Cryptopsyby CloudTrace

Image reports › caddy

caddy — vulnerabilities, FIPS 140-3 and fixes

mirror.gcr.io/library/caddy · Alpine Linux v3.23

Latest: caddy:latest · checked 2026-09-25

Not FIPS-ready

No. caddy:latest relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: 36 known vulnerabilities

36 known vulnerabilities in 14 packages (1 critical, 16 high); 35 can be fixed by upgrading 14 packages. Start with stdlib: upgrade 1.26.3 → 1.26.6 (fixes 13). Rebuilding on the latest base image picks up most OS fixes at once.

Open the full interactive report → Scan your own image

Fix plan for latest

PackageInstalledUpgrade toFixes
stdlib1.26.31.26.613
google.golang.org/grpc1.81.01.83.15
golang.org/x/crypto0.52.00.56.03
golang.org/x/net0.55.00.56.01
golang.org/x/text0.37.00.39.01
github.com/go-chi/chi/v55.2.55.3.03
github.com/google/cel-go0.28.10.30.02
go.opentelemetry.io/otel1.43.01.44.01

Critical, high and exploited vulnerabilities in latest

SeverityIDPackageFixed inSummary
criticalGO-2026-5026stdlib 1.26.31.26.6Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
highGO-2026-4970stdlib 1.26.31.26.5Root escape via symlink plus trailing slash in os
highGO-2026-6303golang.org/x/crypto 0.52.00.55.0Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh
highGO-2026-6354golang.org/x/crypto 0.52.00.56.0Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh
highGO-2026-6355golang.org/x/crypto 0.52.00.56.0Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh
highGO-2026-5942golang.org/x/net 0.55.00.56.0Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage
highGO-2026-5970golang.org/x/text 0.37.00.39.0Infinite loop on invalid input in golang.org/x/text
highGO-2026-5038stdlib 1.26.31.26.4Quadratic complexity in WordDecoder.DecodeHeader in mime
highGO-2026-5942stdlib 1.26.31.26.6Parsing an invalid SVCB or HTTPS RR can panic in golang.org/x/net/dns/dnsmessage
highGO-2026-5972stdlib 1.26.31.26.6Enforce maximum recursion depth in encoding/asn1
highGO-2026-6088stdlib 1.26.31.26.6Add recursion depth guard during decode in encoding/xml
highGO-2026-6089stdlib 1.26.31.26.6Apply ReadHeaderTimeout when doing unencrypted HTTP/2 check in net/http
highGO-2026-6090stdlib 1.26.31.26.6Limit handshake messages we are willing to accept post-handshake in crypto/tls
highGHSA-hrxh-6v49-42gfgoogle.golang.org/grpc 1.81.01.82.1gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
highGO-2026-6061google.golang.org/grpc 1.81.01.82.1Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc

All checked tags

TagFIPSKnown vulnerabilitiesChecked
latestNot FIPS-readyD 36 1 critical2026-09-25Full report