Image reports › ocimend.io/mongo
ocimend.io/mongo — vulnerabilities, FIPS 140-3 and fixes
ocimend.io/mongo · Ubuntu 24.04.5 LTS
Latest: ocimend.io/mongo:latest-fips · checked 2026-09-27
Not FIPS-ready
No. mongo:latest-fips relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: Grade D: 81 known vulnerabilities
81 known vulnerabilities in 16 packages (3 critical, 36 high); 58 can be fixed by upgrading 5 packages. Start with stdlib: upgrade 1.24.6 → 1.25.13 (fixes 45). Rebuilding on the latest base image picks up most OS fixes at once.
Open the full report → Get a fixed image Get a FIPS image Scan your own image
Fix plan for latest-fips
| Package | Installed | Upgrade to | Fixes |
|---|---|---|---|
| stdlib | 1.24.6 | 1.25.13 | 45 |
| golang.org/x/sys | 0.1.0 | 0.44.0 | 1 |
| stdlib | 1.26.5 | 1.26.6 | 8 |
| golang.org/x/crypto | 0.54.0 | 0.56.0 | 3 |
| github.com/klauspost/compress | 1.18.6 | 1.18.7 | 1 |
Critical, high and exploited vulnerabilities in latest-fips
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| critical | GO-2026-4337 | stdlib 1.24.6 | 1.24.13 | Unexpected session resumption in crypto/tls |
| critical | GO-2026-5026 | stdlib 1.24.6 | 1.25.13 | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna |
| high | GO-2026-4341 | stdlib 1.24.6 | 1.24.12 | Memory exhaustion in query parameter parsing in net/url |
| high | UBUNTU-CVE-2016-20013 | libc6 2.39-0ubuntu8.9 | no fix yet | sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password. |
| high | UBUNTU-CVE-2024-26461 | libgssapi-krb5-2 1.20.1-6ubuntu2.10 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| high | UBUNTU-CVE-2024-26461 | libk5crypto3 1.20.1-6ubuntu2.10 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| high | UBUNTU-CVE-2024-26461 | libkrb5-3 1.20.1-6ubuntu2.10 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| high | UBUNTU-CVE-2024-26461 | libkrb5support0 1.20.1-6ubuntu2.10 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| high | GO-2026-4981 | stdlib 1.24.6 | 1.25.10 | Crash when handling long CNAME response in net |
| high | GO-2026-4986 | stdlib 1.24.6 | 1.25.10 | Quadratic string concatentation in consumeComment in net/mail |
| high | GO-2026-4601 | stdlib 1.24.6 | 1.25.8 | Incorrect parsing of IPv6 host literals in net/url |
| high | GO-2026-4977 | stdlib 1.24.6 | 1.25.10 | Quadratic string concatenation in consumePhrase in net/mail |
| high | GO-2026-4918 | stdlib 1.24.6 | 1.25.10 | Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net |
| high | GO-2026-4947 | stdlib 1.24.6 | 1.25.9 | Unexpected work during chain building in crypto/x509 |
| high | GO-2026-4870 | stdlib 1.24.6 | 1.25.9 | Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| latest-fips | Not FIPS-ready | D 81 3 critical | 2026-09-27 | ReportFix |