Image reports › ocimend.io/gcr.io/distroless/base-debian12
ocimend.io/gcr.io/distroless/base-debian12 — vulnerabilities, FIPS 140-3 and fixes
ocimend.io/gcr.io/distroless/base-debian12 · Distroless
Latest: ocimend.io/gcr.io/distroless/base-debian12:latest-fips · checked 2026-09-27
Almost FIPS-ready
Not yet. base-debian12:latest-fips is close, but a few settings need fixing before it can be used where FIPS is required.
Security: Grade A: 3 known vulnerabilities
3 known vulnerabilities in 2 packages (1 critical); none has a fix available yet.
Open the full report → Get a fixed image Get a FIPS image Scan your own image
Critical, high and exploited vulnerabilities in latest-fips
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| critical | CVE-2024-5535 | libssl3 3.0.20-1~deb12u2 | no fix yet | Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| latest-fips | FIPS-ready with conditions | A 3 1 critical | 2026-09-27 | ReportFix |