Image reports › mariadb
mariadb — vulnerabilities, FIPS 140-3 and fixes
mirror.gcr.io/library/mariadb · Ubuntu 26.04.1 LTS
Latest: mariadb:latest · checked 2026-09-25
Not FIPS-ready
No. mariadb:latest relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: 482 known vulnerabilities
482 known vulnerabilities in 42 packages (10 critical, 147 high); 47 can be fixed by upgrading 3 packages. Start with stdlib: upgrade 1.24.6 → 1.25.13 (fixes 45). Rebuilding on the latest base image picks up most OS fixes at once.
Fix plan for latest
| Package | Installed | Upgrade to | Fixes |
|---|---|---|---|
| stdlib | 1.24.6 | 1.25.13 | 45 |
| libsqlite3-0 | 3.46.1-9ubuntu0.2 | 3.46.1-9ubuntu0.3 | 1 |
| golang.org/x/sys | 0.1.0 | 0.44.0 | 1 |
Critical, high and exploited vulnerabilities in latest
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| critical | UBUNTU-CVE-2026-14739 | libdbi-perl 1.647-1ubuntu0.26.04.1 | no fix yet | DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders. DBI version 1.650 sets a hard limit of 99,999 placeholders. |
| critical | UBUNTU-CVE-2026-15043 | libdbi-perl 1.647-1ubuntu0.26.04.1 | no fix yet | DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, <= was evaluated using Perl's ge ope |
| critical | UBUNTU-CVE-2026-73193 | libdbi-perl 1.647-1ubuntu0.26.04.1 | no fix yet | DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by preparse. preparse reserves its output buffer with `newSV(strlen(statement) * 7 + 16)`, budgeting seven output bytes per input byte for the longest ':p99 |
| critical | UBUNTU-CVE-2026-78030 | libdbi-perl 1.647-1ubuntu0.26.04.1 | no fix yet | DBI versions before 1.653 for Perl load arbitrary modules via unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM. DBD::DBM passes the dbm_type and dbm_mldbm connect attributes to require without checking that the value names a module. require treats a path-shaped string as a literal filename |
| critical | GO-2026-5026 | stdlib 1.24.6 | 1.25.13 | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna |
| critical | GO-2026-4337 | stdlib 1.24.6 | 1.24.13 | Unexpected session resumption in crypto/tls |
| critical | UBUNTU-CVE-2026-14740 | libdbi-perl 1.647-1ubuntu0.26.04.1 | no fix yet | DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte. |
| critical | UBUNTU-CVE-2026-60082 | libdbi-perl 1.647-1ubuntu0.26.04.1 | no fix yet | DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row. When the statement handle had no fields but the source row was non-empty, the internal row-buffer helper would read from a negative array index. This could be triggered by a caller supplying inconsistent met |
| critical | UBUNTU-CVE-2026-73194 | libdbi-perl 1.647-1ubuntu0.26.04.1 | no fix yet | DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse. preparse reserves seven output bytes per input byte, the width of the longest ':p99999' expansion. The ':N' branch parses the number with `atoi(src)` a |
| critical | UBUNTU-CVE-2026-53791 | rsync 3.4.1+ds1-7ubuntu0.3 | no fix yet | rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access controls by sending a crafted PROXY protocol header with a forged source address. Attackers who can connect directly to the rsync daemon can inject a spoofed |
| high | UBUNTU-CVE-2026-14380 | libdbi-perl 1.647-1ubuntu0.26.04.1 | no fix yet | DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation of the package name. |
| high | UBUNTU-CVE-2026-60163 | libmariadb3 1:13.0.2+maria~ubu2604 | no fix yet | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allo |
| high | UBUNTU-CVE-2026-60163 | mariadb-backup 1:13.0.2+maria~ubu2604 | no fix yet | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allo |
| high | UBUNTU-CVE-2026-60163 | mariadb-client 1:13.0.2+maria~ubu2604 | no fix yet | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allo |
| high | UBUNTU-CVE-2026-60163 | mariadb-client-core 1:13.0.2+maria~ubu2604 | no fix yet | Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allo |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| latest | Not FIPS-ready | F 482 10 critical | 2026-09-25 | Full report |