Ocimendby CloudTrace

Image reports › ocimend.io/postgres

ocimend.io/postgres — vulnerabilities, FIPS 140-3 and fixes

ocimend.io/postgres · Debian GNU/Linux 13 (trixie)

Latest: ocimend.io/postgres:15.17-fips · checked 2026-09-26

Not FIPS-ready

No. postgres:15.17-fips relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: Grade D: 112 known vulnerabilities

112 known vulnerabilities in 43 packages (2 critical, 26 high); 46 can be fixed by upgrading 2 packages. Start with stdlib: upgrade 1.24.6 → 1.25.13 (fixes 45). Rebuilding on the latest base image picks up most OS fixes at once.

Open the full interactive report → Scan your own image

Fix plan for 15.17-fips

PackageInstalledUpgrade toFixes
stdlib1.24.61.25.1345
golang.org/x/sys0.1.00.44.01

Critical, high and exploited vulnerabilities in 15.17-fips

SeverityIDPackageFixed inSummary
criticalGO-2026-4337stdlib 1.24.61.24.13Unexpected session resumption in crypto/tls
criticalGO-2026-5026stdlib 1.24.61.25.13Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
highGO-2026-4341stdlib 1.24.61.24.12Memory exhaustion in query parameter parsing in net/url
highCVE-2024-25062libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u2no fix yetAn issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free.
highCVE-2024-26461libgssapi-krb5-2 1.21.3-5no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
highCVE-2024-26461libk5crypto3 1.21.3-5no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
highCVE-2024-26461libkrb5-3 1.21.3-5no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
highCVE-2024-26461libkrb5support0 1.21.3-5no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
highGO-2026-4981stdlib 1.24.61.25.10Crash when handling long CNAME response in net
highGO-2026-4918stdlib 1.24.61.25.10Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net
highGO-2026-4986stdlib 1.24.61.25.10Quadratic string concatentation in consumeComment in net/mail
highGO-2026-4601stdlib 1.24.61.25.8Incorrect parsing of IPv6 host literals in net/url
highGO-2026-4977stdlib 1.24.61.25.10Quadratic string concatenation in consumePhrase in net/mail
highGO-2026-4947stdlib 1.24.61.25.9Unexpected work during chain building in crypto/x509
highGO-2026-4870stdlib 1.24.61.25.9Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls

All checked tags

TagFIPSKnown vulnerabilitiesChecked
15.17-fipsNot FIPS-readyD 112 2 critical2026-09-26Full report