Cryptopsyby CloudTrace

Image reports › registry.access.redhat.com/ubi9/ubi

registry.access.redhat.com/ubi9/ubi — vulnerabilities, FIPS 140-3 and fixes

registry.access.redhat.com/ubi9/ubi · Red Hat Enterprise Linux 9.8 (Plow)

Latest: registry.access.redhat.com/ubi9/ubi:latest · checked 2026-09-25

FIPS-ready on a FIPS-enabled host

Yes, with one condition: ubi:latest has certified crypto, but its FIPS mode turns on only when the host it runs on is in FIPS mode.

Security: 19 known vulnerabilities

19 known vulnerabilities in 5 packages (8 high); 19 can be fixed by upgrading 5 packages. Start with urllib3: upgrade 1.26.5 → 2.7.0 (fixes 8). Rebuilding on the latest base image picks up most OS fixes at once.

Open the full interactive report → Scan your own image

Fix plan for latest

PackageInstalledUpgrade toFixes
urllib31.26.52.7.08
setuptools53.0.083.0.04
idna2.103.152
libxml22.9.13-14.el9_8.40:2.9.13-14.el9_8.51
requests2.25.12.33.04

Critical, high and exploited vulnerabilities in latest

SeverityIDPackageFixed inSummary
highPYSEC-2025-49setuptools 53.0.078.1.1setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with
highPYSEC-2026-1918setuptools 53.0.070.0.0setuptools vulnerable to Command Injection via package URL
highRHSA-2026:71585libxml2 2.9.13-14.el9_8.40:2.9.13-14.el9_8.5Red Hat Security Advisory: libxml2 security update
highPYSEC-2023-192urllib3 1.26.51.26.17urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to specify a `Cookie` header and unknowingly leak inform
highPYSEC-2024-60idna 2.103.7A vulnerability was identified in the kjd/idna library, specifically within the `idna.encode()` function, affecting version 3.6. The issue arises from the function's handling of crafted input strings, which can lead to quadratic complexity and consequently, a denial of service condition. This vulner
highPYSEC-2026-1994urllib3 1.26.52.6.0urllib3 streaming API improperly handles highly compressed data
highPYSEC-2026-1996urllib3 1.26.52.6.3Decompression-bomb safeguards bypassed when following HTTP redirects (streaming API)
highPYSEC-2026-1998urllib3 1.26.52.6.0urllib3 allows an unbounded number of links in the decompression chain

All checked tags

TagFIPSKnown vulnerabilitiesChecked
latestFIPS-ready with conditionsC 192026-09-25Full report