Image reports › ocimend.io/elasticsearch
ocimend.io/elasticsearch — vulnerabilities, FIPS 140-3 and fixes
ocimend.io/elasticsearch · Red Hat Enterprise Linux 9.8 (Plow)
Latest: ocimend.io/elasticsearch:9.5.3-fixed · checked 2026-09-29
Not FIPS-ready
No. elasticsearch:9.5.3-fixed relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: Grade A: 33 known vulnerabilities
33 known vulnerabilities in 10 packages (1 critical, 10 high); 33 can be fixed by upgrading 12 packages. Start with io.netty:netty-handler: upgrade 4.1.135.Final → 4.1.137.Final (fixes 2). Rebuilding on the latest base image picks up most OS fixes at once.
Open the full report → Get a fixed image Get a FIPS image Scan your own image
Fix plan for 9.5.3-fixed
| Package | Installed | Upgrade to | Fixes |
|---|---|---|---|
| io.netty:netty-handler | 4.1.135.Final | 4.1.137.Final | 2 |
| com.fasterxml.jackson.core:jackson-databind | 2.19.2 | 2.21.6 | 9 |
| com.fasterxml.jackson.core:jackson-databind | 2.18.9 | 2.18.10 | 3 |
| com.fasterxml.jackson.core:jackson-databind | 2.21.5 | 2.21.6 | 3 |
| io.netty:netty-codec-http | 4.1.135.Final | 4.1.137.Final | 8 |
| io.netty:netty-codec-http2 | 4.1.135.Final | 4.1.136.Final | 2 |
| io.netty:netty-codec | 4.1.135.Final | 4.1.136.Final | 1 |
| org.apache.commons:commons-lang3 | 3.9 | 3.18.0 | 1 |
Critical, high and exploited vulnerabilities in 9.5.3-fixed
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| critical | GHSA-c4c3-7fpv-j4q5 | io.netty:netty-handler 4.1.135.Final | 4.1.137.Final | Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext |
| high | GHSA-rmj7-2vxq-3g9f | com.fasterxml.jackson.core:jackson-databind 2.19.2 | 2.21.4 | jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray) |
| high | GHSA-j3rv-43j4-c7qm | com.fasterxml.jackson.core:jackson-databind 2.19.2 | 2.21.4 | jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation |
| high | GHSA-6jqx-86gh-f27w | io.netty:netty-codec-http 4.1.135.Final | 4.1.136.Final | Netty SPDY SETTINGS frame count materializes unbounded settings map |
| high | GHSA-mvh2-crg5-v77c | io.netty:netty-codec-http 4.1.135.Final | 4.1.136.Final | Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation |
| high | GHSA-93wv-jw9v-4972 | io.netty:netty-codec-http2 4.1.135.Final | 4.1.136.Final | Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS) |
| high | GHSA-jppx-w49h-x2qq | io.netty:netty-codec-http 4.1.135.Final | 4.1.136.Final | Netty: [SpdyHttpDecoder] ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion |
| high | GHSA-q4xh-88c3-wmh7 | com.fasterxml.jackson.core:jackson-databind 2.19.2 | 2.21.6 | jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS |
| high | GHSA-q4xh-88c3-wmh7 | com.fasterxml.jackson.core:jackson-databind 2.18.9 | 2.18.10 | jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS |
| high | GHSA-q4xh-88c3-wmh7 | com.fasterxml.jackson.core:jackson-databind 2.21.5 | 2.21.6 | jackson-databind: Duration XMLGregorianCalendar Unbounded Number Parse DoS |
| high | GHSA-558v-64gr-wgg4 | io.netty:netty-codec 4.1.135.Final | 4.1.136.Final | Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| 9.5.3-fixed | Not FIPS-ready | A 33 1 critical | 2026-09-29 | ReportFix |