Image reports › mcr.microsoft.com/oss/go/microsoft/golang
mcr.microsoft.com/oss/go/microsoft/golang — vulnerabilities, FIPS 140-3 and fixes
mcr.microsoft.com/oss/go/microsoft/golang · Debian GNU/Linux 12 (bookworm)
Latest: mcr.microsoft.com/oss/go/microsoft/golang:latest · checked 2026-09-25
Not FIPS-ready
No. golang:latest relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: 569 known vulnerabilities
569 known vulnerabilities in 94 packages (5 critical, 88 high); none has a fix available yet.
Critical, high and exploited vulnerabilities in latest
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| critical | CVE-2024-38541 | linux-libc-dev 6.1.187-1 | no fix yet | In the Linux kernel, the following vulnerability has been resolved: |
| critical | CVE-2023-45853 | zlib1g 1:1.2.13.dfsg-1 | no fix yet | MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affe |
| critical | CVE-2024-5535 | libssl3 3.0.20-1~deb12u2 | no fix yet | Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an |
| critical | CVE-2024-5535 | openssl 3.0.20-1~deb12u2 | no fix yet | Issue summary: Calling the OpenSSL API function SSL_select_next_proto with an |
| critical | CVE-2024-38428 | wget 1.21.3-1+deb12u1 | no fix yet | url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent. |
| high | CVE-2023-52629 | linux-libc-dev 6.1.187-1 | no fix yet | In the Linux kernel, the following vulnerability has been resolved: |
| high | CVE-2024-26945 | linux-libc-dev 6.1.187-1 | no fix yet | In the Linux kernel, the following vulnerability has been resolved: |
| high | CVE-2024-27407 | linux-libc-dev 6.1.187-1 | no fix yet | In the Linux kernel, the following vulnerability has been resolved: |
| high | CVE-2024-35869 | linux-libc-dev 6.1.187-1 | no fix yet | In the Linux kernel, the following vulnerability has been resolved: |
| high | CVE-2024-35948 | linux-libc-dev 6.1.187-1 | no fix yet | In the Linux kernel, the following vulnerability has been resolved: |
| high | CVE-2023-31484 | libperl5.36 5.36.0-7+deb12u3 | no fix yet | CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS. |
| high | CVE-2024-36913 | linux-libc-dev 6.1.187-1 | no fix yet | In the Linux kernel, the following vulnerability has been resolved: |
| high | CVE-2023-31484 | perl 5.36.0-7+deb12u3 | no fix yet | CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS. |
| high | CVE-2023-31484 | perl-base 5.36.0-7+deb12u3 | no fix yet | CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS. |
| high | CVE-2023-31484 | perl-modules-5.36 5.36.0-7+deb12u3 | no fix yet | CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS. |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| latest | Not FIPS-ready | F 569 5 critical | 2026-09-25 | Full report |