Image reports › ocimend.io/ubuntu/go
ocimend.io/ubuntu/go — vulnerabilities, FIPS 140-3 and fixes
ocimend.io/ubuntu/go · Ubuntu 26.04 LTS
Latest: ocimend.io/ubuntu/go:1.26-26.04-fixed · checked 2026-09-28
Not FIPS-ready
No. go:1.26-26.04-fixed relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: Grade F: 147 known vulnerabilities
147 known vulnerabilities in 25 packages (9 critical, 41 high); 85 can be fixed by upgrading 21 packages. Start with libssl3t64: upgrade 3.5.5-1ubuntu3.2 → 3.5.5-1ubuntu3.4 (fixes 2). Rebuilding on the latest base image picks up most OS fixes at once.
Open the full report → Get a fixed image Get a FIPS image Scan your own image
Fix plan for 1.26-26.04-fixed
| Package | Installed | Upgrade to | Fixes |
|---|---|---|---|
| libssl3t64 | 3.5.5-1ubuntu3.2 | 3.5.5-1ubuntu3.4 | 2 |
| openssl | 3.5.5-1ubuntu3.2 | 3.5.5-1ubuntu3.4 | 2 |
| openssl-provider-legacy | 3.5.5-1ubuntu3.2 | 3.5.5-1ubuntu3.4 | 2 |
| wget | 1.25.0-2ubuntu4 | 1.25.0-2ubuntu4.4 | 3 |
| stdlib | 1.26.0 | 1.26.6 | 33 |
| golang.org/x/net | 0.40.0 | 0.56.0 | 10 |
| libc-bin | 2.43-2ubuntu2 | 2.43-2ubuntu2.4 | 2 |
| libc6 | 2.43-2ubuntu2 | 2.43-2ubuntu2.4 | 2 |
Critical, high and exploited vulnerabilities in 1.26-26.04-fixed
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| critical | USN-8678-1 | libssl3t64 3.5.5-1ubuntu3.2 | 3.5.5-1ubuntu3.4 | openssl vulnerabilities |
| critical | USN-8678-1 | openssl 3.5.5-1ubuntu3.2 | 3.5.5-1ubuntu3.4 | openssl vulnerabilities |
| critical | USN-8678-1 | openssl-provider-legacy 3.5.5-1ubuntu3.2 | 3.5.5-1ubuntu3.4 | openssl vulnerabilities |
| critical | USN-8611-1 | libc-bin 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc vulnerabilities |
| critical | USN-8611-1 | libc6 2.43-2ubuntu2 | 2.43-2ubuntu2.3 | glibc vulnerabilities |
| critical | GO-2026-5026 | golang.org/x/net 0.40.0 | 0.55.0 | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna |
| critical | GO-2026-5026 | stdlib 1.26.4 | 1.26.6 | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna |
| critical | GO-2026-5026 | stdlib 1.26.0 | 1.26.6 | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna |
| critical | USN-8543-1 | wget 1.25.0-2ubuntu4 | 1.25.0-2ubuntu4.2 | wget vulnerabilities |
| high | GO-2026-4981 | stdlib 1.26.0 | 1.26.3 | Crash when handling long CNAME response in net |
| high | GO-2026-4986 | stdlib 1.26.0 | 1.26.3 | Quadratic string concatentation in consumeComment in net/mail |
| high | GO-2026-4601 | stdlib 1.26.0 | 1.26.1 | Incorrect parsing of IPv6 host literals in net/url |
| high | GO-2026-4977 | stdlib 1.26.0 | 1.26.3 | Quadratic string concatenation in consumePhrase in net/mail |
| high | GO-2026-4918 | golang.org/x/net 0.40.0 | 0.53.0 | Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net |
| high | GO-2026-4918 | stdlib 1.26.0 | 1.26.3 | Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| 1.26-26.04-fixed | Not FIPS-ready | F 147 9 critical | 2026-09-28 | ReportFix |