Cryptopsyby CloudTrace

Image reports › mysql

mysql — vulnerabilities, FIPS 140-3 and fixes

mirror.gcr.io/library/mysql · Oracle Linux Server 9.8

Latest: mysql:latest · checked 2026-09-25

Not FIPS-ready

No. mysql:latest relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.

Security: 55 known vulnerabilities

55 known vulnerabilities in 4 packages (3 high); 55 can be fixed by upgrading 4 packages. Start with cryptography: upgrade 46.0.7 → 50.0.0 (fixes 4). Rebuilding on the latest base image picks up most OS fixes at once.

Open the full interactive report → Scan your own image

Fix plan for latest

PackageInstalledUpgrade toFixes
cryptography46.0.750.0.04
pip25.326.25
stdlib1.24.61.25.1345
golang.org/x/sys0.1.00.44.01

Critical, high and exploited vulnerabilities in latest

SeverityIDPackageFixed inSummary
highGHSA-537c-gmf6-5ccfcryptography 46.0.748.0.1Vulnerable OpenSSL included in cryptography wheels
highPYSEC-2026-3552cryptography 46.0.750.0.0cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing
highPYSEC-2026-3553cryptography 46.0.749.0.0python-cryptography: Duplicate self-signed intermediates can cause exponential path-building

All checked tags

TagFIPSKnown vulnerabilitiesChecked
latestNot FIPS-readyB 552026-09-25Full report