DirectorySecurity AdvisoriesPricing
Sign in
Directory
gitlab-webservice-ce-fips logoFIPS

gitlab-webservice-ce-fips

packaged by Chainguard

Last changed
Request a free trial

Contact our team to test out this image for free. Please also indicate any other images you would like to evaluate.

Tags
Overview
Comparison
Provenance
Specifications
SBOM
Vulnerabilities
Advisories

Expand
CVE ID
Severity
Package
Version
Last detected
CVE-2021-23369
Critical
handlebars
1.0.0
CVE-2019-19919
Critical
handlebars
1.0.0
CVE-2026-5450
Critical
glibc
2.43-r12
CVE-2026-50195
Critical
github.com/containerd/containerd
v1.7.33
CVE-2026-53492
Critical
github.com/containerd/containerd
v1.7.33
CVE-2021-23383
Critical
handlebars
1.0.0
CVE-2026-56852
High
golang.org/x/text
v0.37.0
CVE-2026-4046
High
glibc
2.43-r12
CVE-2026-5435
High
glibc
2.43-r12
CVE-2026-39821
High
golang.org/x/net
v0.54.0
CVE-2026-71556
High
github.com/go-git/go-git/v5
v5.19.1
CVE-2026-15308
High
python-3.12
3.12.13-r10
CVE-2026-43870
High
thrift
0.0.0-DEVELOPMENT
CVE-2026-4775
High
tiff
4.7.2-r1
CVE-2026-54904
High
concurrent-ruby
1.3.6
CVE-2026-61666
High
websocket-driver
0.8.0
CVE-2026-46600
High
golang.org/x/net
v0.54.0
CVE-2026-4786
High
python-3.12
3.12.13-r10
CVE-2026-53727
High
css_parser
1.14.0
CVE-2026-3644
High
python-3.12
3.12.13-r10
CVE-2020-7712
High
json
1.0.0
CVE-2026-7210
High
python-3.12
3.12.13-r10
CVE-2026-6100
High
python-3.12
3.12.13-r10
CVE-2026-41567
High
github.com/docker/docker
v28.0.0+incompatible
CVE-2026-3298
High
python-3.12
3.12.13-r10
CVE-2020-7788
High
ini
1.0.0
GHSA-q42p-pg8m-cqh6
High
handlebars
1.0.0
CVE-2019-16775
High
npm
1.0.1
CVE-2018-7408
High
npm
1.0.1
CVE-2026-11940
High
python-3.12
3.12.13-r10
GHSA-h6ch-v84p-w6p9
High
diff
1.0.0
CVE-2026-5928
High
glibc
2.43-r12
GHSA-hrxh-6v49-42gf
High
google.golang.org/grpc
v1.80.0
CVE-2019-16776
High
npm
1.0.1
GHSA-q2c6-c6pm-g3gh
High
handlebars
1.0.0
CVE-2026-71556
High
github.com/go-git/go-git/v5
v5.19.1
CVE-2019-20920
High
handlebars
1.0.0
CVE-2016-3956
High
npm
1.0.1
CVE-2026-11972
High
python-3.12
3.12.13-r10
CVE-2025-15558
High
github.com/docker/cli
v25.0.1+incompatible
CVE-2026-34040
High
github.com/docker/docker
v28.0.0+incompatible
CVE-2019-16777
High
npm
1.0.1
CVE-2026-9669
High
python-3.12
3.12.13-r10
GHSA-g9r4-xpmj-mj65
High
handlebars
1.0.0
CVE-2026-4224
High
python-3.12
3.12.13-r10
GHSA-2cf5-4w76-r9qv
High
handlebars
1.0.0
CVE-2026-4437
High
glibc
2.43-r12
CVE-2026-41636
High
thrift
0.0.0-DEVELOPMENT
CVE-2026-0861
High
glibc
2.43-r12
CVE-2026-42306
High
github.com/docker/docker
v28.0.0+incompatible
CVE-2026-6019
Medium
python-3.12
3.12.13-r10
CVE-2026-6238
Medium
glibc
2.43-r12
CVE-2026-44836
Medium
view_component
3.23.2
CVE-2021-21353
Medium
pug
1.0.0
CVE-2026-44587
Medium
carrierwave
1.3.4
CVE-2025-67202
Medium
sidekiq-cron
2.3.1
CVE-2026-71557
Medium
github.com/go-git/go-git/v5
v5.19.1
GHSA-5prr-v3j2-97mh
Medium
nokogiri
1.19.3
CVE-2024-36361
Medium
pug
1.0.0
CVE-2026-25680
Medium
golang.org/x/net
v0.54.0
CVE-2026-33532
Medium
yaml
1.0.0
CVE-2026-40295
Medium
devise
4.9.4
CVE-2026-44476
Medium
doorkeeper-openid_connect
1.9.0
CVE-2026-3276
Medium
python-3.12
3.12.13-r10
CVE-2026-0864
Medium
python-3.12
3.12.13-r10
CVE-2026-42502
Medium
golang.org/x/net
v0.54.0
CVE-2026-32700
Medium
devise
4.9.4
CVE-2026-41178
Medium
go.opentelemetry.io/otel
v1.43.0
CVE-2026-7774
Medium
python-3.12
3.12.13-r10
CVE-2026-54463
Medium
websocket-driver
0.8.0
CVE-2026-2297
Medium
python-3.12
3.12.13-r10
CVE-2026-53489
Medium
github.com/containerd/containerd
v1.7.33
CVE-2020-15095
Medium
npm
1.0.1
CVE-2026-54171
Medium
excon
1.3.0
CVE-2025-15367
Medium
python-3.12
3.12.13-r10
CVE-2026-25681
Medium
golang.org/x/net
v0.54.0
CVE-2026-71557
Medium
github.com/go-git/go-git/v5
v5.19.1
CVE-2026-27136
Medium
golang.org/x/net
v0.54.0
CVE-2026-44312
Medium
css_parser
1.14.0
CVE-2026-44837
Medium
view_component
3.23.2
GHSA-9wjq-cp2p-hrgf
Medium
loofah
2.25.1
GHSA-cj75-f6xr-r4g7
Medium
rails-html-sanitizer
1.7.0
CVE-2025-15366
Medium
python-3.12
3.12.13-r10
CVE-2023-49090
Medium
carrierwave
1.3.4
CVE-2026-4438
Medium
glibc
2.43-r12
CVE-2026-8328
Medium
python-3.12
3.12.13-r10
CVE-2026-42506
Medium
golang.org/x/net
v0.54.0
CVE-2026-12003
Medium
python-3.12
3.12.13-r10
CVE-2026-33997
Medium
github.com/docker/docker
v28.0.0+incompatible
CVE-2026-4360
Medium
python-3.12
3.12.13-r10
CVE-2026-41568
Medium
github.com/docker/docker
v28.0.0+incompatible
CVE-2026-54465
Medium
websocket-driver
0.8.0
CVE-2026-54464
Medium
websocket-driver
0.8.0
CVE-2025-12781
Medium
python-3.12
3.12.13-r10
CVE-2015-8861
Medium
handlebars
1.0.0
CVE-2026-1502
Medium
python-3.12
3.12.13-r10
CVE-2024-29034
Medium
carrierwave
1.3.4
CVE-2026-3446
Medium
python-3.12
3.12.13-r10
CVE-2025-13462
Low
python-3.12
3.12.13-r10
GHSA-wx77-rp39-c6vg
Low
markdown
1.0.0
GHSA-9cv2-cfxc-v4v2
Low
nokogiri
1.19.3
GHSA-p67v-3w7g-wjg7
Low
nokogiri
1.19.3
CVE-2026-54522
Low
msgpack
1.5.4
CVE-2026-24001
Low
diff
1.0.0
GHSA-phwj-rprq-35pp
Low
nokogiri
1.19.3
CVE-2026-54906
Low
concurrent-ruby
1.3.6
GHSA-5v8h-3h3q-446p
Low
nokogiri
1.19.3
CVE-2026-6879
Low
python-3.12
3.12.13-r10
CVE-2026-54905
Low
concurrent-ruby
1.3.6
GHSA-8whx-365g-h9vv
Low
loofah
2.25.1
CVE-2026-48978
Low
oras.land/oras-go
v1.2.5
CVE-2013-4116
Low
npm
1.0.1
CVE-2026-4519
Low
python-3.12
3.12.13-r10
CVE-2026-54696
Low
json
2.19.2
GHSA-wfpw-mmfh-qq69
Low
nokogiri
1.19.3
GHSA-8678-w3jw-xfc2
Low
nokogiri
1.19.3
GHSA-5qhf-9phg-95m2
Low
loofah
2.25.1
GHSA-wjv4-x9w8-wm3h
Low
nokogiri
1.19.3
GO-2026-5932
Unknown
golang.org/x/crypto
v0.53.0
GO-2026-5841
Unknown
github.com/klauspost/compress
v1.18.5
CVE-2026-3479
Unknown
python-3.12
3.12.13-r10
GO-2026-5932
Unknown
golang.org/x/crypto
v0.52.0
Last updated:


The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.