Image reports › elasticsearch
elasticsearch — vulnerabilities, FIPS 140-3 and fixes
mirror.gcr.io/library/elasticsearch · Red Hat Enterprise Linux 9.8 (Plow)
Latest: elasticsearch:9.5.3 · checked 2026-09-25
Not FIPS-ready
No. elasticsearch:9.5.3 relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: 24 known vulnerabilities
24 known vulnerabilities in 11 packages (1 critical, 8 high); 24 can be fixed by upgrading 11 packages. Start with io.netty:netty-handler: upgrade 4.1.135.Final → 4.1.137.Final (fixes 2). Rebuilding on the latest base image picks up most OS fixes at once.
Fix plan for 9.5.3
| Package | Installed | Upgrade to | Fixes |
|---|---|---|---|
| io.netty:netty-handler | 4.1.135.Final | 4.1.137.Final | 2 |
| io.netty:netty-codec-http | 4.1.135.Final | 4.1.137.Final | 8 |
| com.fasterxml.jackson.core:jackson-databind | 2.19.2 | 2.21.5 | 5 |
| io.netty:netty-codec-http2 | 4.1.135.Final | 4.1.136.Final | 2 |
| io.netty:netty-codec | 4.1.135.Final | 4.1.136.Final | 1 |
| libxml2 | 2.9.13-14.el9_8.4 | 0:2.9.13-14.el9_8.5 | 1 |
| com.fasterxml.jackson.core:jackson-core | 2.19.2 | 2.21.1 | 1 |
| io.netty:netty-codec-dns | 4.1.135.Final | 4.1.136.Final | 1 |
Critical, high and exploited vulnerabilities in 9.5.3
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| critical | GHSA-c4c3-7fpv-j4q5 | io.netty:netty-handler 4.1.135.Final | 4.1.137.Final | Netty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext |
| high | RHSA-2026:71585 | libxml2 2.9.13-14.el9_8.4 | 0:2.9.13-14.el9_8.5 | Red Hat Security Advisory: libxml2 security update |
| high | GHSA-j3rv-43j4-c7qm | com.fasterxml.jackson.core:jackson-databind 2.19.2 | 2.21.4 | jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation |
| high | GHSA-rmj7-2vxq-3g9f | com.fasterxml.jackson.core:jackson-databind 2.19.2 | 2.21.4 | jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray) |
| high | GHSA-6jqx-86gh-f27w | io.netty:netty-codec-http 4.1.135.Final | 4.1.136.Final | Netty SPDY SETTINGS frame count materializes unbounded settings map |
| high | GHSA-mvh2-crg5-v77c | io.netty:netty-codec-http 4.1.135.Final | 4.1.136.Final | Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation |
| high | GHSA-93wv-jw9v-4972 | io.netty:netty-codec-http2 4.1.135.Final | 4.1.136.Final | Netty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS) |
| high | GHSA-558v-64gr-wgg4 | io.netty:netty-codec 4.1.135.Final | 4.1.136.Final | Netty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang |
| high | GHSA-jppx-w49h-x2qq | io.netty:netty-codec-http 4.1.135.Final | 4.1.136.Final | Netty: [SpdyHttpDecoder] ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| 9.5.3 | Not FIPS-ready | D 24 1 critical | 2026-09-25 | Full report |