Cryptopsyby CloudTrace

Image reports › node

node — vulnerabilities, FIPS 140-3 and fixes

docker.io/library/node · Alpine Linux v3.24

Latest: node:22-alpine · checked 2026-09-25

Not FIPS-ready

No. node:22-alpine relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: Grade C: 13 known vulnerabilities

13 known vulnerabilities in 7 packages (7 high); 13 can be fixed by upgrading 8 packages. Start with brace-expansion: upgrade 2.0.2 → 2.1.4 (fixes 4). Rebuilding on the latest base image picks up most OS fixes at once.

Open the full interactive report → Scan your own image

Fix plan for 22-alpine

PackageInstalledUpgrade toFixes
brace-expansion2.0.22.1.44
ip-address10.1.010.3.12
picomatch4.0.34.0.42
pacote20.0.121.5.11
pacote19.0.221.5.11
sigstore3.1.04.1.11
@sigstore/core2.0.03.2.11
postcss-selector-parser7.1.17.1.31

Critical, high and exploited vulnerabilities in 22-alpine

SeverityIDPackageFixed inSummary
highGHSA-mh99-v99m-4gvgbrace-expansion 2.0.22.1.3brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
highGHSA-rgw5-rvv9-x895brace-expansion 2.0.22.1.4brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation
highGHSA-w4pp-8pjf-rmxwpacote 20.0.121.5.1pacote is vulnerable to Denial of Service (DoS) via the addGitSha function
highGHSA-w4pp-8pjf-rmxwpacote 19.0.221.5.1pacote is vulnerable to Denial of Service (DoS) via the addGitSha function
highGHSA-c2c7-rcm5-vvqjpicomatch 4.0.34.0.4Picomatch has a ReDoS vulnerability via extglob quantifiers
highGHSA-52v5-jr5w-gjxrsigstore 3.1.04.1.1sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced
highGHSA-mwp4-54f8-5fhrip-address 10.1.010.3.1ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass

All checked tags

TagFIPSKnown vulnerabilitiesChecked
22-alpineNot FIPS-readyC 132026-09-25Full report