Image reports › node
node — vulnerabilities, FIPS 140-3 and fixes
docker.io/library/node · Alpine Linux v3.24
Latest: node:22-alpine · checked 2026-09-25
Not FIPS-ready
No. node:22-alpine relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: Grade C: 13 known vulnerabilities
13 known vulnerabilities in 7 packages (7 high); 13 can be fixed by upgrading 8 packages. Start with brace-expansion: upgrade 2.0.2 → 2.1.4 (fixes 4). Rebuilding on the latest base image picks up most OS fixes at once.
Fix plan for 22-alpine
| Package | Installed | Upgrade to | Fixes |
|---|---|---|---|
| brace-expansion | 2.0.2 | 2.1.4 | 4 |
| ip-address | 10.1.0 | 10.3.1 | 2 |
| picomatch | 4.0.3 | 4.0.4 | 2 |
| pacote | 20.0.1 | 21.5.1 | 1 |
| pacote | 19.0.2 | 21.5.1 | 1 |
| sigstore | 3.1.0 | 4.1.1 | 1 |
| @sigstore/core | 2.0.0 | 3.2.1 | 1 |
| postcss-selector-parser | 7.1.1 | 7.1.3 | 1 |
Critical, high and exploited vulnerabilities in 22-alpine
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| high | GHSA-mh99-v99m-4gvg | brace-expansion 2.0.2 | 2.1.3 | brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash |
| high | GHSA-rgw5-rvv9-x895 | brace-expansion 2.0.2 | 2.1.4 | brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation |
| high | GHSA-w4pp-8pjf-rmxw | pacote 20.0.1 | 21.5.1 | pacote is vulnerable to Denial of Service (DoS) via the addGitSha function |
| high | GHSA-w4pp-8pjf-rmxw | pacote 19.0.2 | 21.5.1 | pacote is vulnerable to Denial of Service (DoS) via the addGitSha function |
| high | GHSA-c2c7-rcm5-vvqj | picomatch 4.0.3 | 4.0.4 | Picomatch has a ReDoS vulnerability via extglob quantifiers |
| high | GHSA-52v5-jr5w-gjxr | sigstore 3.1.0 | 4.1.1 | sigstore's `certificateOIDs` verification constraints are silently dropped and never enforced |
| high | GHSA-mwp4-54f8-5fhr | ip-address 10.1.0 | 10.3.1 | ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| 22-alpine | Not FIPS-ready | C 13 | 2026-09-25 | Full report |