Image reports › ocimend.io/node
ocimend.io/node — vulnerabilities, FIPS 140-3 and fixes
ocimend.io/node · Alpine Linux v3.17
Latest: ocimend.io/node:18.13-alpine-fixed · checked 2026-09-28
Not FIPS-ready
No. node:18.13-alpine-fixed relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: Grade B: 36 known vulnerabilities
36 known vulnerabilities in 9 packages (23 high); 35 can be fixed by upgrading 11 packages; the operating system (Alpine Linux v3.17) no longer receives security fixes. Start with ip: upgrade 2.0.0 → 2.0.1 (fixes 1). Rebuilding on the latest base image picks up most OS fixes at once.
Open the full report → Get a fixed image Get a FIPS image Scan your own image
Fix plan for 18.13-alpine-fixed
| Package | Installed | Upgrade to | Fixes |
|---|---|---|---|
| ip | 2.0.0 | 2.0.1 | 1 |
| semver | 7.3.7 | 7.5.2 | 1 |
| http-cache-semantics | 4.1.0 | 4.1.1 | 1 |
| tar | 6.1.11 | 7.5.21 | 13 |
| brace-expansion | 2.0.1 | 2.1.4 | 5 |
| brace-expansion | 1.1.11 | 1.1.18 | 5 |
| pacote | 13.6.2 | 21.5.1 | 1 |
| minimatch | 5.1.0 | 5.1.8 | 3 |
Critical, high and exploited vulnerabilities in 18.13-alpine-fixed
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| high | GHSA-2p57-rm9w-gvfp | ip 2.0.0 | no fix yet | ip SSRF improper categorization in isPublic |
| high | GHSA-c2qf-rxjj-qqgw | semver 7.3.7 | 7.5.2 | semver vulnerable to Regular Expression Denial of Service |
| high | GHSA-rc47-6667-2j5j | http-cache-semantics 4.1.0 | 4.1.1 | http-cache-semantics vulnerable to Regular Expression Denial of Service |
| high | GHSA-rgw5-rvv9-x895 | brace-expansion 2.0.1 | 2.1.4 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation |
| high | GHSA-rgw5-rvv9-x895 | brace-expansion 1.1.11 | 1.1.18 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation |
| high | GHSA-23hp-3jrh-7fpw | tar 6.1.11 | 7.5.19 | node-tar: Decompression/parse DoS via unlimited input |
| high | GHSA-8x88-c5mf-7j5w | tar 6.1.11 | 7.5.18 | node-tar: Negative tar entry size causes infinite loop in archive replace |
| high | GHSA-mh99-v99m-4gvg | brace-expansion 2.0.1 | 2.1.3 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash |
| high | GHSA-mh99-v99m-4gvg | brace-expansion 1.1.11 | 1.1.17 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash |
| high | GHSA-w4pp-8pjf-rmxw | pacote 13.6.2 | 21.5.1 | pacote is vulnerable to Denial of Service (DoS) via the addGitSha function |
| high | GHSA-34x7-hfp2-rc4v | tar 6.1.11 | 7.5.7 | node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal |
| high | GHSA-7r86-cg39-jmmj | minimatch 5.1.0 | 5.1.8 | minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments |
| high | GHSA-7r86-cg39-jmmj | minimatch 3.1.2 | 3.1.3 | minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adjacent GLOBSTAR segments |
| high | GHSA-3ppc-4f35-3m26 | minimatch 5.1.0 | 5.1.7 | minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern |
| high | GHSA-3ppc-4f35-3m26 | minimatch 3.1.2 | 3.1.3 | minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| 18.13-alpine-fixed | Not FIPS-ready | B 36 | 2026-09-28 | ReportFix |
| 22.17-alpine3.21-fixed | Not FIPS-ready | A 41 | 2026-09-28 | ReportFix |