OCImendby CloudTrace

Image reports › ocimend.io/elasticsearch

ocimend.io/elasticsearch — vulnerabilities, FIPS 140-3 and fixes

ocimend.io/elasticsearch · Red Hat Enterprise Linux 9.8 (Plow)

Latest: ocimend.io/elasticsearch:9.5.3-fixed · checked 2026-09-29

Not FIPS-ready

No. elasticsearch:9.5.3-fixed relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: Grade A: 33 known vulnerabilities

33 known vulnerabilities in 10 packages (1 critical, 10 high); 33 can be fixed by upgrading 12 packages. Start with io.netty:netty-handler: upgrade 4.1.135.Final → 4.1.137.Final (fixes 2). Rebuilding on the latest base image picks up most OS fixes at once.

Open the full report → Get a fixed image Get a FIPS image Scan your own image

Fix plan for 9.5.3-fixed

PackageInstalledUpgrade toFixes
io.netty:netty-handler4.1.135.Final4.1.137.Final2
com.fasterxml.jackson.core:jackson-databind2.19.22.21.69
com.fasterxml.jackson.core:jackson-databind2.18.92.18.103
com.fasterxml.jackson.core:jackson-databind2.21.52.21.63
io.netty:netty-codec-http4.1.135.Final4.1.137.Final8
io.netty:netty-codec-http24.1.135.Final4.1.136.Final2
io.netty:netty-codec4.1.135.Final4.1.136.Final1
org.apache.commons:commons-lang33.93.18.01

Critical, high and exploited vulnerabilities in 9.5.3-fixed

SeverityIDPackageFixed inSummary
criticalGHSA-c4c3-7fpv-j4q5io.netty:netty-handler 4.1.135.Final4.1.137.FinalNetty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext
highGHSA-rmj7-2vxq-3g9fcom.fasterxml.jackson.core:jackson-databind 2.19.22.21.4jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
highGHSA-j3rv-43j4-c7qmcom.fasterxml.jackson.core:jackson-databind 2.19.22.21.4jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation
highGHSA-6jqx-86gh-f27wio.netty:netty-codec-http 4.1.135.Final4.1.136.FinalNetty SPDY SETTINGS frame count materializes unbounded settings map
highGHSA-mvh2-crg5-v77cio.netty:netty-codec-http 4.1.135.Final4.1.136.FinalNetty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation
highGHSA-93wv-jw9v-4972io.netty:netty-codec-http2 4.1.135.Final4.1.136.FinalNetty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
highGHSA-jppx-w49h-x2qqio.netty:netty-codec-http 4.1.135.Final4.1.136.FinalNetty: [SpdyHttpDecoder] ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion
highGHSA-q4xh-88c3-wmh7com.fasterxml.jackson.core:jackson-databind 2.19.22.21.6jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS
highGHSA-q4xh-88c3-wmh7com.fasterxml.jackson.core:jackson-databind 2.18.92.18.10jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS
highGHSA-q4xh-88c3-wmh7com.fasterxml.jackson.core:jackson-databind 2.21.52.21.6jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS
highGHSA-558v-64gr-wgg4io.netty:netty-codec 4.1.135.Final4.1.136.FinalNetty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang

All checked tags

TagFIPSKnown vulnerabilitiesChecked
9.5.3-fixedNot FIPS-readyA 33 1 critical2026-09-29ReportFix