OCImendby CloudTrace

Image reports › ocimend.io/traefik

ocimend.io/traefik — vulnerabilities, FIPS 140-3 and fixes

ocimend.io/traefik · Alpine Linux v3.21

Latest: ocimend.io/traefik:v3.3.0-fips · checked 2026-09-27

Not FIPS-ready

No. traefik:v3.3.0-fips relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: Grade F: 210 known vulnerabilities

210 known vulnerabilities in 37 packages (17 critical, 83 high); 202 can be fixed by upgrading 36 packages. Start with libcrypto3: upgrade 3.3.2-r4 → 3.3.7-r1 (fixes 31). Rebuilding on the latest base image picks up most OS fixes at once.

Open the full report → Get a fixed image Get a FIPS image Scan your own image

Fix plan for v3.3.0-fips

PackageInstalledUpgrade toFixes
libcrypto33.3.2-r43.3.7-r131
libssl33.3.2-r43.3.7-r131
stdlib1.23.41.25.1355
golang.org/x/crypto0.31.00.56.020
golang.org/x/net0.33.00.56.012
golang.org/x/oauth20.24.00.27.01
github.com/go-jose/go-jose/v44.0.44.1.42
github.com/golang-jwt/jwt/v44.5.14.5.21

Critical, high and exploited vulnerabilities in v3.3.0-fips

SeverityIDPackageFixed inSummary
highALPINE-CVE-2025-15467libcrypto3 3.3.2-r43.3.6-r0Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with
highALPINE-CVE-2025-15467libssl3 3.3.2-r43.3.6-r0Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with
criticalGO-2026-4337stdlib 1.23.41.24.13Unexpected session resumption in crypto/tls
criticalGO-2025-3563stdlib 1.23.41.23.8Request smuggling due to acceptance of invalid chunked data in net/http
criticalGO-2026-5006golang.org/x/crypto 0.31.00.52.0Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent
criticalGO-2026-5026golang.org/x/net 0.33.00.55.0Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
criticalGO-2026-5026stdlib 1.23.41.25.13Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
criticalGO-2026-5021golang.org/x/crypto 0.31.00.52.0Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts
criticalGO-2026-5020golang.org/x/crypto 0.31.00.52.0Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh
criticalGO-2026-5017golang.org/x/crypto 0.31.00.52.0Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh
criticalGO-2026-5023golang.org/x/crypto 0.31.00.52.0Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh
criticalGO-2026-5005golang.org/x/crypto 0.31.00.52.0Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent
criticalGO-2026-5019golang.org/x/crypto 0.31.00.52.0Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh
highGO-2026-4341stdlib 1.23.41.24.12Memory exhaustion in query parameter parsing in net/url
highGO-2025-3487golang.org/x/crypto 0.31.00.35.0Potential denial of service in golang.org/x/crypto

All checked tags

TagFIPSKnown vulnerabilitiesChecked
v3.3.0-fipsNot FIPS-readyF 210 17 critical2026-09-27ReportFix
v3.3.0-fixedNot FIPS-readyF 134 11 critical2026-09-27ReportFix
latest-fipsNot FIPS-readyA 12026-09-27ReportFix