Ocimendby CloudTrace

Image reports › ocimend.io/python

ocimend.io/python — vulnerabilities, FIPS 140-3 and fixes

ocimend.io/python · Debian GNU/Linux 12 (bookworm)

Latest: ocimend.io/python:3.11.11-fips · checked 2026-09-26

Not FIPS-ready

No. python:3.11.11-fips relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: Grade D: 927 known vulnerabilities

927 known vulnerabilities in 173 packages (10 critical, 119 high); 10 can be fixed by upgrading 3 packages. Start with setuptools: upgrade 65.5.1 → 83.0.0 (fixes 3). Rebuilding on the latest base image picks up most OS fixes at once.

Open the full interactive report → Scan your own image

Fix plan for 3.11.11-fips

PackageInstalledUpgrade toFixes
setuptools65.5.183.0.03
wheel0.45.10.46.21
pip24.026.26

Critical, high and exploited vulnerabilities in 3.11.11-fips

SeverityIDPackageFixed inSummary
criticalCVE-2024-5535libssl3 3.0.15-1~deb12u1no fix yetIssue summary: Calling the OpenSSL API function SSL_select_next_proto with an
criticalCVE-2023-45853zlib1g 1:1.2.13.dfsg-1no fix yetMiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affe
highCVE-2024-7592libpython3.11-minimal 3.11.2-6+deb12u5no fix yetThere is a LOW severity vulnerability affecting CPython, specifically the
highCVE-2024-7592libpython3.11-stdlib 3.11.2-6+deb12u5no fix yetThere is a LOW severity vulnerability affecting CPython, specifically the
highCVE-2024-6232libpython3.11-minimal 3.11.2-6+deb12u5no fix yetThere is a MEDIUM severity vulnerability affecting CPython.
highCVE-2024-6232libpython3.11-stdlib 3.11.2-6+deb12u5no fix yetThere is a MEDIUM severity vulnerability affecting CPython.
highCVE-2023-52425libexpat1 2.5.0-1+deb12u1no fix yetlibexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed.
highCVE-2023-7104libsqlite3-0 3.40.1-2+deb12u1no fix yetA vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a pa
highCVE-2024-26461libgssapi-krb5-2 1.20.1-2+deb12u2no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
highCVE-2024-26461libk5crypto3 1.20.1-2+deb12u2no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
highCVE-2024-26461libkrb5-3 1.20.1-2+deb12u2no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
highCVE-2024-26461libkrb5support0 1.20.1-2+deb12u2no fix yetKerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.
criticalCVE-2024-5535libssl-dev 3.0.15-1~deb12u1no fix yetIssue summary: Calling the OpenSSL API function SSL_select_next_proto with an
criticalCVE-2024-5535openssl 3.0.15-1~deb12u1no fix yetIssue summary: Calling the OpenSSL API function SSL_select_next_proto with an
criticalCVE-2023-45853zlib1g-dev 1:1.2.13.dfsg-1no fix yetMiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affe

All checked tags

TagFIPSKnown vulnerabilitiesChecked
3.11.11-fipsNot FIPS-readyD 927 10 critical2026-09-26Full report
3.14.0-slim-bookworm-fipsNot FIPS-readyB 59 3 critical2026-09-26Full report