Ocimendby CloudTrace

Image reports › ocimend.io/mysql

ocimend.io/mysql — vulnerabilities, FIPS 140-3 and fixes

ocimend.io/mysql · Oracle Linux Server 9.4

Latest: ocimend.io/mysql:8.0.38-fips · checked 2026-09-26

Not FIPS-ready

No. mysql:8.0.38-fips relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: Grade F: 122 known vulnerabilities, 1 actively exploited

122 known vulnerabilities in 7 packages (11 critical, 54 high); 1 is being actively exploited in the wild; 121 can be fixed by upgrading 6 packages. Start with stdlib: upgrade 1.18.2 → 1.25.13 (fixes 109). Rebuilding on the latest base image picks up most OS fixes at once.

Open the full interactive report → Scan your own image

Fix plan for 8.0.38-fips

PackageInstalledUpgrade toFixes
stdlib1.18.21.25.13109
golang.org/x/sys0.13.00.44.01
cryptography42.0.749.0.07
pyOpenSSL24.1.026.0.02
certifi2024.2.22024.7.41
PyNaCl1.5.01.6.21

Critical, high and exploited vulnerabilities in 8.0.38-fips

SeverityIDPackageFixed inSummary
high exploitedGO-2023-2102stdlib 1.18.21.20.10HTTP/2 rapid reset can cause excessive work in net/http
criticalGO-2023-1703stdlib 1.18.21.19.8Backticks not treated as string delimiters in html/template
criticalGO-2024-2887stdlib 1.18.21.21.11Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netip
criticalGO-2023-1752stdlib 1.18.21.19.9Improper handling of JavaScript whitespace in html/template
criticalGO-2023-1751stdlib 1.18.21.19.9Improper sanitization of CSS values in html/template
criticalGO-2023-1753stdlib 1.18.21.19.9Improper handling of empty HTML attributes in html/template
criticalGO-2026-4337stdlib 1.18.21.24.13Unexpected session resumption in crypto/tls
criticalGO-2025-3563stdlib 1.18.21.23.8Request smuggling due to acceptance of invalid chunked data in net/http
criticalGO-2026-5026stdlib 1.18.21.25.13Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
highGO-2023-1571stdlib 1.18.21.19.6Denial of service via crafted HTTP/2 stream in net/http and golang.org/x/net
highGO-2022-0969stdlib 1.18.21.18.6Denial of service in net/http and golang.org/x/net/http2
highGO-2023-2185stdlib 1.18.21.20.11Insecure parsing of Windows paths with a \??\ prefix in path/filepath
highGO-2022-0537stdlib 1.18.21.18.5Panic when decoding Float and Rat types in math/big
highGO-2026-4341stdlib 1.18.21.24.12Memory exhaustion in query parameter parsing in net/url
highGO-2022-0521stdlib 1.18.21.18.4Stack exhaustion from deeply nested XML documents in encoding/xml

All checked tags

TagFIPSKnown vulnerabilitiesChecked
8.0.38-fipsNot FIPS-readyF 122 11 critical 1 exploited2026-09-26Full report