Image reports › postgres
postgres — vulnerabilities, FIPS 140-3 and fixes
mirror.gcr.io/library/postgres · Debian GNU/Linux 13 (trixie)
Latest: postgres:latest · checked 2026-09-25
Not FIPS-ready
No. postgres:latest relies on cryptography that isn't FIPS-certified, so it can't be used where FIPS 140-3 is required as it stands.
Security: 112 known vulnerabilities
112 known vulnerabilities in 43 packages (1 high); 46 can be fixed by upgrading 2 packages. Start with stdlib: upgrade 1.24.6 → 1.25.13 (fixes 45). Rebuilding on the latest base image picks up most OS fixes at once.
Fix plan for latest
| Package | Installed | Upgrade to | Fixes |
|---|---|---|---|
| stdlib | 1.24.6 | 1.25.13 | 45 |
| golang.org/x/sys | 0.1.0 | 0.44.0 | 1 |
Critical, high and exploited vulnerabilities in latest
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| high | CVE-2024-25062 | libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u3 | no fix yet | An issue was discovered in libxml2 before 2.11.7 and 2.12.x before 2.12.5. When using the XML Reader interface with DTD validation and XInclude expansion enabled, processing crafted XML documents can lead to an xmlValidatePopElement use-after-free. |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| latest | Not FIPS-ready | A 112 | 2026-09-25 | Full report |