get a fixed image Get a FIPS image Scan your own image

Fix plan for latest-fips

PackageInstalledUpgrade toFixes
stdlib1.26.31.26.613
google.golang.org/grpc1.81.01.83.15
golang.org/x/net0.55.00.56.01
golang.org/x/crypto0.52.00.56.03
golang.org/x/text0.37.00.39.01
github.com/go-chi/chi/v55.2.55.3.03
go.opentelemetry.io/otel1.43.01.44.01
go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc0.19.00.21.01

Critical, high and exploited vulnerabilities in latest-fips

SeverityIDPackageFixed inSummary
criticalGO-2026-5026stdlib 1.26.31.26.6Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
highGO-2026-6443google.golang.org/grpc 1.81.01.82.2Server panic via missing authority or Host headers in google.golang.org/grpc
highGO-2026-5942golang.org/x/net 0.55.00.56.0Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage
highGO-2026-5942stdlib 1.26.31.26.6Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage
highGO-2026-6348google.golang.org/grpc 1.81.01.83.1Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation in google.golang.org/grpc
highGO-2026-5972stdlib 1.26.31.26.6Enforce maximum recursion depth in encoding/asn1
highGO-2026-6088stdlib 1.26.31.26.6Add recursion depth guard during decode in encoding/xml
highGO-2026-6089stdlib 1.26.31.26.6Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http
highGO-2026-6090stdlib 1.26.31.26.6Limit handshake messages we are willing to accept post-handshake in crypto/tls
highGO-2026-5038stdlib 1.26.31.26.4Quadratic complexity in WordDecoder.DecodeHeader in mime
highGO-2026-6355golang.org/x/crypto 0.52.00.56.0Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh
highGO-2026-5970golang.org/x/text 0.37.00.39.0Infinite loop on invalid input in golang.org/x/text
highGO-2026-6303golang.org/x/crypto 0.52.00.55.0Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh
highGO-2026-6354golang.org/x/crypto 0.52.00.56.0Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh
highGO-2026-4970stdlib 1.26.31.26.5Root escape via symlink plus trailing slash in os

All checked tags

TagFIPSKnown vulnerabilitiesChecked
latest-fipsNot FIPS-readyD 36 1 critical2026-09-27ReportFix