Image reports › ocimend.io/caddy
ocimend.io/caddy — vulnerabilities, FIPS 140-3 and fixes
ocimend.io/caddy · Alpine Linux v3.23
Latest: ocimend.io/caddy:latest-fips · checked 2026-09-27
Not FIPS-ready
No. caddy:latest-fips relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: Grade D: 36 known vulnerabilities
36 known vulnerabilities in 14 packages (1 critical, 16 high); 35 can be fixed by upgrading 14 packages. Start with stdlib: upgrade 1.26.3 → 1.26.6 (fixes 13). Rebuilding on the latest base image picks up most OS fixes at once.
Open the full report → Get a fixed image Get a FIPS image Scan your own image
Fix plan for latest-fips
| Package | Installed | Upgrade to | Fixes |
|---|---|---|---|
| stdlib | 1.26.3 | 1.26.6 | 13 |
| google.golang.org/grpc | 1.81.0 | 1.83.1 | 5 |
| golang.org/x/net | 0.55.0 | 0.56.0 | 1 |
| golang.org/x/crypto | 0.52.0 | 0.56.0 | 3 |
| golang.org/x/text | 0.37.0 | 0.39.0 | 1 |
| github.com/go-chi/chi/v5 | 5.2.5 | 5.3.0 | 3 |
| go.opentelemetry.io/otel | 1.43.0 | 1.44.0 | 1 |
| go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc | 0.19.0 | 0.21.0 | 1 |
Critical, high and exploited vulnerabilities in latest-fips
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| critical | GO-2026-5026 | stdlib 1.26.3 | 1.26.6 | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna |
| high | GO-2026-6443 | google.golang.org/grpc 1.81.0 | 1.82.2 | Server panic via missing authority or Host headers in google.golang.org/grpc |
| high | GO-2026-5942 | golang.org/x/net 0.55.0 | 0.56.0 | Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage |
| high | GO-2026-5942 | stdlib 1.26.3 | 1.26.6 | Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage |
| high | GO-2026-6348 | google.golang.org/grpc 1.81.0 | 1.83.1 | Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation in google.golang.org/grpc |
| high | GO-2026-5972 | stdlib 1.26.3 | 1.26.6 | Enforce maximum recursion depth in encoding/asn1 |
| high | GO-2026-6088 | stdlib 1.26.3 | 1.26.6 | Add recursion depth guard during decode in encoding/xml |
| high | GO-2026-6089 | stdlib 1.26.3 | 1.26.6 | Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http |
| high | GO-2026-6090 | stdlib 1.26.3 | 1.26.6 | Limit handshake messages we are willing to accept post-handshake in crypto/tls |
| high | GO-2026-5038 | stdlib 1.26.3 | 1.26.4 | Quadratic complexity in WordDecoder.DecodeHeader in mime |
| high | GO-2026-6355 | golang.org/x/crypto 0.52.0 | 0.56.0 | Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh |
| high | GO-2026-5970 | golang.org/x/text 0.37.0 | 0.39.0 | Infinite loop on invalid input in golang.org/x/text |
| high | GO-2026-6303 | golang.org/x/crypto 0.52.0 | 0.55.0 | Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh |
| high | GO-2026-6354 | golang.org/x/crypto 0.52.0 | 0.56.0 | Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh |
| high | GO-2026-4970 | stdlib 1.26.3 | 1.26.5 | Root escape via symlink plus trailing slash in os |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| latest-fips | Not FIPS-ready | D 36 1 critical | 2026-09-27 | ReportFix |