Cryptopsyby CloudTrace

Image reports › elasticsearch

elasticsearch — vulnerabilities, FIPS 140-3 and fixes

mirror.gcr.io/library/elasticsearch · Red Hat Enterprise Linux 9.8 (Plow)

Latest: elasticsearch:9.5.3 · checked 2026-09-25

Not FIPS-ready

No. elasticsearch:9.5.3 relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: 24 known vulnerabilities

24 known vulnerabilities in 11 packages (1 critical, 8 high); 24 can be fixed by upgrading 11 packages. Start with io.netty:netty-handler: upgrade 4.1.135.Final → 4.1.137.Final (fixes 2). Rebuilding on the latest base image picks up most OS fixes at once.

Open the full interactive report → Scan your own image

Fix plan for 9.5.3

PackageInstalledUpgrade toFixes
io.netty:netty-handler4.1.135.Final4.1.137.Final2
io.netty:netty-codec-http4.1.135.Final4.1.137.Final8
com.fasterxml.jackson.core:jackson-databind2.19.22.21.55
io.netty:netty-codec-http24.1.135.Final4.1.136.Final2
io.netty:netty-codec4.1.135.Final4.1.136.Final1
libxml22.9.13-14.el9_8.40:2.9.13-14.el9_8.51
com.fasterxml.jackson.core:jackson-core2.19.22.21.11
io.netty:netty-codec-dns4.1.135.Final4.1.136.Final1

Critical, high and exploited vulnerabilities in 9.5.3

SeverityIDPackageFixed inSummary
criticalGHSA-c4c3-7fpv-j4q5io.netty:netty-handler 4.1.135.Final4.1.137.FinalNetty: SNI Routing Bypass via Fragmented TLS ClientHello Causing Fallback to Default SslContext
highRHSA-2026:71585libxml2 2.9.13-14.el9_8.40:2.9.13-14.el9_8.5Red Hat Security Advisory: libxml2 security update
highGHSA-j3rv-43j4-c7qmcom.fasterxml.jackson.core:jackson-databind 2.19.22.21.4jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation
highGHSA-rmj7-2vxq-3g9fcom.fasterxml.jackson.core:jackson-databind 2.19.22.21.4jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
highGHSA-6jqx-86gh-f27wio.netty:netty-codec-http 4.1.135.Final4.1.136.FinalNetty SPDY SETTINGS frame count materializes unbounded settings map
highGHSA-mvh2-crg5-v77cio.netty:netty-codec-http 4.1.135.Final4.1.136.FinalNetty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation
highGHSA-93wv-jw9v-4972io.netty:netty-codec-http2 4.1.135.Final4.1.136.FinalNetty: HTTP/2 decompression leaks ByteBuf reference count when the decompressor channel is already closed (Direct memory leak / OOM DoS)
highGHSA-558v-64gr-wgg4io.netty:netty-codec 4.1.135.Final4.1.136.FinalNetty: [Bzip2Decoder] Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang
highGHSA-jppx-w49h-x2qqio.netty:netty-codec-http 4.1.135.Final4.1.136.FinalNetty: [SpdyHttpDecoder] ByteBuf Reference Leak on RST_STREAM Leads to Native Memory Exhaustion

All checked tags

TagFIPSKnown vulnerabilitiesChecked
9.5.3Not FIPS-readyD 24 1 critical2026-09-25Full report