Image reports › ocimend.io/postgres
ocimend.io/postgres — vulnerabilities, FIPS 140-3 and fixes
ocimend.io/postgres · Debian GNU/Linux 13 (trixie)
Latest: ocimend.io/postgres:15.17-fips · checked 2026-09-26
Not FIPS-ready
No. postgres:15.17-fips relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: Grade D: 112 known vulnerabilities
112 known vulnerabilities in 43 packages (2 critical, 26 high); 46 can be fixed by upgrading 2 packages. Start with stdlib: upgrade 1.24.6 → 1.25.13 (fixes 45). Rebuilding on the latest base image picks up most OS fixes at once.
Fix plan for 15.17-fips
| Package | Installed | Upgrade to | Fixes |
|---|---|---|---|
| stdlib | 1.24.6 | 1.25.13 | 45 |
| golang.org/x/sys | 0.1.0 | 0.44.0 | 1 |
Critical, high and exploited vulnerabilities in 15.17-fips
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| critical | GO-2026-4337 | stdlib 1.24.6 | 1.24.13 | Unexpected session resumption in crypto/tls |
| critical | GO-2026-5026 | stdlib 1.24.6 | 1.25.13 | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna |
| high | GO-2026-4341 | stdlib 1.24.6 | 1.24.12 | Memory exhaustion in query parameter parsing in net/url |
| high | CVE-2024-25062 | libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u2 | no fix yet | An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free. |
| high | CVE-2024-26461 | libgssapi-krb5-2 1.21.3-5 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| high | CVE-2024-26461 | libk5crypto3 1.21.3-5 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| high | CVE-2024-26461 | libkrb5-3 1.21.3-5 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| high | CVE-2024-26461 | libkrb5support0 1.21.3-5 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| high | GO-2026-4981 | stdlib 1.24.6 | 1.25.10 | Crash when handling long CNAME response in net |
| high | GO-2026-4918 | stdlib 1.24.6 | 1.25.10 | Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net |
| high | GO-2026-4986 | stdlib 1.24.6 | 1.25.10 | Quadratic string concatentation in consumeComment in net/mail |
| high | GO-2026-4601 | stdlib 1.24.6 | 1.25.8 | Incorrect parsing of IPv6 host literals in net/url |
| high | GO-2026-4977 | stdlib 1.24.6 | 1.25.10 | Quadratic string concatenation in consumePhrase in net/mail |
| high | GO-2026-4947 | stdlib 1.24.6 | 1.25.9 | Unexpected work during chain building in crypto/x509 |
| high | GO-2026-4870 | stdlib 1.24.6 | 1.25.9 | Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| 15.17-fips | Not FIPS-ready | D 112 2 critical | 2026-09-26 | Full report |