Image reports › registry.access.redhat.com/ubi9/ubi
registry.access.redhat.com/ubi9/ubi — vulnerabilities, FIPS 140-3 and fixes
registry.access.redhat.com/ubi9/ubi · Red Hat Enterprise Linux 9.8 (Plow)
Latest: registry.access.redhat.com/ubi9/ubi:latest · checked 2026-09-25
FIPS-ready on a FIPS-enabled host
Yes, with one condition: ubi:latest has certified crypto, but its FIPS mode turns on only when the host it runs on is in FIPS mode.
Security: 19 known vulnerabilities
19 known vulnerabilities in 5 packages (8 high); 19 can be fixed by upgrading 5 packages. Start with urllib3: upgrade 1.26.5 → 2.7.0 (fixes 8). Rebuilding on the latest base image picks up most OS fixes at once.
Fix plan for latest
| Package | Installed | Upgrade to | Fixes |
|---|---|---|---|
| urllib3 | 1.26.5 | 2.7.0 | 8 |
| setuptools | 53.0.0 | 83.0.0 | 4 |
| idna | 2.10 | 3.15 | 2 |
| libxml2 | 2.9.13-14.el9_8.4 | 0:2.9.13-14.el9_8.5 | 1 |
| requests | 2.25.1 | 2.33.0 | 4 |
Critical, high and exploited vulnerabilities in latest
| Severity | ID | Package | Fixed in | Summary |
|---|---|---|---|---|
| high | PYSEC-2025-49 | setuptools 53.0.0 | 78.1.1 | setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with |
| high | PYSEC-2026-1918 | setuptools 53.0.0 | 70.0.0 | setuptools vulnerable to Command Injection via package URL |
| high | RHSA-2026:71585 | libxml2 2.9.13-14.el9_8.4 | 0:2.9.13-14.el9_8.5 | Red Hat Security Advisory: libxml2 security update |
| high | PYSEC-2023-192 | urllib3 1.26.5 | 1.26.17 | urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak inform |
| high | PYSEC-2024-60 | idna 2.10 | 3.7 | A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting version 3.6. The issue arises from the function's handling of crafted input strings, which can lead to quadratic complexity and consequently, a denial of service condition. This vulner |
| high | PYSEC-2026-1994 | urllib3 1.26.5 | 2.6.0 | urllib3 streaming API improperly handles highly compressed data |
| high | PYSEC-2026-1996 | urllib3 1.26.5 | 2.6.3 | Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API) |
| high | PYSEC-2026-1998 | urllib3 1.26.5 | 2.6.0 | urllib3 allows an unbounded number of links in the decompression chain |
All checked tags
| Tag | FIPS | Known vulnerabilities | Checked | |
|---|---|---|---|---|
| latest | FIPS-ready with conditions | C 19 | 2026-09-25 | Full report |