Image reports › public.ecr.aws/q9t5s3a7/vllm-ci-postmerge-repo
public.ecr.aws/q9t5s3a7/vllm-ci-postmerge-repo — vulnerabilities, FIPS 140-3 and fixes
public.ecr.aws/q9t5s3a7/vllm-ci-postmerge-repo · Ubuntu 24.04.4 LTS
Latest: public.ecr.aws/q9t5s3a7/vllm-ci-postmerge-repo:latest · checked 2026-09-30
Not FIPS-ready
No. vllm-ci-postmerge-repo:latest relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: Grade F: 368 known vulnerabilities
368 known vulnerabilities in 109 packages (22 critical, 176 high); 93 can be fixed by upgrading 30 packages. Start with cryptography: upgrade 41.0.7 → 49.0.0 (fixes 9). Rebuilding on the latest base image picks up most OS fixes at once.
Open the full report → Get a fixed image Get a FIPS image Scan your own image
Fix plan for latest
| Package | Installed | Upgrade to | Fixes |
|---|---|---|---|
| cryptography | 41.0.7 | 49.0.0 | 9 |
| cryptography | 46.0.5 | 50.0.0 | 6 |
| black | 24.10.0 | 26.3.1 | 2 |
| PyJWT | 2.11.0 | 2.14.0 | 12 |
| PyJWT | 2.7.0 | 2.14.0 | 9 |
| anyio | 4.14.1 | 4.14.2 | 3 |
| urllib3 | 2.2.3 | 2.7.0 | 6 |
| setuptools | 77.0.3 | 83.0.0 | 2 |
Critical, high and exploited vulnerabilities in latest
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| critical | UBUNTU-CVE-2019-17113 | libopenmpt0t64 0.7.3-1.1build3 | no fix yet | In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and ModPlug_SampleName in libopenmpt_modplug.c do not restrict the lengths of libmodplug output-buffer strings in the C API, leading to a buffer overflow. |
| critical | UBUNTU-CVE-2021-44732 | libmbedcrypto7t64 2.28.8-1 | no fix yet | Mbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure. |
| critical | UBUNTU-CVE-2022-35409 | libmbedcrypto7t64 2.28.8-1 | no fix yet | An issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attacker can send an invalid ClientHello message to a DTLS server that causes a heap-based buffer over-read of up to 255 bytes. This can cause a server crash or possibly information dis |
| critical | UBUNTU-CVE-2022-46393 | libmbedcrypto7t64 2.28.8-1 | no fix yet | An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-read in DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is enabled and MBEDTLS_SSL_CID_IN_LEN_MAX > 2 * MBEDTLS_SSL_CID_OUT_LEN_MAX. |
| critical | UBUNTU-CVE-2023-45199 | libmbedcrypto7t64 2.28.8-1 | no fix yet | Mbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution. |
| critical | UBUNTU-CVE-2023-0645 | libjxl0.7 0.7.0-10.2ubuntu6.1 | no fix yet | An out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. We recommend upgrading to version 0.8.1 or past commit https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159 https://gith |
| critical | UBUNTU-CVE-2023-45927 | libslang2 2.3.3-3build2 | no fix yet | S-Lang 2.3.2 was discovered to contain an arithmetic exception via the function tt_sprintf(). |
| critical | PYSEC-2026-36 | cryptography 46.0.5 | 46.0.7 | cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in |
| critical | UBUNTU-CVE-2023-45929 | libslang2 2.3.3-3build2 | no fix yet | S-Lang 2.3.2 was discovered to contain a segmentation fault via the function fixup_tgetstr(). |
| critical | UBUNTU-CVE-2024-45158 | libmbedcrypto7t64 2.28.8-1 | no fix yet | An issue was discovered in Mbed TLS 3.6 before 3.6.1. A stack buffer overflow in mbedtls_ecdsa_der_to_raw() and mbedtls_ecdsa_raw_to_der() can occur when the bits parameter is larger than the largest supported curve. In some configurations with PSA disabled, all values of bits are affected. (This ne |
| critical | PYSEC-2026-2120 | black 24.10.0 | 26.3.0 | Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject: true, for reading the version of Black to use from the repository pyproject.toml. A malicious pull request could edit pyproject.toml to use a direct U |
| critical | UBUNTU-CVE-2024-45159 | libmbedcrypto7t64 2.28.8-1 | no fix yet | An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the client-provided certificate does not have appropriate values in if keyUsage or extKeyUsage extensions, then the return value of mbedtls_ssl_get_verify_result() woul |
| critical | PYSEC-2026-3554 | cryptography 41.0.7 | 49.0.0 | python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees |
| critical | PYSEC-2026-3554 | cryptography 46.0.5 | 49.0.0 | python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees |
| critical | GHSA-82r6-8w77-94w6 | anyio 4.14.1 | 4.14.2 | AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing |