Image reports › mysql
mysql — vulnerabilities, FIPS 140-3 and fixes
mirror.gcr.io/library/mysql · Oracle Linux Server 9.8
Latest: mysql:latest · checked 2026-09-25
Not FIPS-ready
No. mysql:latest relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: 55 known vulnerabilities
55 known vulnerabilities in 4 packages (3 high); 55 can be fixed by upgrading 4 packages. Start with cryptography: upgrade 46.0.7 → 50.0.0 (fixes 4). Rebuilding on the latest base image picks up most OS fixes at once.
Fix plan for latest
| Package | Installed | Upgrade to | Fixes |
|---|---|---|---|
| cryptography | 46.0.7 | 50.0.0 | 4 |
| pip | 25.3 | 26.2 | 5 |
| stdlib | 1.24.6 | 1.25.13 | 45 |
| golang.org/x/sys | 0.1.0 | 0.44.0 | 1 |
Critical, high and exploited vulnerabilities in latest
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| high | GHSA-537c-gmf6-5ccf | cryptography 46.0.7 | 48.0.1 | Vulnerable OpenSSL included in cryptography wheels |
| high | PYSEC-2026-3552 | cryptography 46.0.7 | 50.0.0 | cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing |
| high | PYSEC-2026-3553 | cryptography 46.0.7 | 49.0.0 | python-cryptography: Duplicate self-signed intermediates can cause exponential path-building |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| latest | Not FIPS-ready | B 55 | 2026-09-25 | Full report |