Ocimendby CloudTrace

Image reports › ocimend.io/golang

ocimend.io/golang — vulnerabilities, FIPS 140-3 and fixes

ocimend.io/golang · Debian GNU/Linux 12 (bookworm)

Latest: ocimend.io/golang:1.20.8-fixed · checked 2026-09-26

Not FIPS-ready

No. golang:1.20.8-fixed relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: Grade F: 641 known vulnerabilities, 1 actively exploited

641 known vulnerabilities in 96 packages (9 critical, 116 high); 1 is being actively exploited in the wild; 71 can be fixed by upgrading 1 package. Start with stdlib: upgrade 1.20.8 → 1.25.13 (fixes 71).

Open the full interactive report → Scan your own image

Fix plan for 1.20.8-fixed

PackageInstalledUpgrade toFixes
stdlib1.20.81.25.1371

Critical, high and exploited vulnerabilities in 1.20.8-fixed

SeverityIDPackageFixed inSummary
high exploitedGO-2023-2102stdlib 1.20.81.20.10HTTP/2 rapid reset can cause excessive work in net/http
criticalCVE-2024-5535libssl3 3.0.22-1~deb12u1no fix yetIssue summary: Calling the OpenSSL API function SSL_select_next_proto with an
criticalCVE-2024-5535openssl 3.0.22-1~deb12u1no fix yetIssue summary: Calling the OpenSSL API function SSL_select_next_proto with an
criticalCVE-2023-45853zlib1g 1:1.2.13.dfsg-1no fix yetMiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affe
criticalGO-2024-2887stdlib 1.20.81.21.11Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netip
criticalCVE-2024-38541linux-libc-dev 6.1.187-1no fix yetIn the Linux kernel, the following vulnerability has been resolved:
criticalGO-2026-4337stdlib 1.20.81.24.13Unexpected session resumption in crypto/tls
criticalGO-2025-3563stdlib 1.20.81.23.8Request smuggling due to acceptance of invalid chunked data in net/http
criticalCVE-2024-38428wget 1.21.3-1no fix yeturl.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
criticalGO-2026-5026stdlib 1.20.81.25.13Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
highCVE-2019-19814linux-libc-dev 6.1.187-1no fix yetIn the Linux kernel 5.0.21, mounting a crafted f2fs filesystem image can cause __remove_dirty_segment slab-out-of-bounds write access because an array is bounded by the number of dirty types (8) but the array index can exceed this.
highGO-2023-2185stdlib 1.20.81.20.11Insecure parsing of Windows paths with a \??\ prefix in path/filepath
highGO-2026-4341stdlib 1.20.81.24.12Memory exhaustion in query parameter parsing in net/url
highCVE-2024-7592libpython3.11-minimal 3.11.2-6+deb12u8no fix yetThere is a LOW severity vulnerability affecting CPython, specifically the
highCVE-2024-7592libpython3.11-stdlib 3.11.2-6+deb12u8no fix yetThere is a LOW severity vulnerability affecting CPython, specifically the

All checked tags

TagFIPSKnown vulnerabilitiesChecked
1.20.8-fixedNot FIPS-readyF 641 9 critical 1 exploited2026-09-26Full report
1.20.9-fixedNot FIPS-readyF 641 9 critical 1 exploited2026-09-26Full report