Image reports › ocimend.io/haproxy
ocimend.io/haproxy — vulnerabilities, FIPS 140-3 and fixes
ocimend.io/haproxy · Debian GNU/Linux 12 (bookworm)
Latest: ocimend.io/haproxy:3.0.6-fips · checked 2026-09-27
Not FIPS-ready
No. haproxy:3.0.6-fips relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: Grade A: 50 known vulnerabilities
50 known vulnerabilities in 35 packages (3 critical, 1 high); none has a fix available yet.
Open the full report → Get a fixed image Get a FIPS image Scan your own image
Critical, high and exploited vulnerabilities in 3.0.6-fips
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| critical | CVE-2024-5535 | libssl3 3.0.15-1~deb12u1 | no fix yet | Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an |
| critical | CVE-2024-5535 | openssl 3.0.15-1~deb12u1 | no fix yet | Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an |
| critical | CVE-2023-45853 | zlib1g 1:1.2.13.dfsg-1 | no fix yet | MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affe |
| high | CVE-2023-31484 | perl-base 5.36.0-7+deb12u1 | no fix yet | CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS. |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| 3.0.6-fips | Not FIPS-ready | A 50 3 critical | 2026-09-27 | ReportFix |
| 3.1.0-fips | Not FIPS-ready | A 50 3 critical | 2026-09-27 | ReportFix |
| latest-fips | FIPS-ready | A 26 | 2026-09-27 | ReportFix |