Image reports › ocimend.io/mysql
ocimend.io/mysql — vulnerabilities, FIPS 140-3 and fixes
ocimend.io/mysql · Oracle Linux Server 9.4
Latest: ocimend.io/mysql:8.0.38-fips · checked 2026-09-26
Not FIPS-ready
No. mysql:8.0.38-fips relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: Grade F: 122 known vulnerabilities, 1 actively exploited
122 known vulnerabilities in 7 packages (11 critical, 54 high); 1 is being actively exploited in the wild; 121 can be fixed by upgrading 6 packages. Start with stdlib: upgrade 1.18.2 → 1.25.13 (fixes 109). Rebuilding on the latest base image picks up most OS fixes at once.
Fix plan for 8.0.38-fips
| Package | Installed | Upgrade to | Fixes |
|---|---|---|---|
| stdlib | 1.18.2 | 1.25.13 | 109 |
| golang.org/x/sys | 0.13.0 | 0.44.0 | 1 |
| cryptography | 42.0.7 | 49.0.0 | 7 |
| pyOpenSSL | 24.1.0 | 26.0.0 | 2 |
| certifi | 2024.2.2 | 2024.7.4 | 1 |
| PyNaCl | 1.5.0 | 1.6.2 | 1 |
Critical, high and exploited vulnerabilities in 8.0.38-fips
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| high exploited | GO-2023-2102 | stdlib 1.18.2 | 1.20.10 | HTTP/2 rapid reset can cause excessive work in net/http |
| critical | GO-2023-1703 | stdlib 1.18.2 | 1.19.8 | Backticks not treated as string delimiters in html/template |
| critical | GO-2024-2887 | stdlib 1.18.2 | 1.21.11 | Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netip |
| critical | GO-2023-1752 | stdlib 1.18.2 | 1.19.9 | Improper handling of JavaScript whitespace in html/template |
| critical | GO-2023-1751 | stdlib 1.18.2 | 1.19.9 | Improper sanitization of CSS values in html/template |
| critical | GO-2023-1753 | stdlib 1.18.2 | 1.19.9 | Improper handling of empty HTML attributes in html/template |
| critical | GO-2026-4337 | stdlib 1.18.2 | 1.24.13 | Unexpected session resumption in crypto/tls |
| critical | GO-2025-3563 | stdlib 1.18.2 | 1.23.8 | Request smuggling due to acceptance of invalid chunked data in net/http |
| critical | GO-2026-5026 | stdlib 1.18.2 | 1.25.13 | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna |
| high | GO-2023-1571 | stdlib 1.18.2 | 1.19.6 | Denial of service via crafted HTTP/2 stream in net/http and golang.org/x/net |
| high | GO-2022-0969 | stdlib 1.18.2 | 1.18.6 | Denial of service in net/http and golang.org/x/net/http2 |
| high | GO-2023-2185 | stdlib 1.18.2 | 1.20.11 | Insecure parsing of Windows paths with a \??\ prefix in path/filepath |
| high | GO-2022-0537 | stdlib 1.18.2 | 1.18.5 | Panic when decoding Float and Rat types in math/big |
| high | GO-2026-4341 | stdlib 1.18.2 | 1.24.12 | Memory exhaustion in query parameter parsing in net/url |
| high | GO-2022-0521 | stdlib 1.18.2 | 1.18.4 | Stack exhaustion from deeply nested XML documents in encoding/xml |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| 8.0.38-fips | Not FIPS-ready | F 122 11 critical 1 exploited | 2026-09-26 | Full report |