OCImendby CloudTrace

Image reports › ocimend.io/registry.access.redhat.com/ubi9/ubi

ocimend.io/registry.access.redhat.com/ubi9/ubi — vulnerabilities, FIPS 140-3 and fixes

ocimend.io/registry.access.redhat.com/ubi9/ubi · Red Hat Enterprise Linux 9.8 (Plow)

Latest: ocimend.io/registry.access.redhat.com/ubi9/ubi:latest-fips · checked 2026-09-27

FIPS-ready, confirmed by a live test

Yes. ubi:latest-fips uses certified crypto, FIPS mode is switched on, and a live test inside the running image confirmed that non-approved algorithms are refused.

Security: Grade C: 19 known vulnerabilities

19 known vulnerabilities in 5 packages (8 high); 19 can be fixed by upgrading 5 packages. Start with urllib3: upgrade 1.26.5 → 2.7.0 (fixes 8). Rebuilding on the latest base image picks up most OS fixes at once.

Open the full report → Get a fixed image Get a FIPS image Scan your own image

Fix plan for latest-fips

PackageInstalledUpgrade toFixes
urllib31.26.52.7.08
setuptools53.0.083.0.04
idna2.103.152
libxml22.9.13-14.el9_8.40:2.9.13-14.el9_8.51
requests2.25.12.33.04

Critical, high and exploited vulnerabilities in latest-fips

SeverityIDPackageFixed inSummary
highPYSEC-2026-1996urllib3 1.26.52.6.3Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
highPYSEC-2026-1918setuptools 53.0.070.0.0setuptools vulnerable to Command Injection via package URL
highPYSEC-2025-49setuptools 53.0.078.1.1setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with
highPYSEC-2024-60idna 2.103.7A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting version 3.6. The issue arises from the function's handling of crafted input strings, which can lead to quadratic complexity and consequently, a denial of service condition. This vulner
highPYSEC-2023-192urllib3 1.26.51.26.17urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak inform
highPYSEC-2026-1994urllib3 1.26.52.6.0urllib3 streaming API improperly handles highly compressed data
highPYSEC-2026-1998urllib3 1.26.52.6.0urllib3 allows an unbounded number of links in the decompression chain
highRHSA-2026:71585libxml2 2.9.13-14.el9_8.40:2.9.13-14.el9_8.5Red Hat Security Advisory: libxml2 security update

All checked tags

TagFIPSKnown vulnerabilitiesChecked
latest-fipsFIPS-readyC 192026-09-27ReportFix