OCImendby CloudTrace

Image reports › ocimend.io/node

ocimend.io/node — vulnerabilities, FIPS 140-3 and fixes

ocimend.io/node · Alpine Linux v3.17

Latest: ocimend.io/node:18.13-alpine-fixed · checked 2026-09-28

Not FIPS-ready

No. node:18.13-alpine-fixed relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: Grade B: 36 known vulnerabilities

36 known vulnerabilities in 9 packages (23 high); 35 can be fixed by upgrading 11 packages; the operating system (Alpine Linux v3.17) no longer receives security fixes. Start with ip: upgrade 2.0.0 → 2.0.1 (fixes 1). Rebuilding on the latest base image picks up most OS fixes at once.

Open the full report → Get a fixed image Get a FIPS image Scan your own image

Fix plan for 18.13-alpine-fixed

PackageInstalledUpgrade toFixes
ip2.0.02.0.11
semver7.3.77.5.21
http-cache-semantics4.1.04.1.11
tar6.1.117.5.2113
brace-expansion2.0.12.1.45
brace-expansion1.1.111.1.185
pacote13.6.221.5.11
minimatch5.1.05.1.83

Critical, high and exploited vulnerabilities in 18.13-alpine-fixed

SeverityIDPackageFixed inSummary
highGHSA-2p57-rm9w-gvfpip 2.0.0no fix yetip SSRF improper categorization in isPublic
highGHSA-c2qf-rxjj-qqgwsemver 7.3.77.5.2semver vulnerable to Regular Expression Denial of Service
highGHSA-rc47-6667-2j5jhttp-cache-semantics 4.1.04.1.1http-cache-semantics vulnerable to Regular Expression Denial of Service
highGHSA-rgw5-rvv9-x895brace-expansion 2.0.12.1.4brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
highGHSA-rgw5-rvv9-x895brace-expansion 1.1.111.1.18brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
highGHSA-23hp-3jrh-7fpwtar 6.1.117.5.19node-tar: Decompression/parse DoS via unlimited input
highGHSA-8x88-c5mf-7j5wtar 6.1.117.5.18node-tar: Negative tar entry size causes infinite loop in archive replace
highGHSA-mh99-v99m-4gvgbrace-expansion 2.0.12.1.3brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
highGHSA-mh99-v99m-4gvgbrace-expansion 1.1.111.1.17brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
highGHSA-w4pp-8pjf-rmxwpacote 13.6.221.5.1pacote is vulnerable to Denial of Service (DoS) via the addGitSha function
highGHSA-34x7-hfp2-rc4vtar 6.1.117.5.7node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal
highGHSA-7r86-cg39-jmmjminimatch 5.1.05.1.8minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
highGHSA-7r86-cg39-jmmjminimatch 3.1.23.1.3minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments
highGHSA-3ppc-4f35-3m26minimatch 5.1.05.1.7minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
highGHSA-3ppc-4f35-3m26minimatch 3.1.23.1.3minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern

All checked tags

TagFIPSKnown vulnerabilitiesChecked
18.13-alpine-fixedNot FIPS-readyB 362026-09-28ReportFix
22.17-alpine3.21-fixedNot FIPS-readyA 412026-09-28ReportFix