Cryptopsyby CloudTrace

Image reports › mcr.microsoft.com/oss/go/microsoft/golang

mcr.microsoft.com/oss/go/microsoft/golang — vulnerabilities, FIPS 140-3 and fixes

mcr.microsoft.com/oss/go/microsoft/golang · Debian GNU/Linux 12 (bookworm)

Latest: mcr.microsoft.com/oss/go/microsoft/golang:latest · checked 2026-09-25

Not FIPS-ready

No. golang:latest relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: 569 known vulnerabilities

569 known vulnerabilities in 94 packages (5 critical, 88 high); none has a fix available yet.

Open the full interactive report → Scan your own image

Critical, high and exploited vulnerabilities in latest

SeverityIDPackageFixed inSummary
criticalCVE-2024-38541linux-libc-dev 6.1.187-1no fix yetIn the Linux kernel, the following vulnerability has been resolved:
criticalCVE-2023-45853zlib1g 1:1.2.13.dfsg-1no fix yetMiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affe
criticalCVE-2024-5535libssl3 3.0.20-1~deb12u2no fix yetIssue summary: Calling the OpenSSL API function SSL_select_next_proto with an
criticalCVE-2024-5535openssl 3.0.20-1~deb12u2no fix yetIssue summary: Calling the OpenSSL API function SSL_select_next_proto with an
criticalCVE-2024-38428wget 1.21.3-1+deb12u1no fix yeturl.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
highCVE-2023-52629linux-libc-dev 6.1.187-1no fix yetIn the Linux kernel, the following vulnerability has been resolved:
highCVE-2024-26945linux-libc-dev 6.1.187-1no fix yetIn the Linux kernel, the following vulnerability has been resolved:
highCVE-2024-27407linux-libc-dev 6.1.187-1no fix yetIn the Linux kernel, the following vulnerability has been resolved:
highCVE-2024-35869linux-libc-dev 6.1.187-1no fix yetIn the Linux kernel, the following vulnerability has been resolved:
highCVE-2024-35948linux-libc-dev 6.1.187-1no fix yetIn the Linux kernel, the following vulnerability has been resolved:
highCVE-2023-31484libperl5.36 5.36.0-7+deb12u3no fix yetCPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
highCVE-2024-36913linux-libc-dev 6.1.187-1no fix yetIn the Linux kernel, the following vulnerability has been resolved:
highCVE-2023-31484perl 5.36.0-7+deb12u3no fix yetCPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
highCVE-2023-31484perl-base 5.36.0-7+deb12u3no fix yetCPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
highCVE-2023-31484perl-modules-5.36 5.36.0-7+deb12u3no fix yetCPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.

All checked tags

TagFIPSKnown vulnerabilitiesChecked
latestNot FIPS-readyF 569 5 critical2026-09-25Full report