OCImendby CloudTrace

Image reports › public.ecr.aws/q9t5s3a7/vllm-ci-postmerge-repo

public.ecr.aws/q9t5s3a7/vllm-ci-postmerge-repo — vulnerabilities, FIPS 140-3 and fixes

public.ecr.aws/q9t5s3a7/vllm-ci-postmerge-repo · Ubuntu 24.04.4 LTS

Latest: public.ecr.aws/q9t5s3a7/vllm-ci-postmerge-repo:latest · checked 2026-09-30

Not FIPS-ready

No. vllm-ci-postmerge-repo:latest relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: Grade F: 368 known vulnerabilities

368 known vulnerabilities in 109 packages (22 critical, 176 high); 93 can be fixed by upgrading 30 packages. Start with cryptography: upgrade 41.0.7 → 49.0.0 (fixes 9). Rebuilding on the latest base image picks up most OS fixes at once.

Open the full report → Get a fixed image Get a FIPS image Scan your own image

Fix plan for latest

PackageInstalledUpgrade toFixes
cryptography41.0.749.0.09
cryptography46.0.550.0.06
black24.10.026.3.12
PyJWT2.11.02.14.012
PyJWT2.7.02.14.09
anyio4.14.14.14.23
urllib32.2.32.7.06
setuptools77.0.383.0.02

Critical, high and exploited vulnerabilities in latest

SeverityIDPackageFixed inSummary
criticalUBUNTU-CVE-2019-17113libopenmpt0t64 0.7.3-1.1build3no fix yetIn libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and ModPlug_SampleName in libopenmpt_modplug.c do not restrict the lengths of libmodplug output-buffer strings in the C API, leading to a buffer overflow.
criticalUBUNTU-CVE-2021-44732libmbedcrypto7t64 2.28.8-1no fix yetMbed TLS before 3.0.1 has a double free in certain out-of-memory conditions, as demonstrated by an mbedtls_ssl_set_session() failure.
criticalUBUNTU-CVE-2022-35409libmbedcrypto7t64 2.28.8-1no fix yetAn issue was discovered in Mbed TLS before 2.28.1 and 3.x before 3.2.0. In some configurations, an unauthenticated attacker can send an invalid ClientHello message to a DTLS server that causes a heap-based buffer over-read of up to 255 bytes. This can cause a server crash or possibly information dis
criticalUBUNTU-CVE-2022-46393libmbedcrypto7t64 2.28.8-1no fix yetAn issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-read in DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is enabled and MBEDTLS_SSL_CID_IN_LEN_MAX > 2 * MBEDTLS_SSL_CID_OUT_LEN_MAX.
criticalUBUNTU-CVE-2023-45199libmbedcrypto7t64 2.28.8-1no fix yetMbed TLS 3.2.x through 3.4.x before 3.5 has a Buffer Overflow that can lead to remote Code execution.
criticalUBUNTU-CVE-2023-0645libjxl0.7 0.7.0-10.2ubuntu6.1no fix yetAn out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. We recommend upgrading to version 0.8.1 or past commit https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159 https://gith
criticalUBUNTU-CVE-2023-45927libslang2 2.3.3-3build2no fix yetS-Lang 2.3.2 was discovered to contain an arithmetic exception via the function tt_sprintf().
criticalPYSEC-2026-36cryptography 46.0.546.0.7cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Python buffers (e.g. Hash.update()), this could lead to buffer overflows. This vulnerability is fixed in
criticalUBUNTU-CVE-2023-45929libslang2 2.3.3-3build2no fix yetS-Lang 2.3.2 was discovered to contain a segmentation fault via the function fixup_tgetstr().
criticalUBUNTU-CVE-2024-45158libmbedcrypto7t64 2.28.8-1no fix yetAn issue was discovered in Mbed TLS 3.6 before 3.6.1. A stack buffer overflow in mbedtls_ecdsa_der_to_raw() and mbedtls_ecdsa_raw_to_der() can occur when the bits parameter is larger than the largest supported curve. In some configurations with PSA disabled, all values of bits are affected. (This ne
criticalPYSEC-2026-2120black 24.10.026.3.0Black is the uncompromising Python code formatter. Black provides a GitHub action for formatting code. This action supports an option, use_pyproject: true, for reading the version of Black to use from the repository pyproject.toml. A malicious pull request could edit pyproject.toml to use a direct U
criticalUBUNTU-CVE-2024-45159libmbedcrypto7t64 2.28.8-1no fix yetAn issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the client-provided certificate does not have appropriate values in if keyUsage or extKeyUsage extensions, then the return value of mbedtls_ssl_get_verify_result() woul
criticalPYSEC-2026-3554cryptography 41.0.749.0.0python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
criticalPYSEC-2026-3554cryptography 46.0.549.0.0python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees
criticalGHSA-82r6-8w77-94w6anyio 4.14.14.14.2AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing

All checked tags

TagFIPSKnown vulnerabilitiesChecked
latestNot FIPS-readyF 368 22 critical2026-09-30ReportFix