Image reports › ocimend.io/golang
ocimend.io/golang — vulnerabilities, FIPS 140-3 and fixes
ocimend.io/golang · Debian GNU/Linux 12 (bookworm)
Latest: ocimend.io/golang:1.20.8-fixed · checked 2026-09-26
Not FIPS-ready
No. golang:1.20.8-fixed relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: Grade F: 641 known vulnerabilities, 1 actively exploited
641 known vulnerabilities in 96 packages (9 critical, 116 high); 1 is being actively exploited in the wild; 71 can be fixed by upgrading 1 package. Start with stdlib: upgrade 1.20.8 → 1.25.13 (fixes 71).
Fix plan for 1.20.8-fixed
| Package | Installed | Upgrade to | Fixes |
|---|---|---|---|
| stdlib | 1.20.8 | 1.25.13 | 71 |
Critical, high and exploited vulnerabilities in 1.20.8-fixed
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| high exploited | GO-2023-2102 | stdlib 1.20.8 | 1.20.10 | HTTP/2 rapid reset can cause excessive work in net/http |
| critical | CVE-2024-5535 | libssl3 3.0.22-1~deb12u1 | no fix yet | Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an |
| critical | CVE-2024-5535 | openssl 3.0.22-1~deb12u1 | no fix yet | Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an |
| critical | CVE-2023-45853 | zlib1g 1:1.2.13.dfsg-1 | no fix yet | MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affe |
| critical | GO-2024-2887 | stdlib 1.20.8 | 1.21.11 | Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netip |
| critical | CVE-2024-38541 | linux-libc-dev 6.1.187-1 | no fix yet | In the Linux kernel, the following vulnerability has been resolved: |
| critical | GO-2026-4337 | stdlib 1.20.8 | 1.24.13 | Unexpected session resumption in crypto/tls |
| critical | GO-2025-3563 | stdlib 1.20.8 | 1.23.8 | Request smuggling due to acceptance of invalid chunked data in net/http |
| critical | CVE-2024-38428 | wget 1.21.3-1 | no fix yet | url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent. |
| critical | GO-2026-5026 | stdlib 1.20.8 | 1.25.13 | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna |
| high | CVE-2019-19814 | linux-libc-dev 6.1.187-1 | no fix yet | In the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segment slab-out-of-bounds write access because an array is bounded by the number of dirty types (8) but the array index can exceed this. |
| high | GO-2023-2185 | stdlib 1.20.8 | 1.20.11 | Insecure parsing of Windows paths with a \??\ prefix in path/filepath |
| high | GO-2026-4341 | stdlib 1.20.8 | 1.24.12 | Memory exhaustion in query parameter parsing in net/url |
| high | CVE-2024-7592 | libpython3.11-minimal 3.11.2-6+deb12u8 | no fix yet | There is a LOW severity vulnerability affecting CPython, specifically the |
| high | CVE-2024-7592 | libpython3.11-stdlib 3.11.2-6+deb12u8 | no fix yet | There is a LOW severity vulnerability affecting CPython, specifically the |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| 1.20.8-fixed | Not FIPS-ready | F 641 9 critical 1 exploited | 2026-09-26 | Full report |
| 1.20.9-fixed | Not FIPS-ready | F 641 9 critical 1 exploited | 2026-09-26 | Full report |