Image reports › ocimend.io/python
ocimend.io/python — vulnerabilities, FIPS 140-3 and fixes
ocimend.io/python · Debian GNU/Linux 12 (bookworm)
Latest: ocimend.io/python:3.11.11-fips · checked 2026-09-26
Not FIPS-ready
No. python:3.11.11-fips relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: Grade D: 927 known vulnerabilities
927 known vulnerabilities in 173 packages (10 critical, 119 high); 10 can be fixed by upgrading 3 packages. Start with setuptools: upgrade 65.5.1 → 83.0.0 (fixes 3). Rebuilding on the latest base image picks up most OS fixes at once.
Fix plan for 3.11.11-fips
| Package | Installed | Upgrade to | Fixes |
|---|---|---|---|
| setuptools | 65.5.1 | 83.0.0 | 3 |
| wheel | 0.45.1 | 0.46.2 | 1 |
| pip | 24.0 | 26.2 | 6 |
Critical, high and exploited vulnerabilities in 3.11.11-fips
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| critical | CVE-2024-5535 | libssl3 3.0.15-1~deb12u1 | no fix yet | Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an |
| critical | CVE-2023-45853 | zlib1g 1:1.2.13.dfsg-1 | no fix yet | MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affe |
| high | CVE-2024-7592 | libpython3.11-minimal 3.11.2-6+deb12u5 | no fix yet | There is a LOW severity vulnerability affecting CPython, specifically the |
| high | CVE-2024-7592 | libpython3.11-stdlib 3.11.2-6+deb12u5 | no fix yet | There is a LOW severity vulnerability affecting CPython, specifically the |
| high | CVE-2024-6232 | libpython3.11-minimal 3.11.2-6+deb12u5 | no fix yet | There is a MEDIUM severity vulnerability affecting CPython. |
| high | CVE-2024-6232 | libpython3.11-stdlib 3.11.2-6+deb12u5 | no fix yet | There is a MEDIUM severity vulnerability affecting CPython. |
| high | CVE-2023-52425 | libexpat1 2.5.0-1+deb12u1 | no fix yet | libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed. |
| high | CVE-2023-7104 | libsqlite3-0 3.40.1-2+deb12u1 | no fix yet | A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file ext/session/sqlite3session.c of the component make alltest Handler. The manipulation leads to heap-based buffer overflow. It is recommended to apply a pa |
| high | CVE-2024-26461 | libgssapi-krb5-2 1.20.1-2+deb12u2 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| high | CVE-2024-26461 | libk5crypto3 1.20.1-2+deb12u2 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| high | CVE-2024-26461 | libkrb5-3 1.20.1-2+deb12u2 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| high | CVE-2024-26461 | libkrb5support0 1.20.1-2+deb12u2 | no fix yet | Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c. |
| critical | CVE-2024-5535 | libssl-dev 3.0.15-1~deb12u1 | no fix yet | Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an |
| critical | CVE-2024-5535 | openssl 3.0.15-1~deb12u1 | no fix yet | Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an |
| critical | CVE-2023-45853 | zlib1g-dev 1:1.2.13.dfsg-1 | no fix yet | MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affe |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| 3.11.11-fips | Not FIPS-ready | D 927 10 critical | 2026-09-26 | Full report |
| 3.14.0-slim-bookworm-fips | Not FIPS-ready | B 59 3 critical | 2026-09-26 | Full report |