Image reports › ocimend.io/traefik
ocimend.io/traefik — vulnerabilities, FIPS 140-3 and fixes
ocimend.io/traefik · Alpine Linux v3.21
Latest: ocimend.io/traefik:v3.3.0-fips · checked 2026-09-27
Not FIPS-ready
No. traefik:v3.3.0-fips relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: Grade F: 210 known vulnerabilities
210 known vulnerabilities in 37 packages (17 critical, 83 high); 202 can be fixed by upgrading 36 packages. Start with libcrypto3: upgrade 3.3.2-r4 → 3.3.7-r1 (fixes 31). Rebuilding on the latest base image picks up most OS fixes at once.
Open the full report → Get a fixed image Get a FIPS image Scan your own image
Fix plan for v3.3.0-fips
| Package | Installed | Upgrade to | Fixes |
|---|---|---|---|
| libcrypto3 | 3.3.2-r4 | 3.3.7-r1 | 31 |
| libssl3 | 3.3.2-r4 | 3.3.7-r1 | 31 |
| stdlib | 1.23.4 | 1.25.13 | 55 |
| golang.org/x/crypto | 0.31.0 | 0.56.0 | 20 |
| golang.org/x/net | 0.33.0 | 0.56.0 | 12 |
| golang.org/x/oauth2 | 0.24.0 | 0.27.0 | 1 |
| github.com/go-jose/go-jose/v4 | 4.0.4 | 4.1.4 | 2 |
| github.com/golang-jwt/jwt/v4 | 4.5.1 | 4.5.2 | 1 |
Critical, high and exploited vulnerabilities in v3.3.0-fips
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| high | ALPINE-CVE-2025-15467 | libcrypto3 3.3.2-r4 | 3.3.6-r0 | Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with |
| high | ALPINE-CVE-2025-15467 | libssl3 3.3.2-r4 | 3.3.6-r0 | Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with |
| critical | GO-2026-4337 | stdlib 1.23.4 | 1.24.13 | Unexpected session resumption in crypto/tls |
| critical | GO-2025-3563 | stdlib 1.23.4 | 1.23.8 | Request smuggling due to acceptance of invalid chunked data in net/http |
| critical | GO-2026-5006 | golang.org/x/crypto 0.31.0 | 0.52.0 | Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent |
| critical | GO-2026-5026 | golang.org/x/net 0.33.0 | 0.55.0 | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna |
| critical | GO-2026-5026 | stdlib 1.23.4 | 1.25.13 | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna |
| critical | GO-2026-5021 | golang.org/x/crypto 0.31.0 | 0.52.0 | Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts |
| critical | GO-2026-5020 | golang.org/x/crypto 0.31.0 | 0.52.0 | Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh |
| critical | GO-2026-5017 | golang.org/x/crypto 0.31.0 | 0.52.0 | Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh |
| critical | GO-2026-5023 | golang.org/x/crypto 0.31.0 | 0.52.0 | Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh |
| critical | GO-2026-5005 | golang.org/x/crypto 0.31.0 | 0.52.0 | Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent |
| critical | GO-2026-5019 | golang.org/x/crypto 0.31.0 | 0.52.0 | Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh |
| high | GO-2026-4341 | stdlib 1.23.4 | 1.24.12 | Memory exhaustion in query parameter parsing in net/url |
| high | GO-2025-3487 | golang.org/x/crypto 0.31.0 | 0.35.0 | Potential denial of service in golang.org/x/crypto |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| v3.3.0-fips | Not FIPS-ready | F 210 17 critical | 2026-09-27 | ReportFix |
| v3.3.0-fixed | Not FIPS-ready | F 134 11 critical | 2026-09-27 | ReportFix |
| latest-fips | Not FIPS-ready | A 1 | 2026-09-27 | ReportFix |