Cryptopsyby CloudTrace

Image reports › mariadb

mariadb — vulnerabilities, FIPS 140-3 and fixes

mirror.gcr.io/library/mariadb · Ubuntu 26.04.1 LTS

Latest: mariadb:latest · checked 2026-09-25

Not FIPS-ready

No. mariadb:latest relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: 482 known vulnerabilities

482 known vulnerabilities in 42 packages (10 critical, 147 high); 47 can be fixed by upgrading 3 packages. Start with stdlib: upgrade 1.24.6 → 1.25.13 (fixes 45). Rebuilding on the latest base image picks up most OS fixes at once.

Open the full interactive report → Scan your own image

Fix plan for latest

PackageInstalledUpgrade toFixes
stdlib1.24.61.25.1345
libsqlite3-03.46.1-9ubuntu0.23.46.1-9ubuntu0.31
golang.org/x/sys0.1.00.44.01

Critical, high and exploited vulnerabilities in latest

SeverityIDPackageFixed inSummary
criticalUBUNTU-CVE-2026-14739libdbi-perl 1.647-1ubuntu0.26.04.1no fix yetDBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders. DBI version 1.650 sets a hard limit of 99,999 placeholders.
criticalUBUNTU-CVE-2026-15043libdbi-perl 1.647-1ubuntu0.26.04.1no fix yetDBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, <= was evaluated using Perl's ge ope
criticalUBUNTU-CVE-2026-73193libdbi-perl 1.647-1ubuntu0.26.04.1no fix yetDBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by preparse. preparse reserves its output buffer with `newSV(strlen(statement) * 7 + 16)`, budgeting seven output bytes per input byte for the longest ':p99
criticalUBUNTU-CVE-2026-78030libdbi-perl 1.647-1ubuntu0.26.04.1no fix yetDBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module. require treats a path-shaped string as a literal filename
criticalGO-2026-5026stdlib 1.24.61.25.13Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
criticalGO-2026-4337stdlib 1.24.61.24.13Unexpected session resumption in crypto/tls
criticalUBUNTU-CVE-2026-14740libdbi-perl 1.647-1ubuntu0.26.04.1no fix yetDBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte.
criticalUBUNTU-CVE-2026-60082libdbi-perl 1.647-1ubuntu0.26.04.1no fix yetDBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index. This could be triggered by a caller supplying inconsistent met
criticalUBUNTU-CVE-2026-73194libdbi-perl 1.647-1ubuntu0.26.04.1no fix yetDBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse. preparse reserves seven output bytes per input byte, the width of the longest ':p99999' expansion. The ':N' branch parses the number with `atoi(src)` a
criticalUBUNTU-CVE-2026-53791rsync 3.4.1+ds1-7ubuntu0.3no fix yetrsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Attackers who can connect directly to the rsync daemon can inject a spoofed
highUBUNTU-CVE-2026-14380libdbi-perl 1.647-1ubuntu0.26.04.1no fix yetDBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation of the package name.
highUBUNTU-CVE-2026-60163libmariadb3 1:13.0.2+maria~ubu2604no fix yetVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allo
highUBUNTU-CVE-2026-60163mariadb-backup 1:13.0.2+maria~ubu2604no fix yetVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allo
highUBUNTU-CVE-2026-60163mariadb-client 1:13.0.2+maria~ubu2604no fix yetVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allo
highUBUNTU-CVE-2026-60163mariadb-client-core 1:13.0.2+maria~ubu2604no fix yetVulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allo

All checked tags

TagFIPSKnown vulnerabilitiesChecked
latestNot FIPS-readyF 482 10 critical2026-09-25Full report