Cryptopsyby CloudTrace

Image reports › mongo

mongo — vulnerabilities, FIPS 140-3 and fixes

mirror.gcr.io/library/mongo · Ubuntu 24.04.5 LTS

Latest: mongo:latest · checked 2026-09-25

Not FIPS-ready

No. mongo:latest relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: 81 known vulnerabilities

81 known vulnerabilities in 16 packages (3 critical, 35 high); 58 can be fixed by upgrading 5 packages. Start with stdlib: upgrade 1.24.6 → 1.25.13 (fixes 45). Rebuilding on the latest base image picks up most OS fixes at once.

Open the full interactive report → Scan your own image

Fix plan for latest

PackageInstalledUpgrade toFixes
stdlib1.24.61.25.1345
stdlib1.26.51.26.68
golang.org/x/crypto0.54.00.56.03
golang.org/x/sys0.1.00.44.01
github.com/klauspost/compress1.18.61.18.71

Critical, high and exploited vulnerabilities in latest

SeverityIDPackageFixed inSummary
criticalGO-2026-5026stdlib 1.24.61.25.13Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
criticalGO-2026-5026stdlib 1.26.51.26.6Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
criticalGO-2026-4337stdlib 1.24.61.24.13Unexpected session resumption in crypto/tls
highGO-2026-4970stdlib 1.24.61.25.12Root escape via symlink plus trailing slash in os
highGO-2026-6303golang.org/x/crypto 0.54.00.55.0Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh
highGO-2026-6354golang.org/x/crypto 0.54.00.56.0Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh
highGO-2026-6355golang.org/x/crypto 0.54.00.56.0Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh
highGO-2025-4006stdlib 1.24.61.24.8Excessive CPU consumption in ParseAddress in net/mail
highGO-2025-4007stdlib 1.24.61.24.9Quadratic complexity when checking name constraints in crypto/x509
highGO-2025-4009stdlib 1.24.61.24.8Quadratic complexity when parsing some invalid inputs in encoding/pem
highGO-2025-4013stdlib 1.24.61.24.8Panic when validating certificates with DSA public keys in crypto/x509
highGO-2025-4155stdlib 1.24.61.24.11Excessive resource consumption when printing error string for host certificate validation in crypto/x509
highGO-2026-4341stdlib 1.24.61.24.12Memory exhaustion in query parameter parsing in net/url
highGO-2026-4601stdlib 1.24.61.25.8Incorrect parsing of IPv6 host literals in net/url
highGO-2026-4870stdlib 1.24.61.25.9Unauthenticated TLS 1.3 KeyUpdate record can cause persistent connection retention and DoS in crypto/tls

All checked tags

TagFIPSKnown vulnerabilitiesChecked
latestNot FIPS-readyF 81 3 critical2026-09-25Full report