Image reports › caddy
caddy — vulnerabilities, FIPS 140-3 and fixes
mirror.gcr.io/library/caddy · Alpine Linux v3.23
Latest: caddy:latest · checked 2026-09-25
Not FIPS-ready
No. caddy:latest relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: 36 known vulnerabilities
36 known vulnerabilities in 14 packages (1 critical, 16 high); 35 can be fixed by upgrading 14 packages. Start with stdlib: upgrade 1.26.3 → 1.26.6 (fixes 13). Rebuilding on the latest base image picks up most OS fixes at once.
Fix plan for latest
| Package | Installed | Upgrade to | Fixes |
|---|---|---|---|
| stdlib | 1.26.3 | 1.26.6 | 13 |
| google.golang.org/grpc | 1.81.0 | 1.83.1 | 5 |
| golang.org/x/crypto | 0.52.0 | 0.56.0 | 3 |
| golang.org/x/net | 0.55.0 | 0.56.0 | 1 |
| golang.org/x/text | 0.37.0 | 0.39.0 | 1 |
| github.com/go-chi/chi/v5 | 5.2.5 | 5.3.0 | 3 |
| github.com/google/cel-go | 0.28.1 | 0.30.0 | 2 |
| go.opentelemetry.io/otel | 1.43.0 | 1.44.0 | 1 |
Critical, high and exploited vulnerabilities in latest
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| critical | GO-2026-5026 | stdlib 1.26.3 | 1.26.6 | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna |
| high | GO-2026-4970 | stdlib 1.26.3 | 1.26.5 | Root escape via symlink plus trailing slash in os |
| high | GO-2026-6303 | golang.org/x/crypto 0.52.0 | 0.55.0 | Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh |
| high | GO-2026-6354 | golang.org/x/crypto 0.52.0 | 0.56.0 | Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh |
| high | GO-2026-6355 | golang.org/x/crypto 0.52.0 | 0.56.0 | Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh |
| high | GO-2026-5942 | golang.org/x/net 0.55.0 | 0.56.0 | Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage |
| high | GO-2026-5970 | golang.org/x/text 0.37.0 | 0.39.0 | Infinite loop on invalid input in golang.org/x/text |
| high | GO-2026-5038 | stdlib 1.26.3 | 1.26.4 | Quadratic complexity in WordDecoder.DecodeHeader in mime |
| high | GO-2026-5942 | stdlib 1.26.3 | 1.26.6 | Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage |
| high | GO-2026-5972 | stdlib 1.26.3 | 1.26.6 | Enforce maximum recursion depth in encoding/asn1 |
| high | GO-2026-6088 | stdlib 1.26.3 | 1.26.6 | Add recursion depth guard during decode in encoding/xml |
| high | GO-2026-6089 | stdlib 1.26.3 | 1.26.6 | Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http |
| high | GO-2026-6090 | stdlib 1.26.3 | 1.26.6 | Limit handshake messages we are willing to accept post-handshake in crypto/tls |
| high | GHSA-hrxh-6v49-42gf | google.golang.org/grpc 1.81.0 | 1.82.1 | gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities |
| high | GO-2026-6061 | google.golang.org/grpc 1.81.0 | 1.82.1 | Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| latest | Not FIPS-ready | D 36 1 critical | 2026-09-25 | Full report |