OCImendby CloudTrace

Image reports › ocimend.io/mongo

ocimend.io/mongo — vulnerabilities, FIPS 140-3 and fixes

ocimend.io/mongo · Ubuntu 24.04.5 LTS

Latest: ocimend.io/mongo:latest-fips · checked 2026-09-27

Not FIPS-ready

No. mongo:latest-fips relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: Grade D: 81 known vulnerabilities

81 known vulnerabilities in 16 packages (3 critical, 36 high); 58 can be fixed by upgrading 5 packages. Start with stdlib: upgrade 1.24.6 → 1.25.13 (fixes 45). Rebuilding on the latest base image picks up most OS fixes at once.

Open the full report → Get a fixed image Get a FIPS image Scan your own image

Fix plan for latest-fips

PackageInstalledUpgrade toFixes
stdlib1.24.61.25.1345
golang.org/x/sys0.1.00.44.01
stdlib1.26.51.26.68
golang.org/x/crypto0.54.00.56.03
github.com/klauspost/compress1.18.61.18.71

Critical, high and exploited vulnerabilities in latest-fips

SeverityIDPackageFixed inSummary
criticalGO-2026-4337stdlib 1.24.61.24.13Unexpected session resumption in crypto/tls
criticalGO-2026-5026stdlib 1.24.61.25.13Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
highGO-2026-4341stdlib 1.24.61.24.12Memory exhaustion in query parameter parsing in net/url
highUBUNTU-CVE-2016-20013libc6 2.39-0ubuntu8.9no fix yetsha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password.
highUBUNTU-CVE-2024-26461libgssapi-krb5-2 1.20.1-6ubuntu2.10no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
highUBUNTU-CVE-2024-26461libk5crypto3 1.20.1-6ubuntu2.10no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
highUBUNTU-CVE-2024-26461libkrb5-3 1.20.1-6ubuntu2.10no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
highUBUNTU-CVE-2024-26461libkrb5support0 1.20.1-6ubuntu2.10no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
highGO-2026-4981stdlib 1.24.61.25.10Crash when handling long CNAME response in net
highGO-2026-4986stdlib 1.24.61.25.10Quadratic string concatentation in consumeComment in net/mail
highGO-2026-4601stdlib 1.24.61.25.8Incorrect parsing of IPv6 host literals in net/url
highGO-2026-4977stdlib 1.24.61.25.10Quadratic string concatenation in consumePhrase in net/mail
highGO-2026-4918stdlib 1.24.61.25.10Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net
highGO-2026-4947stdlib 1.24.61.25.9Unexpected work during chain building in crypto/x509
highGO-2026-4870stdlib 1.24.61.25.9Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls

All checked tags

TagFIPSKnown vulnerabilitiesChecked
latest-fipsNot FIPS-readyD 81 3 critical2026-09-27ReportFix