OCImendby CloudTrace

Image reports › ocimend.io/mariadb

ocimend.io/mariadb — vulnerabilities, FIPS 140-3 and fixes

ocimend.io/mariadb · Ubuntu 26.04.1 LTS

Latest: ocimend.io/mariadb:latest-fips · checked 2026-09-28

Not FIPS-ready

No. mariadb:latest-fips relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: Grade F: 482 known vulnerabilities

482 known vulnerabilities in 42 packages (10 critical, 148 high); 47 can be fixed by upgrading 3 packages. Start with stdlib: upgrade 1.24.6 → 1.25.13 (fixes 45). Rebuilding on the latest base image picks up most OS fixes at once.

Open the full report → Get a fixed image Get a FIPS image Scan your own image

Fix plan for latest-fips

PackageInstalledUpgrade toFixes
stdlib1.24.61.25.1345
golang.org/x/sys0.1.00.44.01
libsqlite3-03.46.1-9ubuntu0.23.46.1-9ubuntu0.31

Critical, high and exploited vulnerabilities in latest-fips

SeverityIDPackageFixed inSummary
criticalGO-2026-4337stdlib 1.24.61.24.13Unexpected session resumption in crypto/tls
criticalGO-2026-5026stdlib 1.24.61.25.13Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
criticalUBUNTU-CVE-2026-60082libdbi-perl 1.647-1ubuntu0.26.04.1no fix yetDBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index. This could be triggered by a caller supplying inconsistent met
criticalUBUNTU-CVE-2026-73193libdbi-perl 1.647-1ubuntu0.26.04.1no fix yetDBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by preparse. preparse reserves its output buffer with `newSV(strlen(statement) * 7 + 16)`, budgeting seven output bytes per input byte for the longest ':p99
criticalUBUNTU-CVE-2026-73194libdbi-perl 1.647-1ubuntu0.26.04.1no fix yetDBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse. preparse reserves seven output bytes per input byte, the width of the longest ':p99999' expansion. The ':N' branch parses the number with `atoi(src)` a
criticalUBUNTU-CVE-2026-78030libdbi-perl 1.647-1ubuntu0.26.04.1no fix yetDBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module. require treats a path-shaped string as a literal filename
criticalUBUNTU-CVE-2026-14739libdbi-perl 1.647-1ubuntu0.26.04.1no fix yetDBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders. DBI version 1.650 sets a hard limit of 99,999 placeholders.
criticalUBUNTU-CVE-2026-15043libdbi-perl 1.647-1ubuntu0.26.04.1no fix yetDBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, <= was evaluated using Perl's ge ope
criticalUBUNTU-CVE-2026-14740libdbi-perl 1.647-1ubuntu0.26.04.1no fix yetDBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte.
highGO-2026-4341stdlib 1.24.61.24.12Memory exhaustion in query parameter parsing in net/url
highGO-2026-4981stdlib 1.24.61.25.10Crash when handling long CNAME response in net
highGO-2026-4986stdlib 1.24.61.25.10Quadratic string concatentation in consumeComment in net/mail
highGO-2026-4601stdlib 1.24.61.25.8Incorrect parsing of IPv6 host literals in net/url
highGO-2026-4977stdlib 1.24.61.25.10Quadratic string concatenation in consumePhrase in net/mail
highGO-2026-4918stdlib 1.24.61.25.10Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net

All checked tags

TagFIPSKnown vulnerabilitiesChecked
latest-fipsNot FIPS-readyF 482 10 critical2026-09-28ReportFix