OCImendby CloudTrace

Image reports › ocimend.io/httpd

ocimend.io/httpd — vulnerabilities, FIPS 140-3 and fixes

ocimend.io/httpd · Debian GNU/Linux 13 (trixie)

Latest: ocimend.io/httpd:latest-fips · checked 2026-09-27

Not FIPS-ready

No. httpd:latest-fips relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: Grade A: 53 known vulnerabilities

53 known vulnerabilities in 28 packages (5 high); none has a fix available yet.

Open the full report → Get a fixed image Get a FIPS image Scan your own image

Critical, high and exploited vulnerabilities in latest-fips

SeverityIDPackageFixed inSummary
highCVE-2024-25062libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u3no fix yetAn issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.
highCVE-2024-26461libgssapi-krb5-2 1.21.3-5+deb13u1no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
highCVE-2024-26461libk5crypto3 1.21.3-5+deb13u1no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
highCVE-2024-26461libkrb5-3 1.21.3-5+deb13u1no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
highCVE-2024-26461libkrb5support0 1.21.3-5+deb13u1no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.

All checked tags

TagFIPSKnown vulnerabilitiesChecked
latest-fipsNot FIPS-readyA 532026-09-27ReportFix