Cryptopsyby CloudTrace

Image reports › mcr.microsoft.com/azurelinux/base/core

mcr.microsoft.com/azurelinux/base/core — vulnerabilities, FIPS 140-3 and fixes

mcr.microsoft.com/azurelinux/base/core · Microsoft Azure Linux 3.0

Latest: mcr.microsoft.com/azurelinux/base/core:3.0.20260909 · checked 2026-09-25

Not FIPS-ready

No. core:3.0.20260909 relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: 30 known vulnerabilities

30 known vulnerabilities in 6 packages (6 high); 30 can be fixed by upgrading 6 packages. Start with libpcre2-16-0: upgrade 10.42-3.azl3 → 10.48-1 (fixes 5). Rebuilding on the latest base image picks up most OS fixes at once.

Open the full interactive report → Scan your own image

Fix plan for 3.0.20260909

PackageInstalledUpgrade toFixes
libpcre2-16-010.42-3.azl310.48-15
libpcre2-32-010.42-3.azl310.48-15
libpcre2-8-010.42-3.azl310.48-15
libpcre2-posix210.42-3.azl310.48-15
pcre210.42-3.azl310.48-15
pcre2-tools10.42-3.azl310.48-15

Critical, high and exploited vulnerabilities in 3.0.20260909

SeverityIDPackageFixed inSummary
highAZL-99726libpcre2-16-0 10.42-3.azl310.48-1CVE-2026-86145 affecting package pcre2 for versions less than 10.48-1
highAZL-99726libpcre2-32-0 10.42-3.azl310.48-1CVE-2026-86145 affecting package pcre2 for versions less than 10.48-1
highAZL-99726libpcre2-8-0 10.42-3.azl310.48-1CVE-2026-86145 affecting package pcre2 for versions less than 10.48-1
highAZL-99726libpcre2-posix2 10.42-3.azl310.48-1CVE-2026-86145 affecting package pcre2 for versions less than 10.48-1
highAZL-99726pcre2 10.42-3.azl310.48-1CVE-2026-86145 affecting package pcre2 for versions less than 10.48-1
highAZL-99726pcre2-tools 10.42-3.azl310.48-1CVE-2026-86145 affecting package pcre2 for versions less than 10.48-1

All checked tags

TagFIPSKnown vulnerabilitiesChecked
3.0.20260909Not FIPS-readyC 302026-09-25Full report