Search:
| Image | Mirrored | Release | Binary/Package | Dependency | Vulnerability ID (CVE) | Severity | Status | Justification (for status not affected) | Type (language or OS) |
|---|---|---|---|---|---|---|---|---|---|
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.5-r0 | CVE-2026-31789 | CRITICAL | affected | alpine | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.5-r0 | CVE-2026-28387 | HIGH | affected | alpine | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.5-r0 | CVE-2026-28388 | HIGH | affected | alpine | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.5-r0 | CVE-2026-28389 | HIGH | affected | alpine | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.5-r0 | CVE-2026-28390 | HIGH | affected | alpine | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.5-r0 | CVE-2026-45447 | HIGH | affected | alpine | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | libssl3 | libssl3@3.5.5-r0 | CVE-2026-31789 | CRITICAL | affected | alpine | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | libssl3 | libssl3@3.5.5-r0 | CVE-2026-28387 | HIGH | affected | alpine | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | libssl3 | libssl3@3.5.5-r0 | CVE-2026-28388 | HIGH | affected | alpine | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | libssl3 | libssl3@3.5.5-r0 | CVE-2026-28389 | HIGH | affected | alpine | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | libssl3 | libssl3@3.5.5-r0 | CVE-2026-28390 | HIGH | affected | alpine | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | libssl3 | libssl3@3.5.5-r0 | CVE-2026-45447 | HIGH | affected | alpine | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | musl | musl@1.2.5-r21 | CVE-2026-40200 | HIGH | affected | alpine | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | musl-utils | musl-utils@1.2.5-r21 | CVE-2026-40200 | HIGH | affected | alpine | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | zlib | zlib@1.3.1-r2 | CVE-2026-22184 | HIGH | affected | alpine | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | ip-control-loop | golang.org/x/net@v0.49.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | ip-control-loop | golang.org/x/net@v0.49.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | ip-control-loop | stdlib@v1.25.6 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | ip-control-loop | stdlib@v1.25.6 | CVE-2026-32280 | HIGH | affected | gobinary | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | ip-control-loop | stdlib@v1.25.6 | CVE-2026-33814 | HIGH | affected | gobinary | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | ip-control-loop | stdlib@v1.25.6 | CVE-2026-39836 | HIGH | affected | gobinary | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | node-slice-controller | golang.org/x/net@v0.49.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | node-slice-controller | golang.org/x/net@v0.49.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | node-slice-controller | stdlib@v1.25.6 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | node-slice-controller | stdlib@v1.25.6 | CVE-2026-32280 | HIGH | affected | gobinary | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | node-slice-controller | stdlib@v1.25.6 | CVE-2026-33814 | HIGH | affected | gobinary | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | node-slice-controller | stdlib@v1.25.6 | CVE-2026-39836 | HIGH | affected | gobinary | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | whereabouts | golang.org/x/net@v0.49.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | whereabouts | golang.org/x/net@v0.49.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | whereabouts | stdlib@v1.25.6 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | whereabouts | stdlib@v1.25.6 | CVE-2026-32280 | HIGH | affected | gobinary | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | whereabouts | stdlib@v1.25.6 | CVE-2026-33814 | HIGH | affected | gobinary | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | whereabouts | stdlib@v1.25.6 | CVE-2026-39836 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | inetutils-ping | inetutils-ping@2:2.5-3ubuntu4 | CVE-2026-24061 | HIGH | affected | ubuntu | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | libssl3t64 | libssl3t64@3.0.13-0ubuntu3.5 | CVE-2026-45447 | HIGH | affected | ubuntu | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | libssl3t64-fips | libssl3t64-fips@3.0.13-0ubuntu3.5 | CVE-2026-45447 | HIGH | affected | ubuntu | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | libunbound8 | libunbound8@1.19.2-1ubuntu3.5 | CVE-2026-33278 | HIGH | affected | ubuntu | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | openssl | openssl@3.0.13-0ubuntu3.5 | CVE-2026-45447 | HIGH | affected | ubuntu | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn | golang.org/x/net@v0.44.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn | golang.org/x/net@v0.44.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn | stdlib@v1.25.1 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn | stdlib@v1.25.1 | CVE-2025-61729 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn | stdlib@v1.25.1 | CVE-2026-32280 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn | stdlib@v1.25.1 | CVE-2026-33814 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn | stdlib@v1.25.1 | CVE-2026-39820 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn | stdlib@v1.25.1 | CVE-2026-39836 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn | stdlib@v1.25.1 | CVE-2026-42499 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn | stdlib@v1.25.1 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn | stdlib@v1.25.1 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn | stdlib@v1.25.1 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-cmd | go.opentelemetry.io/otel@v1.37.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-cmd | golang.org/x/net@v0.44.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-cmd | golang.org/x/net@v0.44.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-cmd | google.golang.org/grpc@v1.73.0 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-cmd | stdlib@v1.25.1 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-cmd | stdlib@v1.25.1 | CVE-2025-61729 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-cmd | stdlib@v1.25.1 | CVE-2026-32280 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-cmd | stdlib@v1.25.1 | CVE-2026-33814 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-cmd | stdlib@v1.25.1 | CVE-2026-39820 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-cmd | stdlib@v1.25.1 | CVE-2026-39836 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-cmd | stdlib@v1.25.1 | CVE-2026-42499 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-cmd | stdlib@v1.25.1 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-cmd | stdlib@v1.25.1 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-cmd | stdlib@v1.25.1 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-controller | go.opentelemetry.io/otel@v1.37.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-controller | golang.org/x/net@v0.44.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-controller | golang.org/x/net@v0.44.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-controller | google.golang.org/grpc@v1.73.0 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-controller | stdlib@v1.25.1 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-controller | stdlib@v1.25.1 | CVE-2025-61729 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-controller | stdlib@v1.25.1 | CVE-2026-32280 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-controller | stdlib@v1.25.1 | CVE-2026-33814 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-controller | stdlib@v1.25.1 | CVE-2026-39820 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-controller | stdlib@v1.25.1 | CVE-2026-39836 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-controller | stdlib@v1.25.1 | CVE-2026-42499 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-controller | stdlib@v1.25.1 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-controller | stdlib@v1.25.1 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-controller | stdlib@v1.25.1 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | github.com/containerd/containerd/v2@v2.1.3 | CVE-2026-53488 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | github.com/containerd/containerd/v2@v2.1.3 | CVE-2026-53492 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | github.com/containerd/containerd/v2@v2.1.3 | CVE-2026-50195 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | github.com/docker/docker@v28.3.3+incompatible | CVE-2026-34040 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | github.com/docker/docker@v28.3.3+incompatible | CVE-2026-41567 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | github.com/docker/docker@v28.3.3+incompatible | CVE-2026-42306 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | github.com/docker/docker@v28.3.3+incompatible | CVE-2026-33997 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | go.opentelemetry.io/otel@v1.37.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | golang.org/x/net@v0.44.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | golang.org/x/net@v0.44.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | google.golang.org/grpc@v1.73.0 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | stdlib@v1.25.1 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | stdlib@v1.25.1 | CVE-2025-61729 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | stdlib@v1.25.1 | CVE-2026-32280 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | stdlib@v1.25.1 | CVE-2026-33814 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | stdlib@v1.25.1 | CVE-2026-39820 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | stdlib@v1.25.1 | CVE-2026-39836 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | stdlib@v1.25.1 | CVE-2026-42499 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | stdlib@v1.25.1 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | stdlib@v1.25.1 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | stdlib@v1.25.1 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/gobgp | google.golang.org/grpc@v1.56.3 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/gobgp | stdlib@v1.25.1 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/gobgp | stdlib@v1.25.1 | CVE-2025-61729 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/gobgp | stdlib@v1.25.1 | CVE-2026-32280 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/gobgp | stdlib@v1.25.1 | CVE-2026-33811 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/gobgp | stdlib@v1.25.1 | CVE-2026-39836 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/gobgp | stdlib@v1.25.1 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/gobgp | stdlib@v1.25.1 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/gobgp | stdlib@v1.25.1 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/kubectl | go.opentelemetry.io/otel@v1.37.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/kubectl | golang.org/x/net@v0.44.0 | CVE-2026-25680 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/kubectl | golang.org/x/net@v0.44.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/kubectl | golang.org/x/net@v0.44.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.25.1 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.25.1 | CVE-2025-61729 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.25.1 | CVE-2026-32280 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.25.1 | CVE-2026-33811 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.25.1 | CVE-2026-33814 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.25.1 | CVE-2026-39820 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.25.1 | CVE-2026-39836 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.25.1 | CVE-2026-42499 | HIGH | affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.25.1 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.25.1 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.25.1 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | curl | curl@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | glibc-devel | glibc-devel@2.38-150600.14.43.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | glibc-devel | glibc-devel@2.38-150600.14.43.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | libgnutls30 | libgnutls30@3.8.3-150600.4.17.1 | SUSE-SU-2026:2115-1 | HIGH | affected | sles | |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | libnghttp2-14 | libnghttp2-14@1.64.0-150700.1.5 | SUSE-SU-2026:1074-1 | HIGH | affected | sles | |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | libopenssl1_1 | libopenssl1_1@1.1.1w-150700.11.11.1 | SUSE-SU-2026:2392-1 | HIGH | affected | sles | |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-150700.11.5.2 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.51.2-150000.3.36.1 | SUSE-SU-2026:2528-1 | HIGH | affected | sles | |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | libudev1 | libudev1@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | libzypp | libzypp@17.37.18-150700.6.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | qemu-img | qemu-img@9.2.4-150700.3.17.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | qemu-tools | qemu-tools@9.2.4-150700.3.17.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | systemd | systemd@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-150700.13.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/backing-image-manager | golang.org/x/net@v0.49.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/backing-image-manager | golang.org/x/net@v0.49.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/backing-image-manager | google.golang.org/grpc@v1.78.0 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/backing-image-manager | stdlib@v1.25.8 | CVE-2026-32280 | HIGH | affected | gobinary | |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/backing-image-manager | stdlib@v1.25.8 | CVE-2026-33811 | HIGH | affected | gobinary | |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/backing-image-manager | stdlib@v1.25.8 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/backing-image-manager | stdlib@v1.25.8 | CVE-2026-39836 | HIGH | affected | gobinary | |
| longhornio/csi-attacher:v4.11.0 | false | Harvester v1.8.0 | csi-attacher | go.opentelemetry.io/otel@v1.38.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| longhornio/csi-attacher:v4.11.0 | false | Harvester v1.8.0 | csi-attacher | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-24051 | HIGH | affected | gobinary | |
| longhornio/csi-attacher:v4.11.0 | false | Harvester v1.8.0 | csi-attacher | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-39883 | HIGH | affected | gobinary | |
| longhornio/csi-attacher:v4.11.0 | false | Harvester v1.8.0 | csi-attacher | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/csi-attacher:v4.11.0 | false | Harvester v1.8.0 | csi-attacher | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| longhornio/csi-attacher:v4.11.0 | false | Harvester v1.8.0 | csi-attacher | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| longhornio/csi-attacher:v4.11.0 | false | Harvester v1.8.0 | csi-attacher | stdlib@v1.25.7 | CVE-2026-33811 | HIGH | affected | gobinary | |
| longhornio/csi-attacher:v4.11.0 | false | Harvester v1.8.0 | csi-attacher | stdlib@v1.25.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/csi-attacher:v4.11.0 | false | Harvester v1.8.0 | csi-attacher | stdlib@v1.25.7 | CVE-2026-39820 | HIGH | affected | gobinary | |
| longhornio/csi-attacher:v4.11.0 | false | Harvester v1.8.0 | csi-attacher | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| longhornio/csi-attacher:v4.11.0 | false | Harvester v1.8.0 | csi-attacher | stdlib@v1.25.7 | CVE-2026-42499 | HIGH | affected | gobinary | |
| longhornio/csi-node-driver-registrar:v2.16.0 | false | Harvester v1.8.0 | csi-node-driver-registrar | go.opentelemetry.io/otel@v1.40.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| longhornio/csi-node-driver-registrar:v2.16.0 | false | Harvester v1.8.0 | csi-node-driver-registrar | google.golang.org/grpc@v1.78.0 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| longhornio/csi-node-driver-registrar:v2.16.0 | false | Harvester v1.8.0 | csi-node-driver-registrar | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| longhornio/csi-node-driver-registrar:v2.16.0 | false | Harvester v1.8.0 | csi-node-driver-registrar | stdlib@v1.25.7 | CVE-2026-33811 | HIGH | affected | gobinary | |
| longhornio/csi-node-driver-registrar:v2.16.0 | false | Harvester v1.8.0 | csi-node-driver-registrar | stdlib@v1.25.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/csi-node-driver-registrar:v2.16.0 | false | Harvester v1.8.0 | csi-node-driver-registrar | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| longhornio/csi-provisioner:v5.3.0-20260225 | false | Harvester v1.8.0 | csi-provisioner | golang.org/x/net@v0.40.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/csi-provisioner:v5.3.0-20260225 | false | Harvester v1.8.0 | csi-provisioner | golang.org/x/net@v0.40.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| longhornio/csi-provisioner:v5.3.0-20260225 | false | Harvester v1.8.0 | csi-provisioner | stdlib@v1.24.13 | CVE-2026-32280 | HIGH | affected | gobinary | |
| longhornio/csi-provisioner:v5.3.0-20260225 | false | Harvester v1.8.0 | csi-provisioner | stdlib@v1.24.13 | CVE-2026-33811 | HIGH | affected | gobinary | |
| longhornio/csi-provisioner:v5.3.0-20260225 | false | Harvester v1.8.0 | csi-provisioner | stdlib@v1.24.13 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/csi-provisioner:v5.3.0-20260225 | false | Harvester v1.8.0 | csi-provisioner | stdlib@v1.24.13 | CVE-2026-39836 | HIGH | affected | gobinary | |
| longhornio/csi-resizer:v2.1.0 | false | Harvester v1.8.0 | csi-resizer | go.opentelemetry.io/otel@v1.39.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| longhornio/csi-resizer:v2.1.0 | false | Harvester v1.8.0 | csi-resizer | go.opentelemetry.io/otel/sdk@v1.39.0 | CVE-2026-24051 | HIGH | affected | gobinary | |
| longhornio/csi-resizer:v2.1.0 | false | Harvester v1.8.0 | csi-resizer | go.opentelemetry.io/otel/sdk@v1.39.0 | CVE-2026-39883 | HIGH | affected | gobinary | |
| longhornio/csi-resizer:v2.1.0 | false | Harvester v1.8.0 | csi-resizer | golang.org/x/net@v0.48.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/csi-resizer:v2.1.0 | false | Harvester v1.8.0 | csi-resizer | golang.org/x/net@v0.48.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| longhornio/csi-resizer:v2.1.0 | false | Harvester v1.8.0 | csi-resizer | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| longhornio/csi-resizer:v2.1.0 | false | Harvester v1.8.0 | csi-resizer | stdlib@v1.25.7 | CVE-2026-33811 | HIGH | affected | gobinary | |
| longhornio/csi-resizer:v2.1.0 | false | Harvester v1.8.0 | csi-resizer | stdlib@v1.25.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/csi-resizer:v2.1.0 | false | Harvester v1.8.0 | csi-resizer | stdlib@v1.25.7 | CVE-2026-39820 | HIGH | affected | gobinary | |
| longhornio/csi-resizer:v2.1.0 | false | Harvester v1.8.0 | csi-resizer | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| longhornio/csi-resizer:v2.1.0 | false | Harvester v1.8.0 | csi-resizer | stdlib@v1.25.7 | CVE-2026-42499 | HIGH | affected | gobinary | |
| longhornio/csi-snapshotter:v8.5.0 | false | Harvester v1.8.0 | csi-snapshotter | go.opentelemetry.io/otel@v1.40.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| longhornio/csi-snapshotter:v8.5.0 | false | Harvester v1.8.0 | csi-snapshotter | golang.org/x/net@v0.49.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/csi-snapshotter:v8.5.0 | false | Harvester v1.8.0 | csi-snapshotter | golang.org/x/net@v0.49.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| longhornio/csi-snapshotter:v8.5.0 | false | Harvester v1.8.0 | csi-snapshotter | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| longhornio/csi-snapshotter:v8.5.0 | false | Harvester v1.8.0 | csi-snapshotter | stdlib@v1.25.7 | CVE-2026-33811 | HIGH | affected | gobinary | |
| longhornio/csi-snapshotter:v8.5.0 | false | Harvester v1.8.0 | csi-snapshotter | stdlib@v1.25.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/csi-snapshotter:v8.5.0 | false | Harvester v1.8.0 | csi-snapshotter | stdlib@v1.25.7 | CVE-2026-39820 | HIGH | affected | gobinary | |
| longhornio/csi-snapshotter:v8.5.0 | false | Harvester v1.8.0 | csi-snapshotter | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| longhornio/csi-snapshotter:v8.5.0 | false | Harvester v1.8.0 | csi-snapshotter | stdlib@v1.25.7 | CVE-2026-42499 | HIGH | affected | gobinary | |
| longhornio/livenessprobe:v2.18.0 | false | Harvester v1.8.0 | livenessprobe | go.opentelemetry.io/otel@v1.39.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| longhornio/livenessprobe:v2.18.0 | false | Harvester v1.8.0 | livenessprobe | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| longhornio/livenessprobe:v2.18.0 | false | Harvester v1.8.0 | livenessprobe | stdlib@v1.25.7 | CVE-2026-33811 | HIGH | affected | gobinary | |
| longhornio/livenessprobe:v2.18.0 | false | Harvester v1.8.0 | livenessprobe | stdlib@v1.25.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/livenessprobe:v2.18.0 | false | Harvester v1.8.0 | livenessprobe | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | libnghttp2-14 | libnghttp2-14@1.64.0-150700.1.5 | SUSE-SU-2026:1074-1 | HIGH | affected | sles | |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-150700.11.5.2 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.51.2-150000.3.36.1 | SUSE-SU-2026:2528-1 | HIGH | affected | sles | |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | libudev1 | libudev1@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | libzypp | libzypp@17.37.18-150700.6.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-150700.13.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl | stdlib@v1.25.8 | CVE-2026-32280 | HIGH | affected | gobinary | |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl | stdlib@v1.25.8 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl | stdlib@v1.25.8 | CVE-2026-39836 | HIGH | affected | gobinary | |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl-local | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl-local | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl-local | stdlib@v1.25.8 | CVE-2026-32280 | HIGH | affected | gobinary | |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl-local | stdlib@v1.25.8 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl-local | stdlib@v1.25.8 | CVE-2026-39836 | HIGH | affected | gobinary | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | curl | curl@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | HIGH | affected | sles | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | libgnutls30 | libgnutls30@3.8.3-150600.4.17.1 | SUSE-SU-2026:2115-1 | HIGH | affected | sles | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | libldb2 | libldb2@4.21.10+git.449.dcced69e1b5-150700.3.19.1 | SUSE-SU-2026:2076-1 | CRITICAL | affected | sles | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | libopenssl1_1 | libopenssl1_1@1.1.1w-150700.11.11.1 | SUSE-SU-2026:1386-1 | HIGH | affected | sles | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | libopenssl1_1 | libopenssl1_1@1.1.1w-150700.11.11.1 | SUSE-SU-2026:2392-1 | HIGH | affected | sles | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-150700.11.5.2 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.51.2-150000.3.36.1 | SUSE-SU-2026:2528-1 | HIGH | affected | sles | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | libsystemd0 | libsystemd0@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | libudev1 | libudev1@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | libzypp | libzypp@17.37.18-150700.6.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | qemu-img | qemu-img@9.2.4-150700.3.17.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | qemu-pr-helper | qemu-pr-helper@9.2.4-150700.3.17.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | qemu-tools | qemu-tools@9.2.4-150700.3.17.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | samba-client-libs | samba-client-libs@4.21.10+git.449.dcced69e1b5-150700.3.19.1 | SUSE-SU-2026:2076-1 | CRITICAL | affected | sles | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | systemd | systemd@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-150700.13.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | github.com/go-jose/go-jose/v4@v4.1.3 | CVE-2026-34986 | HIGH | affected | gobinary | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | stdlib@v1.25.8 | CVE-2026-32280 | HIGH | affected | gobinary | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | stdlib@v1.25.8 | CVE-2026-39836 | HIGH | affected | gobinary | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn | github.com/moby/moby@v26.1.5+incompatible | CVE-2026-34040 | HIGH | affected | gobinary | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn | github.com/moby/moby@v26.1.5+incompatible | CVE-2026-41567 | HIGH | affected | gobinary | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn | github.com/moby/moby@v26.1.5+incompatible | CVE-2026-42306 | HIGH | affected | gobinary | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn | github.com/moby/moby@v26.1.5+incompatible | CVE-2026-33997 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn | golang.org/x/net@v0.49.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn | golang.org/x/net@v0.49.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn | google.golang.org/grpc@v1.78.0 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn | stdlib@v1.25.8 | CVE-2026-32280 | HIGH | affected | gobinary | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn | stdlib@v1.25.8 | CVE-2026-33811 | HIGH | affected | gobinary | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn | stdlib@v1.25.8 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn | stdlib@v1.25.8 | CVE-2026-39836 | HIGH | affected | gobinary | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | golang.org/x/net@v0.49.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | golang.org/x/net@v0.49.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | google.golang.org/grpc@v1.79.2 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | stdlib@v1.25.8 | CVE-2026-32280 | HIGH | affected | gobinary | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | stdlib@v1.25.8 | CVE-2026-33811 | HIGH | affected | gobinary | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | stdlib@v1.25.8 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | stdlib@v1.25.8 | CVE-2026-39836 | HIGH | affected | gobinary | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | curl | curl@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | libarchive13 | libarchive13@3.7.2-150600.3.17.1 | SUSE-SU-2026:2490-1 | HIGH | affected | sles | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | HIGH | affected | sles | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | libgnutls30 | libgnutls30@3.8.3-150600.4.17.1 | SUSE-SU-2026:2115-1 | HIGH | affected | sles | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | libnghttp2-14 | libnghttp2-14@1.64.0-150700.1.5 | SUSE-SU-2026:1074-1 | HIGH | affected | sles | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | libopenssl1_1 | libopenssl1_1@1.1.1w-150700.11.11.1 | SUSE-SU-2026:2392-1 | HIGH | affected | sles | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | libpython3_11-1_0 | libpython3_11-1_0@3.11.14-150600.3.44.1 | SUSE-SU-2026:1349-1 | HIGH | affected | sles | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-150700.11.5.2 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.51.2-150000.3.36.1 | SUSE-SU-2026:2528-1 | HIGH | affected | sles | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | libsystemd0 | libsystemd0@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | libudev1 | libudev1@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | libzypp | libzypp@17.37.18-150700.6.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | qemu-img | qemu-img@9.2.4-150700.3.17.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | qemu-pr-helper | qemu-pr-helper@9.2.4-150700.3.17.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | qemu-tools | qemu-tools@9.2.4-150700.3.17.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | samba-client-libs | samba-client-libs@4.21.10+git.449.dcced69e1b5-150700.3.19.1 | SUSE-SU-2026:2076-1 | CRITICAL | affected | sles | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | systemd | systemd@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | xz | xz@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-150700.13.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | Python | cryptography@46.0.5 | GHSA-537c-gmf6-5ccf | HIGH | affected | python-pkg | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/go-spdk-helper | stdlib@v1.25.8 | CVE-2026-39836 | HIGH | affected | gobinary | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | github.com/go-jose/go-jose/v4@v4.1.3 | CVE-2026-34986 | HIGH | affected | gobinary | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | stdlib@v1.25.8 | CVE-2026-32280 | HIGH | affected | gobinary | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | stdlib@v1.25.8 | CVE-2026-39836 | HIGH | affected | gobinary | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | golang.org/x/net@v0.49.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | golang.org/x/net@v0.49.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | google.golang.org/grpc@v1.79.2 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | stdlib@v1.25.8 | CVE-2026-32280 | HIGH | affected | gobinary | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | stdlib@v1.25.8 | CVE-2026-33811 | HIGH | affected | gobinary | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | stdlib@v1.25.8 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | stdlib@v1.25.8 | CVE-2026-39836 | HIGH | affected | gobinary | |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | curl | curl@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | HIGH | affected | sles | |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | libldb2 | libldb2@4.21.10+git.449.dcced69e1b5-150700.3.19.1 | SUSE-SU-2026:2076-1 | CRITICAL | affected | sles | |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | libopenssl1_1 | libopenssl1_1@1.1.1w-150700.11.11.1 | SUSE-SU-2026:2392-1 | HIGH | affected | sles | |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | libpython3_6m1_0 | libpython3_6m1_0@3.6.15-150300.10.106.1 | SUSE-SU-2026:1090-1 | HIGH | affected | sles | |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | libpython3_6m1_0 | libpython3_6m1_0@3.6.15-150300.10.106.1 | SUSE-SU-2026:1715-1 | HIGH | affected | sles | |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-150700.11.5.2 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.51.2-150000.3.36.1 | SUSE-SU-2026:2528-1 | HIGH | affected | sles | |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | libudev1 | libudev1@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | libzypp | libzypp@17.37.18-150700.6.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | samba-client-libs | samba-client-libs@4.21.10+git.449.dcced69e1b5-150700.3.19.1 | SUSE-SU-2026:2076-1 | CRITICAL | affected | sles | |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | systemd | systemd@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-150700.13.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/sbin/longhorn-manager | go.opentelemetry.io/otel@v1.38.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/sbin/longhorn-manager | golang.org/x/net@v0.49.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/sbin/longhorn-manager | golang.org/x/net@v0.49.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/sbin/longhorn-manager | google.golang.org/grpc@v1.78.0 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/sbin/longhorn-manager | stdlib@v1.25.8 | CVE-2026-32280 | HIGH | affected | gobinary | |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/sbin/longhorn-manager | stdlib@v1.25.8 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/sbin/longhorn-manager | stdlib@v1.25.8 | CVE-2026-39836 | HIGH | affected | gobinary | |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | curl | curl@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | glibc-devel | glibc-devel@2.38-150600.14.43.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | glibc-devel | glibc-devel@2.38-150600.14.43.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | HIGH | affected | sles | |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | libnghttp2-14 | libnghttp2-14@1.64.0-150700.1.5 | SUSE-SU-2026:1074-1 | HIGH | affected | sles | |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-150700.11.5.2 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.51.2-150000.3.36.1 | SUSE-SU-2026:2528-1 | HIGH | affected | sles | |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | libsystemd0 | libsystemd0@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | libudev1 | libudev1@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | libzypp | libzypp@17.37.18-150700.6.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | systemd | systemd@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-150700.13.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | longhorn-share-manager | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | longhorn-share-manager | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | longhorn-share-manager | google.golang.org/grpc@v1.78.0 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | longhorn-share-manager | stdlib@v1.25.8 | CVE-2026-32280 | HIGH | affected | gobinary | |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | longhorn-share-manager | stdlib@v1.25.8 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | longhorn-share-manager | stdlib@v1.25.8 | CVE-2026-39836 | HIGH | affected | gobinary | |
| longhornio/longhorn-ui:v1.11.1 | false | Harvester v1.8.0 | curl | curl@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| longhornio/longhorn-ui:v1.11.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| longhornio/longhorn-ui:v1.11.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| longhornio/longhorn-ui:v1.11.1 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | HIGH | affected | sles | |
| longhornio/longhorn-ui:v1.11.1 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| longhornio/longhorn-ui:v1.11.1 | false | Harvester v1.8.0 | libnghttp2-14 | libnghttp2-14@1.64.0-150700.1.5 | SUSE-SU-2026:1074-1 | HIGH | affected | sles | |
| longhornio/longhorn-ui:v1.11.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| longhornio/longhorn-ui:v1.11.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| longhornio/longhorn-ui:v1.11.1 | false | Harvester v1.8.0 | libpng16-16 | libpng16-16@1.6.40-150600.3.12.1 | SUSE-SU-2026:1368-1 | HIGH | affected | sles | |
| longhornio/longhorn-ui:v1.11.1 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-150700.11.5.2 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| longhornio/longhorn-ui:v1.11.1 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.51.2-150000.3.36.1 | SUSE-SU-2026:2528-1 | HIGH | affected | sles | |
| longhornio/longhorn-ui:v1.11.1 | false | Harvester v1.8.0 | libtiff5 | libtiff5@4.0.9-150000.45.60.1 | SUSE-SU-2026:1965-1 | HIGH | affected | sles | |
| longhornio/longhorn-ui:v1.11.1 | false | Harvester v1.8.0 | libudev1 | libudev1@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| longhornio/longhorn-ui:v1.11.1 | false | Harvester v1.8.0 | libzypp | libzypp@17.37.18-150700.6.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| longhornio/longhorn-ui:v1.11.1 | false | Harvester v1.8.0 | nginx | nginx@1.21.5-150600.10.12.1 | SUSE-SU-2026:1761-1 | HIGH | affected | sles | |
| longhornio/longhorn-ui:v1.11.1 | false | Harvester v1.8.0 | nginx | nginx@1.21.5-150600.10.12.1 | SUSE-SU-2026:2050-1 | HIGH | affected | sles | |
| longhornio/longhorn-ui:v1.11.1 | false | Harvester v1.8.0 | nginx | nginx@1.21.5-150600.10.12.1 | SUSE-SU-2026:2307-1 | HIGH | affected | sles | |
| longhornio/longhorn-ui:v1.11.1 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-150700.13.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | curl | curl@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | HIGH | affected | sles | |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | libnghttp2-14 | libnghttp2-14@1.64.0-150700.1.5 | SUSE-SU-2026:1074-1 | HIGH | affected | sles | |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-150700.11.5.2 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.51.2-150000.3.36.1 | SUSE-SU-2026:2528-1 | HIGH | affected | sles | |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | libsystemd0 | libsystemd0@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | libudev1 | libudev1@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | libzypp | libzypp@17.37.18-150700.6.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-150700.13.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/support-bundle-kit | golang.org/x/net@v0.50.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/support-bundle-kit | golang.org/x/net@v0.50.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/support-bundle-kit | golang.org/x/net@v0.50.0 | CVE-2026-27141 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/support-bundle-kit | google.golang.org/grpc@v1.71.1 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/support-bundle-kit | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/support-bundle-kit | stdlib@v1.25.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/support-bundle-kit | stdlib@v1.25.7 | CVE-2026-39820 | HIGH | affected | gobinary | |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/support-bundle-kit | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/support-bundle-kit | stdlib@v1.25.7 | CVE-2026-42499 | HIGH | affected | gobinary | |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/yq | golang.org/x/net@v0.50.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.37.1 | SUSE-SU-2026:0371-1 | HIGH | affected | sles | |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.37.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.37.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | usr/bin/alertmanager | golang.org/x/net@v0.33.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | usr/bin/alertmanager | golang.org/x/net@v0.33.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | usr/bin/alertmanager | stdlib@v1.25.3 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | usr/bin/alertmanager | stdlib@v1.25.3 | CVE-2025-61729 | HIGH | affected | gobinary | |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | usr/bin/alertmanager | stdlib@v1.25.3 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | usr/bin/alertmanager | stdlib@v1.25.3 | CVE-2026-33811 | HIGH | affected | gobinary | |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | usr/bin/alertmanager | stdlib@v1.25.3 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | usr/bin/alertmanager | stdlib@v1.25.3 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | usr/bin/alertmanager | stdlib@v1.25.3 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | usr/bin/alertmanager | stdlib@v1.25.3 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | usr/bin/alertmanager | stdlib@v1.25.3 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.37.1 | SUSE-SU-2026:0371-1 | HIGH | affected | sles | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.37.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.37.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | HIGH | affected | sles | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | github.com/apache/thrift@v0.21.0 | CVE-2026-41602 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | github.com/go-git/go-billy/v5@v5.6.2 | CVE-2026-44973 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | github.com/go-git/go-billy/v5@v5.6.2 | CVE-2026-44740 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | github.com/go-git/go-git/v5@v5.14.0 | CVE-2026-45022 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | github.com/go-jose/go-jose/v3@v3.0.4 | CVE-2026-34986 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | github.com/go-jose/go-jose/v4@v4.1.0 | CVE-2026-34986 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | github.com/grafana/grafana@12.1.1 | CVE-2025-41115 | CRITICAL | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | github.com/grafana/grafana@12.1.1 | CVE-2026-27877 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | github.com/grafana/tempo@v1.5.1-0.20250529124718-87c2dc380cec | CVE-2026-21728 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | github.com/grafana/tempo@v1.5.1-0.20250529124718-87c2dc380cec | CVE-2026-28377 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | github.com/jackc/pgx/v5@v5.7.5 | CVE-2026-33816 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | github.com/openfga/openfga@v1.8.13 | CVE-2025-64751 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | github.com/prometheus/prometheus@v0.303.1 | CVE-2026-42151 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | github.com/prometheus/prometheus@v0.303.1 | CVE-2026-42154 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | go.opentelemetry.io/otel@v1.36.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | golang.org/x/crypto@v0.39.0 | CVE-2025-47913 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | golang.org/x/crypto@v0.39.0 | CVE-2026-39828 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | golang.org/x/crypto@v0.39.0 | CVE-2026-39829 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | golang.org/x/crypto@v0.39.0 | CVE-2026-39835 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | golang.org/x/crypto@v0.39.0 | CVE-2026-42508 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | golang.org/x/crypto@v0.39.0 | CVE-2026-46595 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | golang.org/x/crypto@v0.39.0 | CVE-2026-46597 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | golang.org/x/crypto@v0.39.0 | CVE-2026-39831 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | golang.org/x/crypto@v0.39.0 | CVE-2026-39832 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | golang.org/x/crypto@v0.39.0 | CVE-2026-39833 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | golang.org/x/crypto@v0.39.0 | CVE-2026-39834 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | golang.org/x/crypto@v0.39.0 | CVE-2026-46598 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | golang.org/x/net@v0.41.0 | CVE-2026-25680 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | golang.org/x/net@v0.41.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | golang.org/x/net@v0.41.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | google.golang.org/grpc@v1.73.0 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | stdlib@v1.25.1 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | stdlib@v1.25.1 | CVE-2025-61729 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | stdlib@v1.25.1 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | stdlib@v1.25.1 | CVE-2026-33811 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | stdlib@v1.25.1 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | stdlib@v1.25.1 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | stdlib@v1.25.1 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | stdlib@v1.25.1 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | stdlib@v1.25.1 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | stdlib@v1.25.1 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | stdlib@v1.25.1 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana-cli | github.com/grafana/grafana@12.1.1 | CVE-2025-41115 | CRITICAL | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana-cli | github.com/grafana/grafana@12.1.1 | CVE-2026-27877 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana-cli | stdlib@v1.25.1 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana-cli | stdlib@v1.25.1 | CVE-2025-61729 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana-cli | stdlib@v1.25.1 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana-cli | stdlib@v1.25.1 | CVE-2026-33811 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana-cli | stdlib@v1.25.1 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana-cli | stdlib@v1.25.1 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana-cli | stdlib@v1.25.1 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana-cli | stdlib@v1.25.1 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana-cli | stdlib@v1.25.1 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana-cli | stdlib@v1.25.1 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana-cli | stdlib@v1.25.1 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana-server | github.com/grafana/grafana@12.1.1 | CVE-2025-41115 | CRITICAL | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana-server | github.com/grafana/grafana@12.1.1 | CVE-2026-27877 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana-server | stdlib@v1.25.1 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana-server | stdlib@v1.25.1 | CVE-2025-61729 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana-server | stdlib@v1.25.1 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana-server | stdlib@v1.25.1 | CVE-2026-33811 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana-server | stdlib@v1.25.1 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana-server | stdlib@v1.25.1 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana-server | stdlib@v1.25.1 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana-server | stdlib@v1.25.1 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana-server | stdlib@v1.25.1 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana-server | stdlib@v1.25.1 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana-server | stdlib@v1.25.1 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-k8s-sidecar:1.30.7-11.3 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.32.1 | SUSE-SU-2026:0371-1 | HIGH | affected | sles | |
| rancher/appco-k8s-sidecar:1.30.7-11.3 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.32.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| rancher/appco-k8s-sidecar:1.30.7-11.3 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.32.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| rancher/appco-k8s-sidecar:1.30.7-11.3 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | HIGH | affected | sles | |
| rancher/appco-k8s-sidecar:1.30.7-11.3 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.1.4-150600.5.33.1 | SUSE-SU-2026:0312-1 | CRITICAL | affected | sles | |
| rancher/appco-k8s-sidecar:1.30.7-11.3 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.1.4-150600.5.33.1 | SUSE-SU-2025:03442-1 | HIGH | affected | sles | |
| rancher/appco-k8s-sidecar:1.30.7-11.3 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.1.4-150600.5.33.1 | SUSE-SU-2026:1215-1 | HIGH | affected | sles | |
| rancher/appco-k8s-sidecar:1.30.7-11.3 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.1.4-150600.5.33.1 | SUSE-SU-2026:2393-1 | HIGH | affected | sles | |
| rancher/appco-k8s-sidecar:1.30.7-11.3 | false | Harvester v1.8.0 | libpython3_11-1_0 | libpython3_11-1_0@3.11.13-150600.3.30.1 | SUSE-SU-2025:02717-1 | HIGH | affected | sles | |
| rancher/appco-k8s-sidecar:1.30.7-11.3 | false | Harvester v1.8.0 | libpython3_11-1_0 | libpython3_11-1_0@3.11.13-150600.3.30.1 | SUSE-SU-2026:0767-1 | HIGH | affected | sles | |
| rancher/appco-k8s-sidecar:1.30.7-11.3 | false | Harvester v1.8.0 | libpython3_11-1_0 | libpython3_11-1_0@3.11.13-150600.3.30.1 | SUSE-SU-2026:1349-1 | HIGH | affected | sles | |
| rancher/appco-k8s-sidecar:1.30.7-11.3 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.50.2-150000.3.33.1 | SUSE-SU-2026:2528-1 | HIGH | affected | sles | |
| rancher/appco-k8s-sidecar:1.30.7-11.3 | false | Harvester v1.8.0 | python311 | python311@3.11.13-150600.3.30.1 | SUSE-SU-2025:02717-1 | HIGH | affected | sles | |
| rancher/appco-k8s-sidecar:1.30.7-11.3 | false | Harvester v1.8.0 | python311 | python311@3.11.13-150600.3.30.1 | SUSE-SU-2026:0767-1 | HIGH | affected | sles | |
| rancher/appco-k8s-sidecar:1.30.7-11.3 | false | Harvester v1.8.0 | python311 | python311@3.11.13-150600.3.30.1 | SUSE-SU-2026:1349-1 | HIGH | affected | sles | |
| rancher/appco-k8s-sidecar:1.30.7-11.3 | false | Harvester v1.8.0 | python311-base | python311-base@3.11.13-150600.3.30.1 | SUSE-SU-2025:02717-1 | HIGH | affected | sles | |
| rancher/appco-k8s-sidecar:1.30.7-11.3 | false | Harvester v1.8.0 | python311-base | python311-base@3.11.13-150600.3.30.1 | SUSE-SU-2026:0767-1 | HIGH | affected | sles | |
| rancher/appco-k8s-sidecar:1.30.7-11.3 | false | Harvester v1.8.0 | python311-base | python311-base@3.11.13-150600.3.30.1 | SUSE-SU-2026:1349-1 | HIGH | affected | sles | |
| rancher/appco-k8s-sidecar:1.30.7-11.3 | false | Harvester v1.8.0 | Python | pyasn1@0.6.1 | CVE-2026-23490 | HIGH | affected | python-pkg | |
| rancher/appco-k8s-sidecar:1.30.7-11.3 | false | Harvester v1.8.0 | Python | pyasn1@0.6.1 | CVE-2026-30922 | HIGH | affected | python-pkg | |
| rancher/appco-k8s-sidecar:1.30.7-11.3 | false | Harvester v1.8.0 | Python | urllib3@2.5.0 | CVE-2025-66418 | HIGH | affected | python-pkg | |
| rancher/appco-k8s-sidecar:1.30.7-11.3 | false | Harvester v1.8.0 | Python | urllib3@2.5.0 | CVE-2025-66471 | HIGH | affected | python-pkg | |
| rancher/appco-k8s-sidecar:1.30.7-11.3 | false | Harvester v1.8.0 | Python | urllib3@2.5.0 | CVE-2026-21441 | HIGH | affected | python-pkg | |
| rancher/appco-k8s-sidecar:1.30.7-11.3 | false | Harvester v1.8.0 | Python | urllib3@2.5.0 | CVE-2026-44431 | HIGH | affected | python-pkg | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.37.1 | SUSE-SU-2026:0371-1 | HIGH | affected | sles | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.37.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.37.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | HIGH | affected | sles | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | usr/bin/kube-state-metrics | golang.org/x/crypto@v0.40.0 | CVE-2025-47913 | HIGH | affected | gobinary | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | usr/bin/kube-state-metrics | golang.org/x/crypto@v0.40.0 | CVE-2026-39828 | HIGH | affected | gobinary | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | usr/bin/kube-state-metrics | golang.org/x/crypto@v0.40.0 | CVE-2026-39829 | HIGH | affected | gobinary | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | usr/bin/kube-state-metrics | golang.org/x/crypto@v0.40.0 | CVE-2026-39835 | HIGH | affected | gobinary | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | usr/bin/kube-state-metrics | golang.org/x/crypto@v0.40.0 | CVE-2026-42508 | HIGH | affected | gobinary | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | usr/bin/kube-state-metrics | golang.org/x/crypto@v0.40.0 | CVE-2026-46595 | HIGH | affected | gobinary | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | usr/bin/kube-state-metrics | golang.org/x/crypto@v0.40.0 | CVE-2026-46597 | HIGH | affected | gobinary | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | usr/bin/kube-state-metrics | golang.org/x/crypto@v0.40.0 | CVE-2026-39831 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | usr/bin/kube-state-metrics | golang.org/x/crypto@v0.40.0 | CVE-2026-39832 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | usr/bin/kube-state-metrics | golang.org/x/crypto@v0.40.0 | CVE-2026-39833 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | usr/bin/kube-state-metrics | golang.org/x/crypto@v0.40.0 | CVE-2026-39834 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | usr/bin/kube-state-metrics | golang.org/x/crypto@v0.40.0 | CVE-2026-46598 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | usr/bin/kube-state-metrics | golang.org/x/net@v0.41.0 | CVE-2026-25680 | HIGH | affected | gobinary | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | usr/bin/kube-state-metrics | golang.org/x/net@v0.41.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | usr/bin/kube-state-metrics | golang.org/x/net@v0.41.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | usr/bin/kube-state-metrics | google.golang.org/grpc@v1.68.1 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | usr/bin/kube-state-metrics | stdlib@v1.25.4 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | usr/bin/kube-state-metrics | stdlib@v1.25.4 | CVE-2025-61729 | HIGH | affected | gobinary | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | usr/bin/kube-state-metrics | stdlib@v1.25.4 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | usr/bin/kube-state-metrics | stdlib@v1.25.4 | CVE-2026-33811 | HIGH | affected | gobinary | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | usr/bin/kube-state-metrics | stdlib@v1.25.4 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | usr/bin/kube-state-metrics | stdlib@v1.25.4 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | usr/bin/kube-state-metrics | stdlib@v1.25.4 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | usr/bin/kube-state-metrics | stdlib@v1.25.4 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | usr/bin/kube-state-metrics | stdlib@v1.25.4 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.37.1 | SUSE-SU-2026:0371-1 | HIGH | affected | sles | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.37.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.37.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | HIGH | affected | sles | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | usr/bin/node_exporter | github.com/opencontainers/selinux@v1.11.1 | CVE-2025-52881 | HIGH | affected | gobinary | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | usr/bin/node_exporter | golang.org/x/crypto@v0.36.0 | CVE-2026-39828 | HIGH | affected | gobinary | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | usr/bin/node_exporter | golang.org/x/crypto@v0.36.0 | CVE-2026-39829 | HIGH | affected | gobinary | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | usr/bin/node_exporter | golang.org/x/crypto@v0.36.0 | CVE-2026-39835 | HIGH | affected | gobinary | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | usr/bin/node_exporter | golang.org/x/crypto@v0.36.0 | CVE-2026-42508 | HIGH | affected | gobinary | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | usr/bin/node_exporter | golang.org/x/crypto@v0.36.0 | CVE-2026-46595 | HIGH | affected | gobinary | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | usr/bin/node_exporter | golang.org/x/crypto@v0.36.0 | CVE-2026-46597 | HIGH | affected | gobinary | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | usr/bin/node_exporter | golang.org/x/crypto@v0.36.0 | CVE-2026-39831 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | usr/bin/node_exporter | golang.org/x/crypto@v0.36.0 | CVE-2026-39832 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | usr/bin/node_exporter | golang.org/x/crypto@v0.36.0 | CVE-2026-39833 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | usr/bin/node_exporter | golang.org/x/crypto@v0.36.0 | CVE-2026-39834 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | usr/bin/node_exporter | golang.org/x/crypto@v0.36.0 | CVE-2026-46598 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | usr/bin/node_exporter | golang.org/x/net@v0.37.0 | CVE-2026-25680 | HIGH | affected | gobinary | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | usr/bin/node_exporter | golang.org/x/net@v0.37.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | usr/bin/node_exporter | golang.org/x/net@v0.37.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | usr/bin/node_exporter | stdlib@v1.25.3 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | usr/bin/node_exporter | stdlib@v1.25.3 | CVE-2025-61729 | HIGH | affected | gobinary | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | usr/bin/node_exporter | stdlib@v1.25.3 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | usr/bin/node_exporter | stdlib@v1.25.3 | CVE-2026-33811 | HIGH | affected | gobinary | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | usr/bin/node_exporter | stdlib@v1.25.3 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | usr/bin/node_exporter | stdlib@v1.25.3 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | usr/bin/node_exporter | stdlib@v1.25.3 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | usr/bin/node_exporter | stdlib@v1.25.3 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | usr/bin/node_exporter | stdlib@v1.25.3 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | google.golang.org/grpc@v1.72.3 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | stdlib@v1.24.6 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | stdlib@v1.24.6 | CVE-2025-61729 | HIGH | affected | gobinary | |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | stdlib@v1.24.6 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | stdlib@v1.24.6 | CVE-2026-33811 | HIGH | affected | gobinary | |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | stdlib@v1.24.6 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | stdlib@v1.24.6 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | stdlib@v1.24.6 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | stdlib@v1.24.6 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | stdlib@v1.24.6 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | stdlib@v1.24.6 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | stdlib@v1.24.6 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | busybox | busybox@1.37.0-150700.18.15.1 | SUSE-SU-2026:2054-1 | HIGH | affected | sles | |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetagent | github.com/rancher/fleet@v0.15.0 | CVE-2026-41050 | CRITICAL | affected | gobinary | |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetagent | golang.org/x/crypto@v0.48.0 | CVE-2026-39829 | HIGH | affected | gobinary | |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetagent | golang.org/x/crypto@v0.48.0 | CVE-2026-39835 | HIGH | affected | gobinary | |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetagent | golang.org/x/crypto@v0.48.0 | CVE-2026-42508 | HIGH | affected | gobinary | |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetagent | golang.org/x/crypto@v0.48.0 | CVE-2026-46597 | HIGH | affected | gobinary | |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetagent | golang.org/x/crypto@v0.48.0 | CVE-2026-39831 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetagent | golang.org/x/crypto@v0.48.0 | CVE-2026-39834 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetagent | golang.org/x/net@v0.50.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetagent | golang.org/x/net@v0.50.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetagent | golang.org/x/net@v0.50.0 | CVE-2026-27141 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetagent | helm.sh/helm/v4@v4.1.1 | CVE-2026-35204 | HIGH | affected | gobinary | |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetagent | helm.sh/helm/v4@v4.1.1 | CVE-2026-35205 | HIGH | affected | gobinary | |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetagent | stdlib@v1.25.8 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetagent | stdlib@v1.25.8 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetagent | stdlib@v1.25.8 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | HIGH | affected | sles | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-150700.11.5.2 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.51.2-150000.3.36.1 | SUSE-SU-2026:2528-1 | HIGH | affected | sles | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | libzypp | libzypp@17.37.18-150700.6.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | openssh-common | openssh-common@9.6p1-150600.6.34.1 | SUSE-SU-2026:2371-1 | HIGH | affected | sles | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | openssh-fips | openssh-fips@9.6p1-150600.6.34.1 | SUSE-SU-2026:1876-1 | HIGH | affected | sles | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | openssh-fips | openssh-fips@9.6p1-150600.6.34.1 | SUSE-SU-2026:2371-1 | HIGH | affected | sles | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-150700.13.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | github.com/go-git/go-billy/v5@v5.8.0 | CVE-2026-44973 | HIGH | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | github.com/go-git/go-billy/v5@v5.8.0 | CVE-2026-44740 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | github.com/go-git/go-git/v5@v5.17.0 | CVE-2026-45022 | HIGH | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | github.com/rancher/fleet@v0.15.0 | CVE-2026-41050 | CRITICAL | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | golang.org/x/crypto@v0.48.0 | CVE-2026-39829 | HIGH | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | golang.org/x/crypto@v0.48.0 | CVE-2026-39835 | HIGH | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | golang.org/x/crypto@v0.48.0 | CVE-2026-42508 | HIGH | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | golang.org/x/crypto@v0.48.0 | CVE-2026-46597 | HIGH | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | golang.org/x/crypto@v0.48.0 | CVE-2026-39831 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | golang.org/x/crypto@v0.48.0 | CVE-2026-39834 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | golang.org/x/net@v0.50.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | golang.org/x/net@v0.50.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | golang.org/x/net@v0.50.0 | CVE-2026-27141 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | helm.sh/helm/v4@v4.1.1 | CVE-2026-35204 | HIGH | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | helm.sh/helm/v4@v4.1.1 | CVE-2026-35205 | HIGH | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | stdlib@v1.25.8 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | stdlib@v1.25.8 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | stdlib@v1.25.8 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | github.com/go-git/go-billy/v5@v5.8.0 | CVE-2026-44973 | HIGH | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | github.com/go-git/go-billy/v5@v5.8.0 | CVE-2026-44740 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | github.com/go-git/go-git/v5@v5.17.0 | CVE-2026-45022 | HIGH | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | github.com/rancher/fleet@v0.15.0 | CVE-2026-41050 | CRITICAL | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | golang.org/x/crypto@v0.48.0 | CVE-2026-39829 | HIGH | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | golang.org/x/crypto@v0.48.0 | CVE-2026-39835 | HIGH | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | golang.org/x/crypto@v0.48.0 | CVE-2026-42508 | HIGH | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | golang.org/x/crypto@v0.48.0 | CVE-2026-46597 | HIGH | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | golang.org/x/crypto@v0.48.0 | CVE-2026-39831 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | golang.org/x/crypto@v0.48.0 | CVE-2026-39834 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | golang.org/x/net@v0.50.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | golang.org/x/net@v0.50.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | golang.org/x/net@v0.50.0 | CVE-2026-27141 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | helm.sh/helm/v4@v4.1.1 | CVE-2026-35204 | HIGH | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | helm.sh/helm/v4@v4.1.1 | CVE-2026-35205 | HIGH | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | stdlib@v1.25.8 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | stdlib@v1.25.8 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | stdlib@v1.25.8 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/hardened-addon-resizer:1.8.23-build20260206 | false | Harvester v1.8.0 | pod_nanny | golang.org/x/net@v0.33.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-addon-resizer:1.8.23-build20260206 | false | Harvester v1.8.0 | pod_nanny | golang.org/x/net@v0.33.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/hardened-addon-resizer:1.8.23-build20260206 | false | Harvester v1.8.0 | pod_nanny | stdlib@v1.24.13 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/hardened-addon-resizer:1.8.23-build20260206 | false | Harvester v1.8.0 | pod_nanny | stdlib@v1.24.13 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-addon-resizer:1.8.23-build20260206 | false | Harvester v1.8.0 | pod_nanny | stdlib@v1.24.13 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/hardened-cluster-autoscaler:v1.10.3-build20260206 | false | Harvester v1.8.0 | cluster-proportional-autoscaler | golang.org/x/net@v0.36.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-cluster-autoscaler:v1.10.3-build20260206 | false | Harvester v1.8.0 | cluster-proportional-autoscaler | golang.org/x/net@v0.36.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/hardened-cluster-autoscaler:v1.10.3-build20260206 | false | Harvester v1.8.0 | cluster-proportional-autoscaler | stdlib@v1.24.13 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/hardened-cluster-autoscaler:v1.10.3-build20260206 | false | Harvester v1.8.0 | cluster-proportional-autoscaler | stdlib@v1.24.13 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-cluster-autoscaler:v1.10.3-build20260206 | false | Harvester v1.8.0 | cluster-proportional-autoscaler | stdlib@v1.24.13 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | busybox | busybox@1.37.0-150700.18.12.1 | SUSE-SU-2026:0759-1 | HIGH | affected | sles | |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | busybox | busybox@1.37.0-150700.18.12.1 | SUSE-SU-2026:2054-1 | HIGH | affected | sles | |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.40.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.40.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | busybox | busybox@1.37.0-150700.18.12.1 | SUSE-SU-2026:0759-1 | HIGH | affected | sles | |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.40.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.40.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | github.com/coredns/coredns@v1.14.1 | CVE-2026-26017 | HIGH | affected | gobinary | |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | github.com/coredns/coredns@v1.14.1 | CVE-2026-26018 | HIGH | affected | gobinary | |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | github.com/coredns/coredns@v1.14.1 | CVE-2026-32934 | HIGH | affected | gobinary | |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | github.com/coredns/coredns@v1.14.1 | CVE-2026-32936 | HIGH | affected | gobinary | |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | github.com/coredns/coredns@v1.14.1 | CVE-2026-33190 | HIGH | affected | gobinary | |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | github.com/coredns/coredns@v1.14.1 | CVE-2026-33489 | HIGH | affected | gobinary | |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | github.com/coredns/coredns@v1.14.1 | CVE-2026-35579 | HIGH | affected | gobinary | |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | go.opentelemetry.io/otel@v1.38.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | golang.org/x/net@v0.49.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | golang.org/x/net@v0.49.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | google.golang.org/grpc@v1.78.0 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | stdlib@v1.24.13 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | stdlib@v1.24.13 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | stdlib@v1.24.13 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | busybox | busybox@1.37.0-150700.18.12.1 | SUSE-SU-2026:0759-1 | HIGH | affected | sles | |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.40.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.40.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | github.com/coredns/coredns@v1.13.1 | CVE-2026-26017 | HIGH | affected | gobinary | |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | github.com/coredns/coredns@v1.13.1 | CVE-2026-26018 | HIGH | affected | gobinary | |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | github.com/coredns/coredns@v1.13.1 | CVE-2026-32934 | HIGH | affected | gobinary | |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | github.com/coredns/coredns@v1.13.1 | CVE-2026-32936 | HIGH | affected | gobinary | |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | github.com/coredns/coredns@v1.13.1 | CVE-2026-33190 | HIGH | affected | gobinary | |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | github.com/coredns/coredns@v1.13.1 | CVE-2026-33489 | HIGH | affected | gobinary | |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | github.com/coredns/coredns@v1.13.1 | CVE-2026-35579 | HIGH | affected | gobinary | |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | github.com/coredns/coredns@v1.13.1 | CVE-2025-68151 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | go.opentelemetry.io/otel@v1.37.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | golang.org/x/net@v0.46.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | golang.org/x/net@v0.46.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | google.golang.org/grpc@v1.75.1 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | stdlib@v1.24.13 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | stdlib@v1.24.13 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | stdlib@v1.24.13 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcd | stdlib@v1.24.13 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcd | stdlib@v1.24.13 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcd | stdlib@v1.24.13 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcdctl | stdlib@v1.24.13 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcdctl | stdlib@v1.24.13 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcdctl | stdlib@v1.24.13 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.40.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.40.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | opt/bin/flanneld | github.com/flannel-io/flannel@v0.28.1 | CVE-2026-32241 | HIGH | affected | gobinary | |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | opt/bin/flanneld | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | opt/bin/flanneld | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | opt/bin/flanneld | stdlib@v1.24.13 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | opt/bin/flanneld | stdlib@v1.24.13 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | opt/bin/flanneld | stdlib@v1.24.13 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | github.com/prometheus/prometheus@v0.304.2 | CVE-2026-42151 | HIGH | affected | gobinary | |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | github.com/prometheus/prometheus@v0.304.2 | CVE-2026-42154 | HIGH | affected | gobinary | |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | golang.org/x/net@v0.40.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | golang.org/x/net@v0.40.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | stdlib@v1.24.13 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | stdlib@v1.24.13 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | stdlib@v1.24.13 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | stdlib@v1.24.13 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | stdlib@v1.24.13 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | curl | curl@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.40.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.40.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | HIGH | affected | sles | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | libnghttp2-14 | libnghttp2-14@1.64.0-150700.1.5 | SUSE-SU-2026:1074-1 | HIGH | affected | sles | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-150700.11.5.2 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.51.2-150000.3.36.1 | SUSE-SU-2026:2528-1 | HIGH | affected | sles | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | libudev1 | libudev1@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | libzypp | libzypp@17.37.18-150700.6.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-150700.13.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-apiserver | go.opentelemetry.io/otel@v1.36.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-apiserver | golang.org/x/crypto@v0.45.0 | CVE-2026-39829 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-apiserver | golang.org/x/crypto@v0.45.0 | CVE-2026-46597 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-apiserver | golang.org/x/crypto@v0.45.0 | CVE-2026-39831 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-apiserver | golang.org/x/crypto@v0.45.0 | CVE-2026-39834 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-apiserver | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-apiserver | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-apiserver | stdlib@v1.25.7 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-apiserver | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-apiserver | stdlib@v1.25.7 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-controller-manager | go.opentelemetry.io/otel@v1.36.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-controller-manager | golang.org/x/crypto@v0.45.0 | CVE-2026-39829 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-controller-manager | golang.org/x/crypto@v0.45.0 | CVE-2026-46597 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-controller-manager | golang.org/x/crypto@v0.45.0 | CVE-2026-39831 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-controller-manager | golang.org/x/crypto@v0.45.0 | CVE-2026-39834 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-controller-manager | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-controller-manager | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-controller-manager | stdlib@v1.25.7 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-controller-manager | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-controller-manager | stdlib@v1.25.7 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-proxy | go.opentelemetry.io/otel@v1.36.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-proxy | golang.org/x/crypto@v0.45.0 | CVE-2026-39829 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-proxy | golang.org/x/crypto@v0.45.0 | CVE-2026-46597 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-proxy | golang.org/x/crypto@v0.45.0 | CVE-2026-39831 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-proxy | golang.org/x/crypto@v0.45.0 | CVE-2026-39834 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-proxy | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-proxy | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-proxy | stdlib@v1.25.7 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-proxy | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-proxy | stdlib@v1.25.7 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-scheduler | go.opentelemetry.io/otel@v1.36.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-scheduler | golang.org/x/crypto@v0.45.0 | CVE-2026-39829 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-scheduler | golang.org/x/crypto@v0.45.0 | CVE-2026-46597 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-scheduler | golang.org/x/crypto@v0.45.0 | CVE-2026-39831 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-scheduler | golang.org/x/crypto@v0.45.0 | CVE-2026-39834 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-scheduler | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-scheduler | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-scheduler | stdlib@v1.25.7 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-scheduler | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-scheduler | stdlib@v1.25.7 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubectl | go.opentelemetry.io/otel@v1.36.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubectl | stdlib@v1.25.7 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubectl | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubectl | stdlib@v1.25.7 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubelet | go.opentelemetry.io/otel@v1.36.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubelet | golang.org/x/crypto@v0.45.0 | CVE-2026-39829 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubelet | golang.org/x/crypto@v0.45.0 | CVE-2026-46597 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubelet | golang.org/x/crypto@v0.45.0 | CVE-2026-39831 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubelet | golang.org/x/crypto@v0.45.0 | CVE-2026-39834 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubelet | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubelet | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubelet | stdlib@v1.25.7 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubelet | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubelet | stdlib@v1.25.7 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | cert-approver | golang.org/x/net@v0.41.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | cert-approver | golang.org/x/net@v0.41.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | cert-approver | stdlib@v1.24.13 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | cert-approver | stdlib@v1.24.13 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | cert-approver | stdlib@v1.24.13 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | install_multus | stdlib@v1.24.13 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | install_multus | stdlib@v1.24.13 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | install_multus | stdlib@v1.24.13 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | kubeconfig_generator | golang.org/x/net@v0.41.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | kubeconfig_generator | golang.org/x/net@v0.41.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | kubeconfig_generator | stdlib@v1.24.13 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | kubeconfig_generator | stdlib@v1.24.13 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | kubeconfig_generator | stdlib@v1.24.13 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | thin_entrypoint | stdlib@v1.24.13 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | thin_entrypoint | stdlib@v1.24.13 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | thin_entrypoint | stdlib@v1.24.13 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | usr/src/multus-cni/bin/multus | golang.org/x/net@v0.41.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | usr/src/multus-cni/bin/multus | golang.org/x/net@v0.41.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | usr/src/multus-cni/bin/multus | stdlib@v1.24.13 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | usr/src/multus-cni/bin/multus | stdlib@v1.24.13 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | usr/src/multus-cni/bin/multus | stdlib@v1.24.13 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/hardened-snapshot-controller:v8.4.0-build20260205 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/net@v0.39.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-snapshot-controller:v8.4.0-build20260205 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/net@v0.39.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/hardened-snapshot-controller:v8.4.0-build20260205 | false | Harvester v1.8.0 | snapshot-controller | stdlib@v1.24.13 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/hardened-snapshot-controller:v8.4.0-build20260205 | false | Harvester v1.8.0 | snapshot-controller | stdlib@v1.24.13 | CVE-2026-33811 | HIGH | affected | gobinary | |
| rancher/hardened-snapshot-controller:v8.4.0-build20260205 | false | Harvester v1.8.0 | snapshot-controller | stdlib@v1.24.13 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/hardened-snapshot-controller:v8.4.0-build20260205 | false | Harvester v1.8.0 | snapshot-controller | stdlib@v1.24.13 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/hardened-snapshot-controller:v8.4.0-build20260205 | false | Harvester v1.8.0 | snapshot-controller | stdlib@v1.24.13 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/hardened-snapshot-controller:v8.4.0-build20260205 | false | Harvester v1.8.0 | snapshot-controller | stdlib@v1.24.13 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/harvester-cluster-repo:v1.8.0 | false | Harvester v1.8.0 | glibc | glibc@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/harvester-cluster-repo:v1.8.0 | false | Harvester v1.8.0 | glibc-locale-base | glibc-locale-base@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/harvester-cluster-repo:v1.8.0 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.8.1-160000.2.2 | SUSE-SU-2026:21848-1 | HIGH | affected | sles | |
| rancher/harvester-cluster-repo:v1.8.0 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | HIGH | affected | sles | |
| rancher/harvester-cluster-repo:v1.8.0 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-cluster-repo:v1.8.0 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.50.4-160000.1.2 | SUSE-SU-2026:22166-1 | HIGH | affected | sles | |
| rancher/harvester-cluster-repo:v1.8.0 | false | Harvester v1.8.0 | libzypp | libzypp@17.38.2-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-cluster-repo:v1.8.0 | false | Harvester v1.8.0 | nginx | nginx@1.27.2-160000.2.2 | SUSE-SU-2026:21823-1 | HIGH | affected | sles | |
| rancher/harvester-cluster-repo:v1.8.0 | false | Harvester v1.8.0 | nginx | nginx@1.27.2-160000.2.2 | SUSE-SU-2026:21832-1 | HIGH | affected | sles | |
| rancher/harvester-cluster-repo:v1.8.0 | false | Harvester v1.8.0 | nginx | nginx@1.27.2-160000.2.2 | SUSE-SU-2026:22178-1 | HIGH | affected | sles | |
| rancher/harvester-cluster-repo:v1.8.0 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | HIGH | affected | sles | |
| rancher/harvester-cluster-repo:v1.8.0 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | glibc | glibc@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | libcap2 | libcap2@2.73-160000.2.2 | SUSE-SU-2026:21373-1 | HIGH | affected | sles | |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | usr/bin/eventrouter | github.com/golang/glog@v0.0.0-20160126235308-23def4e6c14b | CVE-2024-45339 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | usr/bin/eventrouter | golang.org/x/net@v0.38.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | usr/bin/eventrouter | golang.org/x/net@v0.38.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | usr/bin/eventrouter | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | usr/bin/eventrouter | stdlib@v1.25.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | usr/bin/eventrouter | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | glibc | glibc@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | glibc-locale-base | glibc-locale-base@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | libcap2 | libcap2@2.73-160000.2.2 | SUSE-SU-2026:21373-1 | HIGH | affected | sles | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | HIGH | affected | sles | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.50.4-160000.1.2 | SUSE-SU-2026:22166-1 | HIGH | affected | sles | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | libzypp | libzypp@17.38.2-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | manager | go.opentelemetry.io/otel/sdk@v1.34.0 | CVE-2026-24051 | HIGH | affected | gobinary | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | manager | go.opentelemetry.io/otel/sdk@v1.34.0 | CVE-2026-39883 | HIGH | affected | gobinary | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.36.0 | CVE-2025-47913 | HIGH | affected | gobinary | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.36.0 | CVE-2026-39828 | HIGH | affected | gobinary | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.36.0 | CVE-2026-39829 | HIGH | affected | gobinary | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.36.0 | CVE-2026-39835 | HIGH | affected | gobinary | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.36.0 | CVE-2026-42508 | HIGH | affected | gobinary | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.36.0 | CVE-2026-46595 | HIGH | affected | gobinary | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.36.0 | CVE-2026-46597 | HIGH | affected | gobinary | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.36.0 | CVE-2026-39831 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.36.0 | CVE-2026-39832 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.36.0 | CVE-2026-39833 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.36.0 | CVE-2026-39834 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.36.0 | CVE-2026-46598 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | manager | golang.org/x/net@v0.38.0 | CVE-2026-25680 | HIGH | affected | gobinary | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | manager | golang.org/x/net@v0.38.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | manager | golang.org/x/net@v0.38.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | manager | google.golang.org/grpc@v1.72.1 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | manager | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | manager | stdlib@v1.25.7 | CVE-2026-33811 | HIGH | affected | gobinary | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | manager | stdlib@v1.25.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | manager | stdlib@v1.25.7 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | manager | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | manager | stdlib@v1.25.7 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | glibc | glibc@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | libcap2 | libcap2@2.73-160000.2.2 | SUSE-SU-2026:21373-1 | HIGH | affected | sles | |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.8.1-160000.2.2 | SUSE-SU-2026:21848-1 | HIGH | affected | sles | |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | go.opentelemetry.io/otel@v1.36.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | golang.org/x/net@v0.42.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | golang.org/x/net@v0.42.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | stdlib@v1.25.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/harvester-load-balancer:v1.8.0 | false | Harvester v1.8.0 | glibc | glibc@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/harvester-load-balancer:v1.8.0 | false | Harvester v1.8.0 | libcap2 | libcap2@2.73-160000.2.2 | SUSE-SU-2026:21373-1 | HIGH | affected | sles | |
| rancher/harvester-load-balancer:v1.8.0 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.8.1-160000.2.2 | SUSE-SU-2026:21848-1 | HIGH | affected | sles | |
| rancher/harvester-load-balancer:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer | go.opentelemetry.io/otel@v1.36.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/harvester-load-balancer:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer | golang.org/x/net@v0.42.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-load-balancer:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer | golang.org/x/net@v0.42.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/harvester-load-balancer:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/harvester-load-balancer:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer | stdlib@v1.25.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-load-balancer:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/harvester-network-controller:v1.8.0 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.46.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| rancher/harvester-network-controller:v1.8.0 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| rancher/harvester-network-controller:v1.8.0 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-150700.11.5.2 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| rancher/harvester-network-controller:v1.8.0 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.51.3-150000.3.39.1 | SUSE-SU-2026:2528-1 | HIGH | affected | sles | |
| rancher/harvester-network-controller:v1.8.0 | false | Harvester v1.8.0 | libzypp | libzypp@17.37.18-150700.6.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| rancher/harvester-network-controller:v1.8.0 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-150700.13.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| rancher/harvester-network-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-controller | golang.org/x/net@v0.38.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-network-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-controller | golang.org/x/net@v0.38.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/harvester-network-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-controller | stdlib@v1.25.0 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-network-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-controller | stdlib@v1.25.0 | CVE-2025-61729 | HIGH | affected | gobinary | |
| rancher/harvester-network-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-controller | stdlib@v1.25.0 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/harvester-network-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-controller | stdlib@v1.25.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-network-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-controller | stdlib@v1.25.0 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/harvester-network-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-controller | stdlib@v1.25.0 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-network-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-controller | stdlib@v1.25.0 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-network-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-controller | stdlib@v1.25.0 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-network-helper:v1.8.0 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.46.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| rancher/harvester-network-helper:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-helper | golang.org/x/net@v0.38.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-network-helper:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-helper | golang.org/x/net@v0.38.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/harvester-network-helper:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-helper | stdlib@v1.25.0 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-network-helper:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-helper | stdlib@v1.25.0 | CVE-2025-61729 | HIGH | affected | gobinary | |
| rancher/harvester-network-helper:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-helper | stdlib@v1.25.0 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/harvester-network-helper:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-helper | stdlib@v1.25.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-network-helper:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-helper | stdlib@v1.25.0 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/harvester-network-helper:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-helper | stdlib@v1.25.0 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-network-helper:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-helper | stdlib@v1.25.0 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-network-helper:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-helper | stdlib@v1.25.0 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.46.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | golang.org/x/net@v0.38.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | golang.org/x/net@v0.38.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | stdlib@v1.25.0 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | stdlib@v1.25.0 | CVE-2025-61729 | HIGH | affected | gobinary | |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | stdlib@v1.25.0 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | stdlib@v1.25.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | stdlib@v1.25.0 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | stdlib@v1.25.0 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | stdlib@v1.25.0 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | stdlib@v1.25.0 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | glibc | glibc@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | glibc-locale-base | glibc-locale-base@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | libcap2 | libcap2@2.73-160000.2.2 | SUSE-SU-2026:21373-1 | HIGH | affected | sles | |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | HIGH | affected | sles | |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.50.4-160000.1.2 | SUSE-SU-2026:22166-1 | HIGH | affected | sles | |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | libudev1 | libudev1@257.10-160000.1.1 | SUSE-SU-2026:21144-1 | HIGH | affected | sles | |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | libzypp | libzypp@17.38.2-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | HIGH | affected | sles | |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/networkfs-manager | golang.org/x/net@v0.49.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/networkfs-manager | golang.org/x/net@v0.49.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/networkfs-manager | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/networkfs-manager | stdlib@v1.25.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/networkfs-manager | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | glibc | glibc@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | glibc-locale-base | glibc-locale-base@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.8.1-160000.2.2 | SUSE-SU-2026:21848-1 | HIGH | affected | sles | |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.50.4-160000.1.2 | SUSE-SU-2026:22166-1 | HIGH | affected | sles | |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | libzypp | libzypp@17.38.2-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | HIGH | affected | sles | |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager-webhook | golang.org/x/net@v0.49.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager-webhook | golang.org/x/net@v0.49.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager-webhook | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager-webhook | stdlib@v1.25.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager-webhook | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | glibc | glibc@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | libcap2 | libcap2@2.73-160000.2.2 | SUSE-SU-2026:21373-1 | HIGH | affected | sles | |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.8.1-160000.2.2 | SUSE-SU-2026:21848-1 | HIGH | affected | sles | |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | HIGH | affected | sles | |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.50.4-160000.1.2 | SUSE-SU-2026:22166-1 | HIGH | affected | sles | |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | libudev1 | libudev1@257.10-160000.1.1 | SUSE-SU-2026:21144-1 | HIGH | affected | sles | |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | libzypp | libzypp@17.38.2-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | HIGH | affected | sles | |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | xz | xz@5.8.1-160000.2.2 | SUSE-SU-2026:21848-1 | HIGH | affected | sles | |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager | golang.org/x/net@v0.49.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager | golang.org/x/net@v0.49.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager | stdlib@v1.25.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | glibc | glibc@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | glibc-locale-base | glibc-locale-base@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | libcap2 | libcap2@2.73-160000.2.2 | SUSE-SU-2026:21373-1 | HIGH | affected | sles | |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.8.1-160000.2.2 | SUSE-SU-2026:21848-1 | HIGH | affected | sles | |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | HIGH | affected | sles | |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | HIGH | affected | sles | |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.50.4-160000.1.2 | SUSE-SU-2026:22166-1 | HIGH | affected | sles | |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | libudev1 | libudev1@257.10-160000.1.1 | SUSE-SU-2026:21144-1 | HIGH | affected | sles | |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | libzypp | libzypp@17.38.2-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | HIGH | affected | sles | |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | xz | xz@5.8.1-160000.2.2 | SUSE-SU-2026:21848-1 | HIGH | affected | sles | |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager-webhook | golang.org/x/net@v0.38.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager-webhook | golang.org/x/net@v0.38.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager-webhook | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager-webhook | stdlib@v1.25.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager-webhook | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | glibc | glibc@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | glibc-locale-base | glibc-locale-base@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | libcap2 | libcap2@2.73-160000.2.2 | SUSE-SU-2026:21373-1 | HIGH | affected | sles | |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.8.1-160000.2.2 | SUSE-SU-2026:21848-1 | HIGH | affected | sles | |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | HIGH | affected | sles | |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | HIGH | affected | sles | |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.50.4-160000.1.2 | SUSE-SU-2026:22166-1 | HIGH | affected | sles | |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | libudev1 | libudev1@257.10-160000.1.1 | SUSE-SU-2026:21144-1 | HIGH | affected | sles | |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | libzypp | libzypp@17.38.2-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | HIGH | affected | sles | |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | xz | xz@5.8.1-160000.2.2 | SUSE-SU-2026:21848-1 | HIGH | affected | sles | |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager | golang.org/x/net@v0.38.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager | golang.org/x/net@v0.38.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager | stdlib@v1.25.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | glibc | glibc@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | glibc-locale-base | glibc-locale-base@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | libcap2 | libcap2@2.73-160000.2.2 | SUSE-SU-2026:21373-1 | HIGH | affected | sles | |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | HIGH | affected | sles | |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | HIGH | affected | sles | |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.50.4-160000.1.2 | SUSE-SU-2026:22166-1 | HIGH | affected | sles | |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | libudev1 | libudev1@257.10-160000.1.1 | SUSE-SU-2026:21144-1 | HIGH | affected | sles | |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | libzypp | libzypp@17.38.2-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | usr/bin/pcidevices | golang.org/x/net@v0.23.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | usr/bin/pcidevices | golang.org/x/net@v0.23.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | usr/bin/pcidevices | google.golang.org/grpc@v1.56.3 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | usr/bin/pcidevices | kubevirt.io/kubevirt@v1.5.0 | CVE-2025-64324 | HIGH | affected | gobinary | |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | usr/bin/pcidevices | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | usr/bin/pcidevices | stdlib@v1.25.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | usr/bin/pcidevices | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | curl | curl@8.14.1-150600.4.31.1 | SUSE-SU-2026:0885-1 | HIGH | affected | sles | |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | curl | curl@8.14.1-150600.4.31.1 | SUSE-SU-2026:1940-1 | HIGH | affected | sles | |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.37.1 | SUSE-SU-2026:0371-1 | HIGH | affected | sles | |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.37.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.37.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.14.1-150600.4.31.1 | SUSE-SU-2026:0885-1 | HIGH | affected | sles | |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.14.1-150600.4.31.1 | SUSE-SU-2026:1940-1 | HIGH | affected | sles | |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | libfreeipmi17 | libfreeipmi17@1.6.8-150400.1.11 | SUSE-SU-2026:1755-1 | HIGH | affected | sles | |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.1.4-150600.5.39.1 | SUSE-SU-2026:0312-1 | CRITICAL | affected | sles | |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.1.4-150600.5.39.1 | SUSE-SU-2026:1215-1 | HIGH | affected | sles | |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.1.4-150600.5.39.1 | SUSE-SU-2026:2393-1 | HIGH | affected | sles | |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.1.4-150600.5.39.1 | SUSE-SU-2026:0312-1 | CRITICAL | affected | sles | |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.1.4-150600.5.39.1 | SUSE-SU-2026:1215-1 | HIGH | affected | sles | |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.1.4-150600.5.39.1 | SUSE-SU-2026:2393-1 | HIGH | affected | sles | |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.34-150600.8.19.2 | SUSE-SU-2026:2590-1 | HIGH | affected | sles | |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.50.2-150000.3.33.1 | SUSE-SU-2026:2528-1 | HIGH | affected | sles | |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | libudev1 | libudev1@254.27-150600.4.46.2 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | libzypp | libzypp@17.37.18-150600.3.82.1 | SUSE-SU-2026:2590-1 | HIGH | affected | sles | |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.1.4-150600.5.39.1 | SUSE-SU-2026:0312-1 | CRITICAL | affected | sles | |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.1.4-150600.5.39.1 | SUSE-SU-2026:1215-1 | HIGH | affected | sles | |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.1.4-150600.5.39.1 | SUSE-SU-2026:2393-1 | HIGH | affected | sles | |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-150600.10.52.1 | SUSE-SU-2026:2590-1 | HIGH | affected | sles | |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | bin/manager | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | bin/manager | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | bin/manager | stdlib@v1.25.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | bin/manager | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | glibc | glibc@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | glibc-locale-base | glibc-locale-base@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | helm | helm@3.19.1-160000.1.1 | SUSE-SU-2026:22001-1 | HIGH | affected | sles | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | libcap2 | libcap2@2.73-160000.2.2 | SUSE-SU-2026:21373-1 | HIGH | affected | sles | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.8.1-160000.2.2 | SUSE-SU-2026:21848-1 | HIGH | affected | sles | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | HIGH | affected | sles | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | HIGH | affected | sles | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.50.4-160000.1.2 | SUSE-SU-2026:22166-1 | HIGH | affected | sles | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | libudev1 | libudev1@257.10-160000.1.1 | SUSE-SU-2026:21144-1 | HIGH | affected | sles | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | libzypp | libzypp@17.38.2-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | nginx | nginx@1.27.2-160000.2.2 | SUSE-SU-2026:21823-1 | HIGH | affected | sles | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | nginx | nginx@1.27.2-160000.2.2 | SUSE-SU-2026:21832-1 | HIGH | affected | sles | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | nginx | nginx@1.27.2-160000.2.2 | SUSE-SU-2026:22178-1 | HIGH | affected | sles | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | HIGH | affected | sles | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | rsync | rsync@3.4.1-160000.2.3 | SUSE-SU-2026:21795-1 | HIGH | affected | sles | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | rsync | rsync@3.4.1-160000.2.3 | SUSE-SU-2026:22015-1 | HIGH | affected | sles | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | xz | xz@5.8.1-160000.2.2 | SUSE-SU-2026:21848-1 | HIGH | affected | sles | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/kubectl | golang.org/x/net@v0.38.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/kubectl | golang.org/x/net@v0.38.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.24.11 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.24.11 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.24.11 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.24.11 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.24.11 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.24.11 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/virtctl | stdlib@v1.24.9 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/virtctl | stdlib@v1.24.9 | CVE-2025-61729 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/virtctl | stdlib@v1.24.9 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/virtctl | stdlib@v1.24.9 | CVE-2026-33811 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/virtctl | stdlib@v1.24.9 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/virtctl | stdlib@v1.24.9 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/virtctl | stdlib@v1.24.9 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/virtctl | stdlib@v1.24.9 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/virtctl | stdlib@v1.24.9 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | go.opentelemetry.io/otel/sdk@v1.33.0 | CVE-2026-24051 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | go.opentelemetry.io/otel/sdk@v1.33.0 | CVE-2026-39883 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | golang.org/x/net@v0.38.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | golang.org/x/net@v0.38.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | stdlib@v1.24.2 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | stdlib@v1.24.2 | CVE-2025-22874 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | stdlib@v1.24.2 | CVE-2025-61729 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | stdlib@v1.24.2 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | stdlib@v1.24.2 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | stdlib@v1.24.2 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | stdlib@v1.24.2 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | stdlib@v1.24.2 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | stdlib@v1.24.2 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/yq | golang.org/x/net@v0.50.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | github.com/containerd/containerd@v1.7.12 | CVE-2026-53488 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | golang.org/x/crypto@v0.18.0 | CVE-2025-47913 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | golang.org/x/crypto@v0.18.0 | CVE-2026-39828 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | golang.org/x/crypto@v0.18.0 | CVE-2026-39829 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | golang.org/x/crypto@v0.18.0 | CVE-2026-39835 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | golang.org/x/crypto@v0.18.0 | CVE-2026-42508 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | golang.org/x/crypto@v0.18.0 | CVE-2026-46595 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | golang.org/x/crypto@v0.18.0 | CVE-2026-46597 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | golang.org/x/crypto@v0.18.0 | CVE-2026-39831 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | golang.org/x/crypto@v0.18.0 | CVE-2026-39832 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | golang.org/x/crypto@v0.18.0 | CVE-2026-39833 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | golang.org/x/crypto@v0.18.0 | CVE-2026-39834 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | golang.org/x/crypto@v0.18.0 | CVE-2026-46598 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | golang.org/x/net@v0.20.0 | CVE-2026-25680 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | golang.org/x/net@v0.20.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | golang.org/x/net@v0.20.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | stdlib@v1.25.9 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | stdlib@v1.25.9 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | stdlib@v1.25.9 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/harvester-installer | golang.org/x/crypto@v0.31.0 | CVE-2026-39829 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/harvester-installer | golang.org/x/net@v0.33.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/harvester-installer | stdlib@v1.25.9 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/upgrade-helper | go.opentelemetry.io/otel@v1.37.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/upgrade-helper | golang.org/x/crypto@v0.47.0 | CVE-2026-39829 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/upgrade-helper | golang.org/x/net@v0.49.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/upgrade-helper | golang.org/x/net@v0.49.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/upgrade-helper | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/upgrade-helper | stdlib@v1.25.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/upgrade-helper | stdlib@v1.25.7 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/upgrade-helper | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/upgrade-helper | stdlib@v1.25.7 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | glibc | glibc@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | glibc-locale-base | glibc-locale-base@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | libcap2 | libcap2@2.73-160000.2.2 | SUSE-SU-2026:21373-1 | HIGH | affected | sles | |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | libgnutls30 | libgnutls30@3.8.10-160000.2.1 | SUSE-SU-2026:21815-1 | HIGH | affected | sles | |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | HIGH | affected | sles | |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | HIGH | affected | sles | |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.50.4-160000.1.2 | SUSE-SU-2026:22166-1 | HIGH | affected | sles | |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | libudev1 | libudev1@257.10-160000.1.1 | SUSE-SU-2026:21144-1 | HIGH | affected | sles | |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | libzypp | libzypp@17.38.2-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | HIGH | affected | sles | |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | qemu-img | qemu-img@10.0.8-160000.1.1 | SUSE-SU-2026:21354-1 | HIGH | affected | sles | |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | qemu-tools | qemu-tools@10.0.8-160000.1.1 | SUSE-SU-2026:21354-1 | HIGH | affected | sles | |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | xz | xz@5.8.1-160000.2.2 | SUSE-SU-2026:21848-1 | HIGH | affected | sles | |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/vm-import-controller | golang.org/x/net@v0.49.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/vm-import-controller | golang.org/x/net@v0.49.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/vm-import-controller | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/vm-import-controller | stdlib@v1.25.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/vm-import-controller | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | glibc | glibc@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | glibc-locale-base | glibc-locale-base@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | libcap2 | libcap2@2.73-160000.2.2 | SUSE-SU-2026:21373-1 | HIGH | affected | sles | |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | HIGH | affected | sles | |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.50.4-160000.1.2 | SUSE-SU-2026:22166-1 | HIGH | affected | sles | |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | libzypp | libzypp@17.38.2-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | HIGH | affected | sles | |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | github.com/containerd/containerd@v1.7.27 | CVE-2024-25621 | HIGH | affected | gobinary | |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | github.com/containerd/containerd@v1.7.27 | CVE-2026-46680 | HIGH | affected | gobinary | |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | github.com/containerd/containerd@v1.7.27 | CVE-2026-53488 | HIGH | affected | gobinary | |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | github.com/go-jose/go-jose/v3@v3.0.3 | CVE-2026-34986 | HIGH | affected | gobinary | |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | go.opentelemetry.io/otel@v1.37.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | golang.org/x/crypto@v0.47.0 | CVE-2026-39829 | HIGH | affected | gobinary | |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | golang.org/x/net@v0.49.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | golang.org/x/net@v0.49.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | stdlib@v1.25.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | stdlib@v1.25.7 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | stdlib@v1.25.7 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | glibc | glibc@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | glibc-locale-base | glibc-locale-base@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | libcap2 | libcap2@2.73-160000.2.2 | SUSE-SU-2026:21373-1 | HIGH | affected | sles | |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.8.1-160000.2.2 | SUSE-SU-2026:21848-1 | HIGH | affected | sles | |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | HIGH | affected | sles | |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.50.4-160000.1.2 | SUSE-SU-2026:22166-1 | HIGH | affected | sles | |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | libudev1 | libudev1@257.10-160000.1.1 | SUSE-SU-2026:21144-1 | HIGH | affected | sles | |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | libzypp | libzypp@17.38.2-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | HIGH | affected | sles | |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | xz | xz@5.8.1-160000.2.2 | SUSE-SU-2026:21848-1 | HIGH | affected | sles | |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | github.com/containerd/containerd@v1.7.27 | CVE-2024-25621 | HIGH | affected | gobinary | |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | github.com/containerd/containerd@v1.7.27 | CVE-2026-46680 | HIGH | affected | gobinary | |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | github.com/containerd/containerd@v1.7.27 | CVE-2026-53488 | HIGH | affected | gobinary | |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | github.com/go-jose/go-jose/v3@v3.0.3 | CVE-2026-34986 | HIGH | affected | gobinary | |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | go.opentelemetry.io/otel@v1.37.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | golang.org/x/crypto@v0.47.0 | CVE-2026-39829 | HIGH | affected | gobinary | |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | golang.org/x/net@v0.49.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | golang.org/x/net@v0.49.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | stdlib@v1.25.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | stdlib@v1.25.7 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | stdlib@v1.25.7 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.5-r0 | CVE-2026-45447 | HIGH | affected | alpine | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | libssl3 | libssl3@3.5.5-r0 | CVE-2026-45447 | HIGH | affected | alpine | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | musl | musl@1.2.5-r21 | CVE-2026-40200 | HIGH | affected | alpine | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | musl-utils | musl-utils@1.2.5-r21 | CVE-2026-40200 | HIGH | affected | alpine | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | github.com/containerd/containerd@v1.7.29 | CVE-2026-46680 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | github.com/containerd/containerd@v1.7.29 | CVE-2026-53488 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | stdlib@v1.25.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | github.com/containerd/containerd@v1.7.29 | CVE-2026-46680 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | github.com/containerd/containerd@v1.7.29 | CVE-2026-53488 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | golang.org/x/crypto@v0.45.0 | CVE-2026-39828 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | golang.org/x/crypto@v0.45.0 | CVE-2026-39829 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | golang.org/x/crypto@v0.45.0 | CVE-2026-39835 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | golang.org/x/crypto@v0.45.0 | CVE-2026-42508 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | golang.org/x/crypto@v0.45.0 | CVE-2026-46595 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | golang.org/x/crypto@v0.45.0 | CVE-2026-46597 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | golang.org/x/crypto@v0.45.0 | CVE-2026-39831 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | golang.org/x/crypto@v0.45.0 | CVE-2026-39832 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | golang.org/x/crypto@v0.45.0 | CVE-2026-39833 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | golang.org/x/crypto@v0.45.0 | CVE-2026-39834 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | golang.org/x/crypto@v0.45.0 | CVE-2026-46598 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | golang.org/x/net@v0.47.0 | CVE-2026-25680 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | stdlib@v1.25.7 | CVE-2026-33811 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | stdlib@v1.25.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | stdlib@v1.25.7 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | stdlib@v1.25.7 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | usr/bin/helm | github.com/containerd/containerd@v1.7.29 | CVE-2026-46680 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | usr/bin/helm | github.com/containerd/containerd@v1.7.29 | CVE-2026-53488 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | usr/bin/helm | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | usr/bin/helm | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | usr/bin/helm | stdlib@v1.24.11 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | usr/bin/helm | stdlib@v1.24.11 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | usr/bin/helm | stdlib@v1.24.11 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/klipper-lb:v0.4.14 | false | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.5-r0 | CVE-2026-45447 | HIGH | affected | alpine | |
| rancher/klipper-lb:v0.4.14 | false | Harvester v1.8.0 | libssl3 | libssl3@3.5.5-r0 | CVE-2026-45447 | HIGH | affected | alpine | |
| rancher/klipper-lb:v0.4.14 | false | Harvester v1.8.0 | musl | musl@1.2.5-r21 | CVE-2026-40200 | HIGH | affected | alpine | |
| rancher/klipper-lb:v0.4.14 | false | Harvester v1.8.0 | musl-utils | musl-utils@1.2.5-r21 | CVE-2026-40200 | HIGH | affected | alpine | |
| rancher/kubectl:v1.35.1 | false | Harvester v1.8.0 | bin/kubectl | go.opentelemetry.io/otel@v1.36.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/kubectl:v1.35.1 | false | Harvester v1.8.0 | bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/kubectl:v1.35.1 | false | Harvester v1.8.0 | bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/kubectl:v1.35.1 | false | Harvester v1.8.0 | bin/kubectl | stdlib@v1.25.6 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/kubectl:v1.35.1 | false | Harvester v1.8.0 | bin/kubectl | stdlib@v1.25.6 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/kubectl:v1.35.1 | false | Harvester v1.8.0 | bin/kubectl | stdlib@v1.25.6 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/kubectl:v1.35.1 | false | Harvester v1.8.0 | bin/kubectl | stdlib@v1.25.6 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/kubectl:v1.35.1 | false | Harvester v1.8.0 | bin/kubectl | stdlib@v1.25.6 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | busybox | busybox@1.37.0-150700.18.12.1 | SUSE-SU-2026:0759-1 | HIGH | affected | sles | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | busybox | busybox@1.37.0-150700.18.12.1 | SUSE-SU-2026:2054-1 | HIGH | affected | sles | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.40.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.40.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | bin/kuberlr | golang.org/x/net@v0.38.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | bin/kuberlr | golang.org/x/net@v0.38.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | bin/kuberlr | stdlib@v1.24.4 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | bin/kuberlr | stdlib@v1.24.4 | CVE-2025-61729 | HIGH | affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | bin/kuberlr | stdlib@v1.24.4 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | bin/kuberlr | stdlib@v1.24.4 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | bin/kuberlr | stdlib@v1.24.4 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | bin/kuberlr | stdlib@v1.24.4 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | bin/kuberlr | stdlib@v1.24.4 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | bin/kuberlr | stdlib@v1.24.4 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.33.9 | golang.org/x/net@v0.38.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.33.9 | golang.org/x/net@v0.38.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.33.9 | stdlib@v1.24.13 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.33.9 | stdlib@v1.24.13 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.33.9 | stdlib@v1.24.13 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.33.9 | stdlib@v1.24.13 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.33.9 | stdlib@v1.24.13 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.34.5 | golang.org/x/net@v0.38.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.34.5 | golang.org/x/net@v0.38.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.34.5 | stdlib@v1.24.13 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.34.5 | stdlib@v1.24.13 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.34.5 | stdlib@v1.24.13 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.34.5 | stdlib@v1.24.13 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.34.5 | stdlib@v1.24.13 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.35.2 | go.opentelemetry.io/otel@v1.36.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.35.2 | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.35.2 | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.35.2 | stdlib@v1.25.7 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.35.2 | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.35.2 | stdlib@v1.25.7 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | libcap2 | libcap2@1:2.66-4 | CVE-2026-4878 | HIGH | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | libgnutls30 | libgnutls30@3.7.9-2+deb12u3 | CVE-2026-33845 | CRITICAL | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | libgnutls30 | libgnutls30@3.7.9-2+deb12u3 | CVE-2026-42010 | CRITICAL | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | libgnutls30 | libgnutls30@3.7.9-2+deb12u3 | CVE-2025-32988 | HIGH | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | libgnutls30 | libgnutls30@3.7.9-2+deb12u3 | CVE-2025-32990 | HIGH | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | libgnutls30 | libgnutls30@3.7.9-2+deb12u3 | CVE-2026-33846 | HIGH | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | libgnutls30 | libgnutls30@3.7.9-2+deb12u3 | CVE-2026-3833 | HIGH | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | libgnutls30 | libgnutls30@3.7.9-2+deb12u3 | CVE-2026-42009 | HIGH | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | libldap-2.5-0 | libldap-2.5-0@2.5.13+dfsg-5 | CVE-2023-2953 | HIGH | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-0.2 | CVE-2025-31115 | HIGH | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | libpq5 | libpq5@15.8-0+deb12u1 | CVE-2024-10979 | HIGH | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | libpq5 | libpq5@15.8-0+deb12u1 | CVE-2025-1094 | HIGH | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | libpq5 | libpq5@15.8-0+deb12u1 | CVE-2025-8714 | HIGH | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | libpq5 | libpq5@15.8-0+deb12u1 | CVE-2025-8715 | HIGH | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | libpq5 | libpq5@15.8-0+deb12u1 | CVE-2026-2004 | HIGH | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | libpq5 | libpq5@15.8-0+deb12u1 | CVE-2026-2005 | HIGH | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | libpq5 | libpq5@15.8-0+deb12u1 | CVE-2026-2006 | HIGH | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | libpq5 | libpq5@15.8-0+deb12u1 | CVE-2026-6473 | HIGH | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | libpq5 | libpq5@15.8-0+deb12u1 | CVE-2026-6477 | HIGH | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | libpq5 | libpq5@15.8-0+deb12u1 | CVE-2026-6478 | HIGH | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | libssl3 | libssl3@3.0.14-1~deb12u2 | CVE-2026-31789 | CRITICAL | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | libssl3 | libssl3@3.0.14-1~deb12u2 | CVE-2025-15467 | HIGH | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | libssl3 | libssl3@3.0.14-1~deb12u2 | CVE-2025-69421 | HIGH | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | libssl3 | libssl3@3.0.14-1~deb12u2 | CVE-2026-28387 | HIGH | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | libssl3 | libssl3@3.0.14-1~deb12u2 | CVE-2026-28388 | HIGH | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | libssl3 | libssl3@3.0.14-1~deb12u2 | CVE-2026-28389 | HIGH | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | libssl3 | libssl3@3.0.14-1~deb12u2 | CVE-2026-28390 | HIGH | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | libssl3 | libssl3@3.0.14-1~deb12u2 | CVE-2026-45447 | HIGH | affected | debian | |
| rancher/mirrored-fluent-fluent-bit:3.1.8 | true | Harvester v1.8.0 | zlib1g | zlib1g@1:1.2.13.dfsg-1 | CVE-2023-45853 | CRITICAL | affected | debian | |
| rancher/mirrored-ingress-nginx-kube-webhook-certgen:v1.6.7 | true | Harvester v1.8.0 | kube-webhook-certgen | golang.org/x/net@v0.49.0 | CVE-2026-25680 | HIGH | affected | gobinary | |
| rancher/mirrored-ingress-nginx-kube-webhook-certgen:v1.6.7 | true | Harvester v1.8.0 | kube-webhook-certgen | golang.org/x/net@v0.49.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/mirrored-ingress-nginx-kube-webhook-certgen:v1.6.7 | true | Harvester v1.8.0 | kube-webhook-certgen | golang.org/x/net@v0.49.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/mirrored-ingress-nginx-kube-webhook-certgen:v1.6.7 | true | Harvester v1.8.0 | kube-webhook-certgen | stdlib@v1.25.6 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-ingress-nginx-kube-webhook-certgen:v1.6.7 | true | Harvester v1.8.0 | kube-webhook-certgen | stdlib@v1.25.6 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/mirrored-ingress-nginx-kube-webhook-certgen:v1.6.7 | true | Harvester v1.8.0 | kube-webhook-certgen | stdlib@v1.25.6 | CVE-2026-33811 | HIGH | affected | gobinary | |
| rancher/mirrored-ingress-nginx-kube-webhook-certgen:v1.6.7 | true | Harvester v1.8.0 | kube-webhook-certgen | stdlib@v1.25.6 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/mirrored-ingress-nginx-kube-webhook-certgen:v1.6.7 | true | Harvester v1.8.0 | kube-webhook-certgen | stdlib@v1.25.6 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/mirrored-ingress-nginx-kube-webhook-certgen:v1.6.7 | true | Harvester v1.8.0 | kube-webhook-certgen | stdlib@v1.25.6 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/mirrored-ingress-nginx-kube-webhook-certgen:v1.6.7 | true | Harvester v1.8.0 | kube-webhook-certgen | stdlib@v1.25.6 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/mirrored-kube-logging-config-reloader:v0.0.6 | true | Harvester v1.8.0 | config-reloader | google.golang.org/protobuf@v1.28.1 | CVE-2024-24786 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-kube-logging-config-reloader:v0.0.6 | true | Harvester v1.8.0 | config-reloader | stdlib@v1.23.1 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-kube-logging-config-reloader:v0.0.6 | true | Harvester v1.8.0 | config-reloader | stdlib@v1.23.1 | CVE-2025-61729 | HIGH | affected | gobinary | |
| rancher/mirrored-kube-logging-config-reloader:v0.0.6 | true | Harvester v1.8.0 | config-reloader | stdlib@v1.23.1 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/mirrored-kube-logging-config-reloader:v0.0.6 | true | Harvester v1.8.0 | config-reloader | stdlib@v1.23.1 | CVE-2026-33811 | HIGH | affected | gobinary | |
| rancher/mirrored-kube-logging-config-reloader:v0.0.6 | true | Harvester v1.8.0 | config-reloader | stdlib@v1.23.1 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/mirrored-kube-logging-config-reloader:v0.0.6 | true | Harvester v1.8.0 | config-reloader | stdlib@v1.23.1 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/mirrored-kube-logging-config-reloader:v0.0.6 | true | Harvester v1.8.0 | config-reloader | stdlib@v1.23.1 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/mirrored-kube-logging-config-reloader:v0.0.6 | true | Harvester v1.8.0 | config-reloader | stdlib@v1.23.1 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/mirrored-kube-logging-config-reloader:v0.0.6 | true | Harvester v1.8.0 | config-reloader | stdlib@v1.23.1 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-kube-logging-config-reloader:v0.0.6 | true | Harvester v1.8.0 | config-reloader | stdlib@v1.23.1 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-kube-logging-config-reloader:v0.0.6 | true | Harvester v1.8.0 | config-reloader | stdlib@v1.23.1 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.3.3-r0 | CVE-2026-31789 | CRITICAL | affected | alpine | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.3.3-r0 | CVE-2025-15467 | HIGH | affected | alpine | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.3.3-r0 | CVE-2025-69421 | HIGH | affected | alpine | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.3.3-r0 | CVE-2026-28387 | HIGH | affected | alpine | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.3.3-r0 | CVE-2026-28388 | HIGH | affected | alpine | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.3.3-r0 | CVE-2026-28389 | HIGH | affected | alpine | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.3.3-r0 | CVE-2026-28390 | HIGH | affected | alpine | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | libssl3 | libssl3@3.3.3-r0 | CVE-2026-31789 | CRITICAL | affected | alpine | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | libssl3 | libssl3@3.3.3-r0 | CVE-2025-15467 | HIGH | affected | alpine | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | libssl3 | libssl3@3.3.3-r0 | CVE-2025-69421 | HIGH | affected | alpine | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | libssl3 | libssl3@3.3.3-r0 | CVE-2026-28387 | HIGH | affected | alpine | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | libssl3 | libssl3@3.3.3-r0 | CVE-2026-28388 | HIGH | affected | alpine | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | libssl3 | libssl3@3.3.3-r0 | CVE-2026-28389 | HIGH | affected | alpine | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | libssl3 | libssl3@3.3.3-r0 | CVE-2026-28390 | HIGH | affected | alpine | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | musl | musl@1.2.5-r1 | CVE-2026-40200 | HIGH | affected | alpine | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | musl-utils | musl-utils@1.2.5-r0 | CVE-2025-26519 | HIGH | affected | alpine | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | musl-utils | musl-utils@1.2.5-r0 | CVE-2026-40200 | HIGH | affected | alpine | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | ruby | ruby@3.3.6-r0 | CVE-2025-27219 | HIGH | affected | alpine | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | ruby | ruby@3.3.6-r0 | CVE-2025-61594 | HIGH | affected | alpine | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | ruby-libs | ruby-libs@3.3.6-r0 | CVE-2025-27219 | HIGH | affected | alpine | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | ruby-libs | ruby-libs@3.3.6-r0 | CVE-2025-61594 | HIGH | affected | alpine | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | zlib | zlib@1.3.1-r1 | CVE-2026-22184 | HIGH | affected | alpine | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | activesupport@7.1.1 | CVE-2026-33176 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | addressable@2.8.5 | CVE-2026-35611 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | addressable@2.8.6 | CVE-2026-35611 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | concurrent-ruby@1.1.10 | CVE-2026-54904 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | concurrent-ruby@1.2.3 | CVE-2026-54904 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | concurrent-ruby@1.3.5 | CVE-2026-54904 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | erb@4.0.2 | CVE-2026-41316 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | faraday@1.10.3 | CVE-2026-54297 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | faraday@2.7.12 | CVE-2026-54297 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | google-protobuf@3.21.12 | CVE-2024-7254 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | jwt@2.10.1 | CVE-2026-45363 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | net-imap@0.3.4.1 | CVE-2026-42257 | CRITICAL | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | net-imap@0.3.4.1 | CVE-2026-42258 | CRITICAL | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | net-imap@0.3.4.1 | CVE-2026-42245 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | net-imap@0.3.4.1 | CVE-2026-42246 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | net-imap@0.4.19 | CVE-2026-42257 | CRITICAL | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | net-imap@0.4.19 | CVE-2026-42258 | CRITICAL | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | net-imap@0.4.19 | CVE-2026-42245 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | net-imap@0.4.19 | CVE-2026-42246 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | nokogiri@1.18.4 | GHSA-353f-x4gh-cqq8 | CRITICAL | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | nokogiri@1.18.4 | GHSA-c4rq-3m3g-8wgx | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | oj@3.16.1 | CVE-2026-54502 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | oj@3.16.1 | CVE-2026-54592 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | oj@3.16.1 | CVE-2026-54896 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | oj@3.16.1 | CVE-2026-54897 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | oj@3.16.1 | CVE-2026-54898 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | oj@3.16.1 | CVE-2026-54899 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | oj@3.16.1 | CVE-2026-54900 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | oj@3.16.1 | CVE-2026-54901 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | oj@3.16.1 | CVE-2026-54902 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | oj@3.16.1 | CVE-2026-54903 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | oj@3.16.10 | CVE-2026-54502 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | oj@3.16.10 | CVE-2026-54592 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | oj@3.16.10 | CVE-2026-54896 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | oj@3.16.10 | CVE-2026-54897 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | oj@3.16.10 | CVE-2026-54898 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | oj@3.16.10 | CVE-2026-54899 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | oj@3.16.10 | CVE-2026-54900 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | oj@3.16.10 | CVE-2026-54901 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | oj@3.16.10 | CVE-2026-54902 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | oj@3.16.10 | CVE-2026-54903 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | rack@3.0.14 | CVE-2025-46727 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | rack@3.0.14 | CVE-2025-61770 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | rack@3.0.14 | CVE-2025-61771 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | rack@3.0.14 | CVE-2025-61772 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | rack@3.0.14 | CVE-2025-61919 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | rack@3.0.14 | CVE-2026-22860 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | rack@3.0.14 | CVE-2026-34785 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | rack@3.0.14 | CVE-2026-34827 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | rack@3.0.14 | CVE-2026-34829 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | rexml@3.2.6 | CVE-2024-49761 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | rexml@3.3.2 | CVE-2024-49761 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | uri@0.12.2 | CVE-2025-61594 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | webrick@1.8.1 | CVE-2024-47220 | HIGH | affected | gemspec | |
| rancher/mirrored-kube-logging-fluentd:v1.16-4.10-full | true | Harvester v1.8.0 | Ruby | zlib@3.0.0 | CVE-2026-27820 | CRITICAL | affected | gemspec | |
| rancher/mirrored-kube-logging-logging-operator:4.10.0 | true | Harvester v1.8.0 | manager | golang.org/x/net@v0.29.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/mirrored-kube-logging-logging-operator:4.10.0 | true | Harvester v1.8.0 | manager | golang.org/x/net@v0.29.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/mirrored-kube-logging-logging-operator:4.10.0 | true | Harvester v1.8.0 | manager | stdlib@v1.23.1 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-kube-logging-logging-operator:4.10.0 | true | Harvester v1.8.0 | manager | stdlib@v1.23.1 | CVE-2025-61729 | HIGH | affected | gobinary | |
| rancher/mirrored-kube-logging-logging-operator:4.10.0 | true | Harvester v1.8.0 | manager | stdlib@v1.23.1 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/mirrored-kube-logging-logging-operator:4.10.0 | true | Harvester v1.8.0 | manager | stdlib@v1.23.1 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/mirrored-kube-logging-logging-operator:4.10.0 | true | Harvester v1.8.0 | manager | stdlib@v1.23.1 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/mirrored-kube-logging-logging-operator:4.10.0 | true | Harvester v1.8.0 | manager | stdlib@v1.23.1 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-kube-logging-logging-operator:4.10.0 | true | Harvester v1.8.0 | manager | stdlib@v1.23.1 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-kube-logging-logging-operator:4.10.0 | true | Harvester v1.8.0 | manager | stdlib@v1.23.1 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.5-r0 | CVE-2026-31789 | CRITICAL | affected | alpine | |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.5-r0 | CVE-2026-28387 | HIGH | affected | alpine | |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.5-r0 | CVE-2026-28388 | HIGH | affected | alpine | |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.5-r0 | CVE-2026-28389 | HIGH | affected | alpine | |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.5-r0 | CVE-2026-28390 | HIGH | affected | alpine | |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.5-r0 | CVE-2026-45447 | HIGH | affected | alpine | |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | libssl3 | libssl3@3.5.5-r0 | CVE-2026-31789 | CRITICAL | affected | alpine | |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | libssl3 | libssl3@3.5.5-r0 | CVE-2026-28387 | HIGH | affected | alpine | |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | libssl3 | libssl3@3.5.5-r0 | CVE-2026-28388 | HIGH | affected | alpine | |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | libssl3 | libssl3@3.5.5-r0 | CVE-2026-28389 | HIGH | affected | alpine | |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | libssl3 | libssl3@3.5.5-r0 | CVE-2026-28390 | HIGH | affected | alpine | |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | libssl3 | libssl3@3.5.5-r0 | CVE-2026-45447 | HIGH | affected | alpine | |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | musl | musl@1.2.5-r21 | CVE-2026-40200 | HIGH | affected | alpine | |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | musl-utils | musl-utils@1.2.5-r21 | CVE-2026-40200 | HIGH | affected | alpine | |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | zlib | zlib@1.3.1-r2 | CVE-2026-22184 | HIGH | affected | alpine | |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | kube-vip | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | kube-vip | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | kube-vip | google.golang.org/grpc@v1.77.0 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | kube-vip | stdlib@v1.25.6 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | kube-vip | stdlib@v1.25.6 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | kube-vip | stdlib@v1.25.6 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | kube-vip | stdlib@v1.25.6 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.1-r0 | CVE-2026-31789 | CRITICAL | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.1-r0 | CVE-2025-15467 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.1-r0 | CVE-2025-69421 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.1-r0 | CVE-2026-28387 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.1-r0 | CVE-2026-28388 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.1-r0 | CVE-2026-28389 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.1-r0 | CVE-2026-28390 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.1-r0 | CVE-2026-45447 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libexpat | libexpat@2.7.1-r0 | CVE-2025-59375 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libexpat | libexpat@2.7.1-r0 | CVE-2026-25210 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libexpat | libexpat@2.7.1-r0 | CVE-2026-45186 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libpng | libpng@1.6.47-r0 | CVE-2025-64720 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libpng | libpng@1.6.47-r0 | CVE-2025-65018 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libpng | libpng@1.6.47-r0 | CVE-2025-66293 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libpng | libpng@1.6.47-r0 | CVE-2026-22695 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libpng | libpng@1.6.47-r0 | CVE-2026-22801 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libpng | libpng@1.6.47-r0 | CVE-2026-25646 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libssl3 | libssl3@3.5.1-r0 | CVE-2026-31789 | CRITICAL | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libssl3 | libssl3@3.5.1-r0 | CVE-2025-15467 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libssl3 | libssl3@3.5.1-r0 | CVE-2025-69421 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libssl3 | libssl3@3.5.1-r0 | CVE-2026-28387 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libssl3 | libssl3@3.5.1-r0 | CVE-2026-28388 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libssl3 | libssl3@3.5.1-r0 | CVE-2026-28389 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libssl3 | libssl3@3.5.1-r0 | CVE-2026-28390 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libssl3 | libssl3@3.5.1-r0 | CVE-2026-45447 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libxml2 | libxml2@2.13.8-r0 | CVE-2025-49794 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libxml2 | libxml2@2.13.8-r0 | CVE-2025-49795 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libxml2 | libxml2@2.13.8-r0 | CVE-2025-49796 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | libxml2 | libxml2@2.13.8-r0 | CVE-2026-6732 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | musl | musl@1.2.5-r10 | CVE-2026-40200 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | musl-utils | musl-utils@1.2.5-r10 | CVE-2026-40200 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | nghttp2-libs | nghttp2-libs@1.65.0-r0 | CVE-2026-27135 | HIGH | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | pcre2 | pcre2@10.43-r1 | CVE-2025-58050 | CRITICAL | affected | alpine | |
| rancher/mirrored-library-nginx:1.29.1-alpine | true | Harvester v1.8.0 | zlib | zlib@1.3.1-r2 | CVE-2026-22184 | HIGH | affected | alpine | |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | golang.org/x/net@v0.24.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | golang.org/x/net@v0.24.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | google.golang.org/grpc@v1.60.1 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | stdlib@v1.22.2 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | stdlib@v1.22.2 | CVE-2025-61729 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | stdlib@v1.22.2 | CVE-2026-33811 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | stdlib@v1.22.2 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | stdlib@v1.22.2 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | stdlib@v1.22.2 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | stdlib@v1.22.2 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | stdlib@v1.22.2 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | stdlib@v1.22.2 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | stdlib@v1.22.2 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-prometheus-operator-admission-webhook:v0.85.0 | true | Harvester v1.8.0 | bin/admission-webhook | github.com/prometheus/prometheus@v0.305.0 | CVE-2026-42151 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-operator-admission-webhook:v0.85.0 | true | Harvester v1.8.0 | bin/admission-webhook | github.com/prometheus/prometheus@v0.305.0 | CVE-2026-42154 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-operator-admission-webhook:v0.85.0 | true | Harvester v1.8.0 | bin/admission-webhook | go.opentelemetry.io/otel@v1.37.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-operator-admission-webhook:v0.85.0 | true | Harvester v1.8.0 | bin/admission-webhook | golang.org/x/net@v0.43.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-operator-admission-webhook:v0.85.0 | true | Harvester v1.8.0 | bin/admission-webhook | golang.org/x/net@v0.43.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-operator-admission-webhook:v0.85.0 | true | Harvester v1.8.0 | bin/admission-webhook | stdlib@v1.24.6 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-prometheus-operator-admission-webhook:v0.85.0 | true | Harvester v1.8.0 | bin/admission-webhook | stdlib@v1.24.6 | CVE-2025-61729 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-operator-admission-webhook:v0.85.0 | true | Harvester v1.8.0 | bin/admission-webhook | stdlib@v1.24.6 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-operator-admission-webhook:v0.85.0 | true | Harvester v1.8.0 | bin/admission-webhook | stdlib@v1.24.6 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-operator-admission-webhook:v0.85.0 | true | Harvester v1.8.0 | bin/admission-webhook | stdlib@v1.24.6 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-operator-admission-webhook:v0.85.0 | true | Harvester v1.8.0 | bin/admission-webhook | stdlib@v1.24.6 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-prometheus-operator-admission-webhook:v0.85.0 | true | Harvester v1.8.0 | bin/admission-webhook | stdlib@v1.24.6 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-prometheus-operator-admission-webhook:v0.85.0 | true | Harvester v1.8.0 | bin/admission-webhook | stdlib@v1.24.6 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | github.com/prometheus/prometheus@v0.301.0 | CVE-2026-42151 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | github.com/prometheus/prometheus@v0.301.0 | CVE-2026-42154 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | golang.org/x/net@v0.34.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | golang.org/x/net@v0.34.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | stdlib@v1.23.6 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | stdlib@v1.23.6 | CVE-2025-61729 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | stdlib@v1.23.6 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | stdlib@v1.23.6 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | stdlib@v1.23.6 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | stdlib@v1.23.6 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | stdlib@v1.23.6 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | stdlib@v1.23.6 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-prometheus-operator-prometheus-operator:v0.85.0 | true | Harvester v1.8.0 | bin/operator | github.com/prometheus/prometheus@v0.305.0 | CVE-2026-42151 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-operator-prometheus-operator:v0.85.0 | true | Harvester v1.8.0 | bin/operator | github.com/prometheus/prometheus@v0.305.0 | CVE-2026-42154 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-operator-prometheus-operator:v0.85.0 | true | Harvester v1.8.0 | bin/operator | go.opentelemetry.io/otel@v1.37.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-operator-prometheus-operator:v0.85.0 | true | Harvester v1.8.0 | bin/operator | golang.org/x/net@v0.43.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-operator-prometheus-operator:v0.85.0 | true | Harvester v1.8.0 | bin/operator | golang.org/x/net@v0.43.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-operator-prometheus-operator:v0.85.0 | true | Harvester v1.8.0 | bin/operator | stdlib@v1.24.6 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-prometheus-operator-prometheus-operator:v0.85.0 | true | Harvester v1.8.0 | bin/operator | stdlib@v1.24.6 | CVE-2025-61729 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-operator-prometheus-operator:v0.85.0 | true | Harvester v1.8.0 | bin/operator | stdlib@v1.24.6 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-operator-prometheus-operator:v0.85.0 | true | Harvester v1.8.0 | bin/operator | stdlib@v1.24.6 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-operator-prometheus-operator:v0.85.0 | true | Harvester v1.8.0 | bin/operator | stdlib@v1.24.6 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/mirrored-prometheus-operator-prometheus-operator:v0.85.0 | true | Harvester v1.8.0 | bin/operator | stdlib@v1.24.6 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-prometheus-operator-prometheus-operator:v0.85.0 | true | Harvester v1.8.0 | bin/operator | stdlib@v1.24.6 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/mirrored-prometheus-operator-prometheus-operator:v0.85.0 | true | Harvester v1.8.0 | bin/operator | stdlib@v1.24.6 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | github.com/docker/docker@v28.2.2+incompatible | CVE-2026-34040 | HIGH | affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | github.com/docker/docker@v28.2.2+incompatible | CVE-2026-41567 | HIGH | affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | github.com/docker/docker@v28.2.2+incompatible | CVE-2026-42306 | HIGH | affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | github.com/docker/docker@v28.2.2+incompatible | CVE-2026-33997 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | go.opentelemetry.io/otel@v1.36.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | golang.org/x/net@v0.41.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | golang.org/x/net@v0.41.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | google.golang.org/grpc@v1.73.0 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | stdlib@v1.24.5 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | stdlib@v1.24.5 | CVE-2025-61729 | HIGH | affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | stdlib@v1.24.5 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | stdlib@v1.24.5 | CVE-2026-33811 | HIGH | affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | stdlib@v1.24.5 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | stdlib@v1.24.5 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | stdlib@v1.24.5 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | stdlib@v1.24.5 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | stdlib@v1.24.5 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | stdlib@v1.24.5 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | stdlib@v1.24.5 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | github.com/docker/docker@v28.2.2+incompatible | CVE-2026-34040 | HIGH | affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | github.com/docker/docker@v28.2.2+incompatible | CVE-2026-41567 | HIGH | affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | github.com/docker/docker@v28.2.2+incompatible | CVE-2026-42306 | HIGH | affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | github.com/docker/docker@v28.2.2+incompatible | CVE-2026-33997 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | go.opentelemetry.io/otel@v1.36.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | golang.org/x/net@v0.41.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | golang.org/x/net@v0.41.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | google.golang.org/grpc@v1.73.0 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | stdlib@v1.24.5 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | stdlib@v1.24.5 | CVE-2025-61729 | HIGH | affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | stdlib@v1.24.5 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | stdlib@v1.24.5 | CVE-2026-33811 | HIGH | affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | stdlib@v1.24.5 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | stdlib@v1.24.5 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | stdlib@v1.24.5 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | stdlib@v1.24.5 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | stdlib@v1.24.5 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | stdlib@v1.24.5 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | stdlib@v1.24.5 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | HIGH | affected | sles | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | xz | xz@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | github.com/containerd/containerd@v1.7.30 | CVE-2026-46680 | HIGH | affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | github.com/containerd/containerd@v1.7.30 | CVE-2026-53488 | HIGH | affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | github.com/docker/docker@v25.0.13+incompatible | CVE-2026-41567 | HIGH | affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | github.com/docker/docker@v25.0.13+incompatible | CVE-2026-42306 | HIGH | affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | github.com/go-jose/go-jose/v3@v3.0.4 | CVE-2026-34986 | HIGH | affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | github.com/microsoft/kiota-http-go@v1.4.4 | CVE-2026-44503 | HIGH | affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | github.com/rancher/rancher@v2.14.0 | CVE-2026-25705 | HIGH | affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | github.com/russellhaering/goxmldsig@v1.4.0 | CVE-2026-33487 | HIGH | affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | go.opentelemetry.io/otel@v1.38.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | golang.org/x/crypto@v0.48.0 | CVE-2026-39829 | HIGH | affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | golang.org/x/crypto@v0.48.0 | CVE-2026-46597 | HIGH | affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | golang.org/x/crypto@v0.48.0 | CVE-2026-39831 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | golang.org/x/crypto@v0.48.0 | CVE-2026-39832 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | golang.org/x/crypto@v0.48.0 | CVE-2026-39833 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | golang.org/x/crypto@v0.48.0 | CVE-2026-39834 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | golang.org/x/crypto@v0.48.0 | CVE-2026-46598 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | golang.org/x/net@v0.51.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | golang.org/x/net@v0.51.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | google.golang.org/grpc@v1.79.1 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | stdlib@v1.25.8 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | stdlib@v1.25.8 | CVE-2026-33811 | HIGH | affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | stdlib@v1.25.8 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | stdlib@v1.25.8 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | stdlib@v1.25.8 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | stdlib@v1.25.8 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/kubectl | go.opentelemetry.io/otel@v1.36.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.25.6 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.25.6 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.25.6 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.25.6 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.25.6 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/rancher-webhook:v0.10.0 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| rancher/rancher-webhook:v0.10.0 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| rancher/rancher-webhook:v0.10.0 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | HIGH | affected | sles | |
| rancher/rancher-webhook:v0.10.0 | false | Harvester v1.8.0 | usr/bin/webhook | go.opentelemetry.io/otel@v1.37.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/rancher-webhook:v0.10.0 | false | Harvester v1.8.0 | usr/bin/webhook | golang.org/x/net@v0.52.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rancher-webhook:v0.10.0 | false | Harvester v1.8.0 | usr/bin/webhook | golang.org/x/net@v0.52.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/rancher-webhook:v0.10.0 | false | Harvester v1.8.0 | usr/bin/webhook | stdlib@v1.25.8 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/rancher-webhook:v0.10.0 | false | Harvester v1.8.0 | usr/bin/webhook | stdlib@v1.25.8 | CVE-2026-33811 | HIGH | affected | gobinary | |
| rancher/rancher-webhook:v0.10.0 | false | Harvester v1.8.0 | usr/bin/webhook | stdlib@v1.25.8 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rancher-webhook:v0.10.0 | false | Harvester v1.8.0 | usr/bin/webhook | stdlib@v1.25.8 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/rancher-webhook:v0.10.0 | false | Harvester v1.8.0 | usr/bin/webhook | stdlib@v1.25.8 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/rancher-webhook:v0.10.0 | false | Harvester v1.8.0 | usr/bin/webhook | stdlib@v1.25.8 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | HIGH | affected | sles | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-harvester | go.opentelemetry.io/otel@v1.36.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-harvester | golang.org/x/net@v0.38.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-harvester | golang.org/x/net@v0.38.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-harvester | kubevirt.io/kubevirt@v1.6.0 | CVE-2025-64324 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-harvester | stdlib@v1.25.5 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-harvester | stdlib@v1.25.5 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-harvester | stdlib@v1.25.5 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-harvester | stdlib@v1.25.5 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-linode | golang.org/x/crypto@v0.35.0 | CVE-2025-47913 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-linode | golang.org/x/crypto@v0.35.0 | CVE-2026-39828 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-linode | golang.org/x/crypto@v0.35.0 | CVE-2026-39829 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-linode | golang.org/x/crypto@v0.35.0 | CVE-2026-39835 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-linode | golang.org/x/crypto@v0.35.0 | CVE-2026-42508 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-linode | golang.org/x/crypto@v0.35.0 | CVE-2026-46595 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-linode | golang.org/x/crypto@v0.35.0 | CVE-2026-46597 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-linode | golang.org/x/crypto@v0.35.0 | CVE-2026-39831 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-linode | golang.org/x/crypto@v0.35.0 | CVE-2026-39832 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-linode | golang.org/x/crypto@v0.35.0 | CVE-2026-39833 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-linode | golang.org/x/crypto@v0.35.0 | CVE-2026-39834 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-linode | golang.org/x/crypto@v0.35.0 | CVE-2026-46598 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-linode | golang.org/x/net@v0.36.0 | CVE-2026-25680 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-linode | golang.org/x/net@v0.36.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-linode | golang.org/x/net@v0.36.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-linode | stdlib@v1.24.1 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-linode | stdlib@v1.24.1 | CVE-2025-22874 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-linode | stdlib@v1.24.1 | CVE-2025-61729 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-linode | stdlib@v1.24.1 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-linode | stdlib@v1.24.1 | CVE-2026-33811 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-linode | stdlib@v1.24.1 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-linode | stdlib@v1.24.1 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-linode | stdlib@v1.24.1 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-linode | stdlib@v1.24.1 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-linode | stdlib@v1.24.1 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-linode | stdlib@v1.24.1 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-linode | stdlib@v1.24.1 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/bandwidth | stdlib@v1.25.6 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/bandwidth | stdlib@v1.25.6 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/bandwidth | stdlib@v1.25.6 | CVE-2026-33811 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/bandwidth | stdlib@v1.25.6 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/bandwidth | stdlib@v1.25.6 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/bandwidth | stdlib@v1.25.6 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/bandwidth | stdlib@v1.25.6 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/cni | stdlib@v1.25.6 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/cni | stdlib@v1.25.6 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/cni | stdlib@v1.25.6 | CVE-2026-33811 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/cni | stdlib@v1.25.6 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/cni | stdlib@v1.25.6 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/cni | stdlib@v1.25.6 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/cni | stdlib@v1.25.6 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | github.com/docker/docker@v25.0.8+incompatible | CVE-2026-41567 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | github.com/docker/docker@v25.0.8+incompatible | CVE-2026-42306 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | github.com/docker/docker@v25.0.8+incompatible | CVE-2026-33997 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | github.com/flannel-io/flannel@v0.28.0 | CVE-2026-32241 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | github.com/go-jose/go-jose/v4@v4.0.5 | CVE-2026-34986 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | github.com/nats-io/nats-server/v2@v2.12.2 | CVE-2026-27889 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | github.com/nats-io/nats-server/v2@v2.12.2 | CVE-2026-29785 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | github.com/nats-io/nats-server/v2@v2.12.2 | CVE-2026-33216 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | github.com/nats-io/nats-server/v2@v2.12.2 | CVE-2026-33217 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | github.com/nats-io/nats-server/v2@v2.12.2 | CVE-2026-33218 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | github.com/nats-io/nats-server/v2@v2.12.2 | CVE-2026-33247 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | go.opentelemetry.io/otel@v1.38.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | google.golang.org/grpc@v1.72.2 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | stdlib@v1.25.6 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | stdlib@v1.25.6 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | stdlib@v1.25.6 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | stdlib@v1.25.6 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | stdlib@v1.25.6 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | stdlib@v1.25.6 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd-shim-runc-v2 | github.com/containerd/containerd/v2@v2.1.5-k3s1 | CVE-2026-53488 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd-shim-runc-v2 | github.com/containerd/containerd/v2@v2.1.5-k3s1 | CVE-2026-53492 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd-shim-runc-v2 | github.com/containerd/containerd/v2@v2.1.5-k3s1 | CVE-2026-50195 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd-shim-runc-v2 | golang.org/x/net@v0.38.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd-shim-runc-v2 | golang.org/x/net@v0.38.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd-shim-runc-v2 | stdlib@v1.25.6 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd-shim-runc-v2 | stdlib@v1.25.6 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd-shim-runc-v2 | stdlib@v1.25.6 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd-shim-runc-v2 | stdlib@v1.25.6 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/etcdctl | stdlib@v1.24.11 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/etcdctl | stdlib@v1.24.11 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/etcdctl | stdlib@v1.24.11 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/etcdctl | stdlib@v1.24.11 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/firewall | stdlib@v1.25.6 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/firewall | stdlib@v1.25.6 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/firewall | stdlib@v1.25.6 | CVE-2026-33811 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/firewall | stdlib@v1.25.6 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/firewall | stdlib@v1.25.6 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/firewall | stdlib@v1.25.6 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/firewall | stdlib@v1.25.6 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | github.com/docker/docker@v25.0.8+incompatible | CVE-2026-41567 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | github.com/docker/docker@v25.0.8+incompatible | CVE-2026-42306 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | github.com/docker/docker@v25.0.8+incompatible | CVE-2026-33997 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | github.com/flannel-io/flannel@v0.28.0 | CVE-2026-32241 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | github.com/go-jose/go-jose/v4@v4.0.5 | CVE-2026-34986 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | github.com/nats-io/nats-server/v2@v2.12.2 | CVE-2026-27889 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | github.com/nats-io/nats-server/v2@v2.12.2 | CVE-2026-29785 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | github.com/nats-io/nats-server/v2@v2.12.2 | CVE-2026-33216 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | github.com/nats-io/nats-server/v2@v2.12.2 | CVE-2026-33217 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | github.com/nats-io/nats-server/v2@v2.12.2 | CVE-2026-33218 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | github.com/nats-io/nats-server/v2@v2.12.2 | CVE-2026-33247 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | go.opentelemetry.io/otel@v1.38.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | google.golang.org/grpc@v1.72.2 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | stdlib@v1.25.6 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | stdlib@v1.25.6 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | stdlib@v1.25.6 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | stdlib@v1.25.6 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | stdlib@v1.25.6 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | stdlib@v1.25.6 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | github.com/containerd/containerd@v1.7.30 | CVE-2026-46680 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | github.com/containerd/containerd@v1.7.30 | CVE-2026-53488 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | github.com/docker/docker@v25.0.13+incompatible | CVE-2026-41567 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | github.com/docker/docker@v25.0.13+incompatible | CVE-2026-42306 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | github.com/go-jose/go-jose/v3@v3.0.4 | CVE-2026-34986 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | github.com/microsoft/kiota-http-go@v1.4.4 | CVE-2026-44503 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | github.com/rancher/rancher@v2.14.0 | CVE-2026-25705 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | github.com/russellhaering/goxmldsig@v1.4.0 | CVE-2026-33487 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | go.opentelemetry.io/otel@v1.38.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | golang.org/x/crypto@v0.48.0 | CVE-2026-39829 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | golang.org/x/crypto@v0.48.0 | CVE-2026-46597 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | golang.org/x/crypto@v0.48.0 | CVE-2026-39831 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | golang.org/x/crypto@v0.48.0 | CVE-2026-39832 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | golang.org/x/crypto@v0.48.0 | CVE-2026-39833 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | golang.org/x/crypto@v0.48.0 | CVE-2026-39834 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | golang.org/x/crypto@v0.48.0 | CVE-2026-46598 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | golang.org/x/net@v0.51.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | golang.org/x/net@v0.51.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | google.golang.org/grpc@v1.79.1 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | stdlib@v1.25.8 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | stdlib@v1.25.8 | CVE-2026-33811 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | stdlib@v1.25.8 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | stdlib@v1.25.8 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | stdlib@v1.25.8 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | stdlib@v1.25.8 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | github.com/docker/docker@v25.0.8+incompatible | CVE-2026-34040 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | github.com/docker/docker@v25.0.8+incompatible | CVE-2026-41567 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | github.com/docker/docker@v25.0.8+incompatible | CVE-2026-42306 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | github.com/docker/docker@v25.0.8+incompatible | CVE-2026-33997 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | golang.org/x/crypto@v0.44.0 | CVE-2026-39829 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | golang.org/x/crypto@v0.44.0 | CVE-2026-46597 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | golang.org/x/crypto@v0.44.0 | CVE-2026-39831 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | golang.org/x/crypto@v0.44.0 | CVE-2026-39834 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | stdlib@v1.25.8 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | stdlib@v1.25.8 | CVE-2026-33811 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | stdlib@v1.25.8 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | stdlib@v1.25.8 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | stdlib@v1.25.8 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | stdlib@v1.25.8 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/runc | stdlib@v1.25.6 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | go.opentelemetry.io/otel@v1.38.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | golang.org/x/crypto@v0.45.0 | CVE-2026-39828 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | golang.org/x/crypto@v0.45.0 | CVE-2026-39829 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | golang.org/x/crypto@v0.45.0 | CVE-2026-39835 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | golang.org/x/crypto@v0.45.0 | CVE-2026-42508 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | golang.org/x/crypto@v0.45.0 | CVE-2026-46595 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | golang.org/x/crypto@v0.45.0 | CVE-2026-46597 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | golang.org/x/crypto@v0.45.0 | CVE-2026-39831 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | golang.org/x/crypto@v0.45.0 | CVE-2026-39832 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | golang.org/x/crypto@v0.45.0 | CVE-2026-39833 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | golang.org/x/crypto@v0.45.0 | CVE-2026-39834 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | golang.org/x/crypto@v0.45.0 | CVE-2026-46598 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | golang.org/x/net@v0.47.0 | CVE-2026-25680 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | google.golang.org/grpc@v1.76.0 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | github.com/nats-io/nats-server/v2@v2.12.2 | CVE-2026-27889 | HIGH | affected | gobinary | |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | github.com/nats-io/nats-server/v2@v2.12.2 | CVE-2026-29785 | HIGH | affected | gobinary | |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | github.com/nats-io/nats-server/v2@v2.12.2 | CVE-2026-33216 | HIGH | affected | gobinary | |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | github.com/nats-io/nats-server/v2@v2.12.2 | CVE-2026-33217 | HIGH | affected | gobinary | |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | github.com/nats-io/nats-server/v2@v2.12.2 | CVE-2026-33218 | HIGH | affected | gobinary | |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | github.com/nats-io/nats-server/v2@v2.12.2 | CVE-2026-33247 | HIGH | affected | gobinary | |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | go.opentelemetry.io/otel@v1.38.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | stdlib@v1.25.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | github.com/containerd/containerd/v2@v2.1.5-k3s1 | CVE-2026-53488 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | github.com/containerd/containerd/v2@v2.1.5-k3s1 | CVE-2026-53492 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | github.com/containerd/containerd/v2@v2.1.5-k3s1 | CVE-2026-50195 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | golang.org/x/net@v0.38.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | golang.org/x/net@v0.38.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | stdlib@v1.24.13 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | stdlib@v1.24.13 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | stdlib@v1.24.13 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd-shim-runc-v2 | github.com/containerd/containerd/v2@v2.1.5-k3s1 | CVE-2026-53488 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd-shim-runc-v2 | github.com/containerd/containerd/v2@v2.1.5-k3s1 | CVE-2026-53492 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd-shim-runc-v2 | github.com/containerd/containerd/v2@v2.1.5-k3s1 | CVE-2026-50195 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd-shim-runc-v2 | golang.org/x/net@v0.38.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd-shim-runc-v2 | golang.org/x/net@v0.38.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd-shim-runc-v2 | stdlib@v1.24.13 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd-shim-runc-v2 | stdlib@v1.24.13 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd-shim-runc-v2 | stdlib@v1.24.13 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/crictl | go.opentelemetry.io/otel@v1.37.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/crictl | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/crictl | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/crictl | stdlib@v1.25.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/crictl | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/ctr | github.com/containerd/containerd/v2@v2.1.5-k3s1 | CVE-2026-53488 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/ctr | github.com/containerd/containerd/v2@v2.1.5-k3s1 | CVE-2026-53492 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/ctr | github.com/containerd/containerd/v2@v2.1.5-k3s1 | CVE-2026-50195 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/ctr | golang.org/x/net@v0.38.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/ctr | golang.org/x/net@v0.38.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/ctr | stdlib@v1.24.13 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/ctr | stdlib@v1.24.13 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/ctr | stdlib@v1.24.13 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubectl | go.opentelemetry.io/otel@v1.36.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubectl | stdlib@v1.25.7 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubectl | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubectl | stdlib@v1.25.7 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubelet | go.opentelemetry.io/otel@v1.36.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubelet | golang.org/x/crypto@v0.45.0 | CVE-2026-39829 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubelet | golang.org/x/crypto@v0.45.0 | CVE-2026-46597 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubelet | golang.org/x/crypto@v0.45.0 | CVE-2026-39831 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubelet | golang.org/x/crypto@v0.45.0 | CVE-2026-39834 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubelet | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubelet | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubelet | stdlib@v1.25.7 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubelet | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubelet | stdlib@v1.25.7 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/runc | stdlib@v1.24.13 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | busybox | busybox@1.37.0-150700.18.15.1 | SUSE-SU-2026:2054-1 | HIGH | affected | sles | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | libnghttp2-14 | libnghttp2-14@1.64.0-150700.1.5 | SUSE-SU-2026:1074-1 | HIGH | affected | sles | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/helm | github.com/containerd/containerd@v1.7.30 | CVE-2026-46680 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/helm | github.com/containerd/containerd@v1.7.30 | CVE-2026-53488 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/helm | golang.org/x/net@v0.48.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/helm | golang.org/x/net@v0.48.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/helm | stdlib@v1.25.8 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/helm | stdlib@v1.25.8 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/helm | stdlib@v1.25.8 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | github.com/containerd/containerd@v1.7.29 | CVE-2026-46680 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | github.com/containerd/containerd@v1.7.29 | CVE-2026-53488 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | github.com/docker/docker@v28.5.2+incompatible | CVE-2026-34040 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | github.com/docker/docker@v28.5.2+incompatible | CVE-2026-41567 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | github.com/docker/docker@v28.5.2+incompatible | CVE-2026-42306 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | github.com/docker/docker@v28.5.2+incompatible | CVE-2026-33997 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | github.com/go-git/go-billy/v5@v5.7.0 | CVE-2026-44973 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | github.com/go-git/go-billy/v5@v5.7.0 | CVE-2026-44740 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | github.com/go-git/go-git/v5@v5.16.3 | CVE-2026-45022 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | github.com/go-jose/go-jose/v4@v4.0.5 | CVE-2026-34986 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | github.com/hashicorp/go-getter@v1.8.3 | CVE-2026-4660 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | go.opentelemetry.io/otel@v1.37.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | golang.org/x/crypto@v0.46.0 | CVE-2026-39829 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | golang.org/x/crypto@v0.46.0 | CVE-2026-39835 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | golang.org/x/crypto@v0.46.0 | CVE-2026-42508 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | golang.org/x/crypto@v0.46.0 | CVE-2026-46597 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | golang.org/x/crypto@v0.46.0 | CVE-2026-39831 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | golang.org/x/crypto@v0.46.0 | CVE-2026-39834 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | golang.org/x/net@v0.48.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | golang.org/x/net@v0.48.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | stdlib@v1.25.1 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | stdlib@v1.25.1 | CVE-2025-61729 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | stdlib@v1.25.1 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | stdlib@v1.25.1 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | stdlib@v1.25.1 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | stdlib@v1.25.1 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | stdlib@v1.25.1 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | stdlib@v1.25.1 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | stdlib@v1.25.1 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | stdlib@v1.25.1 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/kubectl | go.opentelemetry.io/otel@v1.36.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/kubectl | stdlib@v1.25.7 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/kubectl | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/kubectl | stdlib@v1.25.7 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/kustomize | stdlib@v1.22.7 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/kustomize | stdlib@v1.22.7 | CVE-2025-61729 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/kustomize | stdlib@v1.22.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/kustomize | stdlib@v1.22.7 | CVE-2026-33811 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/kustomize | stdlib@v1.22.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/kustomize | stdlib@v1.22.7 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/kustomize | stdlib@v1.22.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/kustomize | stdlib@v1.22.7 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/kustomize | stdlib@v1.22.7 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/kustomize | stdlib@v1.22.7 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/kustomize | stdlib@v1.22.7 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/support-bundle-kit:master-head | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-150700.11.5.2 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| rancher/support-bundle-kit:master-head | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.51.3-150000.3.39.1 | SUSE-SU-2026:2528-1 | HIGH | affected | sles | |
| rancher/support-bundle-kit:master-head | false | Harvester v1.8.0 | libzypp | libzypp@17.37.18-150700.6.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| rancher/support-bundle-kit:master-head | false | Harvester v1.8.0 | zypper | zypper@1.14.94-150700.13.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| rancher/system-agent-installer-rancher:v2.14.0 | false | Harvester v1.8.0 | helm | github.com/containerd/containerd@v1.7.30 | CVE-2026-46680 | HIGH | affected | gobinary | |
| rancher/system-agent-installer-rancher:v2.14.0 | false | Harvester v1.8.0 | helm | github.com/containerd/containerd@v1.7.30 | CVE-2026-53488 | HIGH | affected | gobinary | |
| rancher/system-agent-installer-rancher:v2.14.0 | false | Harvester v1.8.0 | helm | golang.org/x/net@v0.48.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/system-agent-installer-rancher:v2.14.0 | false | Harvester v1.8.0 | helm | golang.org/x/net@v0.48.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/system-agent-installer-rancher:v2.14.0 | false | Harvester v1.8.0 | helm | stdlib@v1.25.6 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/system-agent-installer-rancher:v2.14.0 | false | Harvester v1.8.0 | helm | stdlib@v1.25.6 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/system-agent-installer-rancher:v2.14.0 | false | Harvester v1.8.0 | helm | stdlib@v1.25.6 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/system-agent-installer-rancher:v2.14.0 | false | Harvester v1.8.0 | helm | stdlib@v1.25.6 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.43.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | opt/rancher-system-agent-suc/rancher-system-agent | go.opentelemetry.io/otel@v1.38.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | opt/rancher-system-agent-suc/rancher-system-agent | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | opt/rancher-system-agent-suc/rancher-system-agent | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | opt/rancher-system-agent-suc/rancher-system-agent | stdlib@v1.25.8 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | opt/rancher-system-agent-suc/rancher-system-agent | stdlib@v1.25.8 | CVE-2026-33811 | HIGH | affected | gobinary | |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | opt/rancher-system-agent-suc/rancher-system-agent | stdlib@v1.25.8 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | opt/rancher-system-agent-suc/rancher-system-agent | stdlib@v1.25.8 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | opt/rancher-system-agent-suc/rancher-system-agent | stdlib@v1.25.8 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | opt/rancher-system-agent-suc/rancher-system-agent | stdlib@v1.25.8 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | usr/bin/kubectl | golang.org/x/net@v0.38.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | usr/bin/kubectl | golang.org/x/net@v0.38.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.24.6 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.24.6 | CVE-2025-61729 | HIGH | affected | gobinary | |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.24.6 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.24.6 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.24.6 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.24.6 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.24.6 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.24.6 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.24.6 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/system-upgrade-controller:v0.19.0 | false | Harvester v1.8.0 | bin/system-upgrade-controller | golang.org/x/net@v0.47.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/system-upgrade-controller:v0.19.0 | false | Harvester v1.8.0 | bin/system-upgrade-controller | golang.org/x/net@v0.47.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/system-upgrade-controller:v0.19.0 | false | Harvester v1.8.0 | bin/system-upgrade-controller | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/system-upgrade-controller:v0.19.0 | false | Harvester v1.8.0 | bin/system-upgrade-controller | stdlib@v1.25.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/system-upgrade-controller:v0.19.0 | false | Harvester v1.8.0 | bin/system-upgrade-controller | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/turtles:v0.26.0 | false | Harvester v1.8.0 | manager | golang.org/x/net@v0.51.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/turtles:v0.26.0 | false | Harvester v1.8.0 | manager | golang.org/x/net@v0.51.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| rancher/turtles:v0.26.0 | false | Harvester v1.8.0 | manager | stdlib@v1.25.8 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/turtles:v0.26.0 | false | Harvester v1.8.0 | manager | stdlib@v1.25.8 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/turtles:v0.26.0 | false | Harvester v1.8.0 | manager | stdlib@v1.25.8 | CVE-2026-39836 | HIGH | affected | gobinary | |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | golang.org/x/net@v0.38.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | golang.org/x/net@v0.38.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | google.golang.org/grpc@v1.68.1 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | stdlib@v1.24.2 | CVE-2025-68121 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | stdlib@v1.24.2 | CVE-2025-22874 | HIGH | affected | gobinary | |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | stdlib@v1.24.2 | CVE-2025-61729 | HIGH | affected | gobinary | |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | stdlib@v1.24.2 | CVE-2026-32280 | HIGH | affected | gobinary | |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | stdlib@v1.24.2 | CVE-2026-33811 | HIGH | affected | gobinary | |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | stdlib@v1.24.2 | CVE-2026-33814 | HIGH | affected | gobinary | |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | stdlib@v1.24.2 | CVE-2026-39820 | HIGH | affected | gobinary | |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | stdlib@v1.24.2 | CVE-2026-39836 | HIGH | affected | gobinary | |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | stdlib@v1.24.2 | CVE-2026-42499 | HIGH | affected | gobinary | |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | stdlib@v1.24.2 | CVE-2025-47912 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | stdlib@v1.24.2 | CVE-2025-58188 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | stdlib@v1.24.2 | CVE-2025-61727 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| registry.k8s.io/sig-storage/snapshot-controller:v8.5.0 | false | Harvester v1.8.0 | snapshot-controller | go.opentelemetry.io/otel@v1.40.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| registry.k8s.io/sig-storage/snapshot-controller:v8.5.0 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/net@v0.49.0 | CVE-2026-33814 | HIGH | affected | gobinary | |
| registry.k8s.io/sig-storage/snapshot-controller:v8.5.0 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/net@v0.49.0 | CVE-2026-39821 | HIGH | affected | gobinary | |
| registry.k8s.io/sig-storage/snapshot-controller:v8.5.0 | false | Harvester v1.8.0 | snapshot-controller | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| registry.k8s.io/sig-storage/snapshot-controller:v8.5.0 | false | Harvester v1.8.0 | snapshot-controller | stdlib@v1.25.7 | CVE-2026-33811 | HIGH | affected | gobinary | |
| registry.k8s.io/sig-storage/snapshot-controller:v8.5.0 | false | Harvester v1.8.0 | snapshot-controller | stdlib@v1.25.7 | CVE-2026-33814 | HIGH | affected | gobinary | |
| registry.k8s.io/sig-storage/snapshot-controller:v8.5.0 | false | Harvester v1.8.0 | snapshot-controller | stdlib@v1.25.7 | CVE-2026-39820 | HIGH | affected | gobinary | |
| registry.k8s.io/sig-storage/snapshot-controller:v8.5.0 | false | Harvester v1.8.0 | snapshot-controller | stdlib@v1.25.7 | CVE-2026-39836 | HIGH | affected | gobinary | |
| registry.k8s.io/sig-storage/snapshot-controller:v8.5.0 | false | Harvester v1.8.0 | snapshot-controller | stdlib@v1.25.7 | CVE-2026-42499 | HIGH | affected | gobinary | |
| registry.suse.com/bci/bci-base:16.0 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.36-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| registry.suse.com/bci/bci-base:16.0 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.51.3-160000.1.1 | SUSE-SU-2026:22166-1 | HIGH | affected | sles | |
| registry.suse.com/bci/bci-base:16.0 | false | Harvester v1.8.0 | libzypp | libzypp@17.38.5-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| registry.suse.com/bci/bci-base:16.0 | false | Harvester v1.8.0 | zypper | zypper@1.14.95-160000.1.1 | SUSE-SU-2026:22172-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | boost-license1_66_0 | boost-license1_66_0@1.66.0-12.3.1 | SUSE-SU-2025:02536-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.32.1 | SUSE-SU-2026:0371-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.32.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.32.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libboost_system1_66_0 | libboost_system1_66_0@1.66.0-12.3.1 | SUSE-SU-2025:02536-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libboost_thread1_66_0 | libboost_thread1_66_0@1.66.0-12.3.1 | SUSE-SU-2025:02536-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libbrotlicommon1 | libbrotlicommon1@1.0.7-3.3.1 | SUSE-SU-2025:03268-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libbrotlidec1 | libbrotlidec1@1.0.7-3.3.1 | SUSE-SU-2025:03268-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.6.0-150600.4.21.1 | SUSE-SU-2025:03198-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.6.0-150600.4.21.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.10.1 | SUSE-SU-2026:0309-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.10.1 | SUSE-SU-2025:03546-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.10.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.32-150600.8.10.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.49.1-150000.3.27.1 | SUSE-SU-2026:2528-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libudev1 | libudev1@254.25-150600.4.40.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libxml2-2 | libxml2-2@2.12.10-150700.4.3.1 | SUSE-SU-2025:02617-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libzypp | libzypp@17.37.5-150600.3.60.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | login_defs | login_defs@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | shadow | shadow@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | zypper | zypper@1.14.90-150600.10.34.3 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | curl | curl@8.6.0-150600.4.21.1 | SUSE-SU-2025:03198-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | curl | curl@8.6.0-150600.4.21.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.32.1 | SUSE-SU-2026:0371-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.32.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.32.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libboost_system1_66_0 | libboost_system1_66_0@1.66.0-12.3.1 | SUSE-SU-2025:02536-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libboost_thread1_66_0 | libboost_thread1_66_0@1.66.0-12.3.1 | SUSE-SU-2025:02536-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libbrotlidec1 | libbrotlidec1@1.0.7-3.3.1 | SUSE-SU-2025:03268-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.6.0-150600.4.21.1 | SUSE-SU-2025:03198-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.6.0-150600.4.21.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libglib-2_0-0 | libglib-2_0-0@2.78.6-150600.4.16.1 | SUSE-SU-2026:0018-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libglib-2_0-0 | libglib-2_0-0@2.78.6-150600.4.16.1 | SUSE-SU-2026:0373-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libnghttp2-14 | libnghttp2-14@1.64.0-150700.1.5 | SUSE-SU-2026:1074-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.10.1 | SUSE-SU-2026:0309-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.10.1 | SUSE-SU-2025:03546-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.10.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.32-150600.8.10.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.49.1-150000.3.27.1 | SUSE-SU-2026:2528-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libudev1 | libudev1@254.25-150600.4.40.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libxml2-2 | libxml2-2@2.12.10-150700.4.3.1 | SUSE-SU-2025:02617-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libzypp | libzypp@17.37.5-150600.3.60.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | login_defs | login_defs@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | shadow | shadow@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | zypper | zypper@1.14.90-150600.10.34.3 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | boost-license1_66_0 | boost-license1_66_0@1.66.0-12.3.1 | SUSE-SU-2025:02536-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | curl | curl@8.6.0-150600.4.21.1 | SUSE-SU-2025:03198-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | curl | curl@8.6.0-150600.4.21.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.32.1 | SUSE-SU-2026:0371-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.32.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.32.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libboost_thread1_66_0 | libboost_thread1_66_0@1.66.0-12.3.1 | SUSE-SU-2025:02536-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libbrotlicommon1 | libbrotlicommon1@1.0.7-3.3.1 | SUSE-SU-2025:03268-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libnghttp2-14 | libnghttp2-14@1.64.0-150700.1.5 | SUSE-SU-2026:1074-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.10.1 | SUSE-SU-2026:0309-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.10.1 | SUSE-SU-2025:03546-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.10.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.32-150600.8.10.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.49.1-150000.3.27.1 | SUSE-SU-2025:02672-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.49.1-150000.3.27.1 | SUSE-SU-2026:2528-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libxml2-2 | libxml2-2@2.12.10-150700.4.3.1 | SUSE-SU-2025:02617-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libzypp | libzypp@17.37.5-150600.3.60.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | login_defs | login_defs@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.10.1 | SUSE-SU-2026:0309-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.10.1 | SUSE-SU-2025:03546-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.10.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | zypper | zypper@1.14.90-150600.10.34.3 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | curl | curl@8.6.0-150600.4.21.1 | SUSE-SU-2025:03198-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | curl | curl@8.6.0-150600.4.21.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.32.1 | SUSE-SU-2026:0371-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.32.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.32.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libboost_system1_66_0 | libboost_system1_66_0@1.66.0-12.3.1 | SUSE-SU-2025:02536-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libbrotlicommon1 | libbrotlicommon1@1.0.7-3.3.1 | SUSE-SU-2025:03268-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libbrotlidec1 | libbrotlidec1@1.0.7-3.3.1 | SUSE-SU-2025:03268-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.6.0-150600.4.21.1 | SUSE-SU-2025:03198-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.6.0-150600.4.21.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libgmodule-2_0-0 | libgmodule-2_0-0@2.78.6-150600.4.16.1 | SUSE-SU-2026:0018-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libgmodule-2_0-0 | libgmodule-2_0-0@2.78.6-150600.4.16.1 | SUSE-SU-2026:0373-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libgnutls30 | libgnutls30@3.8.3-150600.4.6.2 | SUSE-SU-2025:02595-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libgnutls30 | libgnutls30@3.8.3-150600.4.6.2 | SUSE-SU-2026:2115-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libnghttp2-14 | libnghttp2-14@1.64.0-150700.1.5 | SUSE-SU-2026:1074-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.10.1 | SUSE-SU-2026:0309-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.10.1 | SUSE-SU-2025:03546-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.10.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.32-150600.8.10.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.49.1-150000.3.27.1 | SUSE-SU-2025:02672-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.49.1-150000.3.27.1 | SUSE-SU-2026:2528-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libudev1 | libudev1@254.25-150600.4.40.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libxml2-2 | libxml2-2@2.12.10-150700.4.3.1 | SUSE-SU-2025:02617-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libzypp | libzypp@17.37.5-150600.3.60.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | login_defs | login_defs@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.10.1 | SUSE-SU-2026:0309-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.10.1 | SUSE-SU-2025:03546-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.10.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | qemu-img | qemu-img@9.2.4-150700.3.5.1 | SUSE-SU-2026:0288-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | qemu-img | qemu-img@9.2.4-150700.3.5.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | zypper | zypper@1.14.90-150600.10.34.3 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | boost-license1_66_0 | boost-license1_66_0@1.66.0-12.3.1 | SUSE-SU-2025:02536-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | curl | curl@8.6.0-150600.4.21.1 | SUSE-SU-2025:03198-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | curl | curl@8.6.0-150600.4.21.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.32.1 | SUSE-SU-2026:0371-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.32.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.32.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libboost_thread1_66_0 | libboost_thread1_66_0@1.66.0-12.3.1 | SUSE-SU-2025:02536-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libbrotlidec1 | libbrotlidec1@1.0.7-3.3.1 | SUSE-SU-2025:03268-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.6.0-150600.4.21.1 | SUSE-SU-2025:03198-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.6.0-150600.4.21.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.10.1 | SUSE-SU-2026:0309-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.10.1 | SUSE-SU-2025:03546-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.10.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.10.1 | SUSE-SU-2026:0309-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.10.1 | SUSE-SU-2025:03546-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.10.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.32-150600.8.10.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.49.1-150000.3.27.1 | SUSE-SU-2026:2528-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libudev1 | libudev1@254.25-150600.4.40.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libxml2-2 | libxml2-2@2.12.10-150700.4.3.1 | SUSE-SU-2025:02617-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libzypp | libzypp@17.37.5-150600.3.60.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.10.1 | SUSE-SU-2026:0309-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.10.1 | SUSE-SU-2025:03546-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.10.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | shadow | shadow@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | zypper | zypper@1.14.90-150600.10.34.3 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | curl | curl@8.6.0-150600.4.21.1 | SUSE-SU-2025:03198-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | curl | curl@8.6.0-150600.4.21.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.32.1 | SUSE-SU-2026:0371-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.32.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.32.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libboost_system1_66_0 | libboost_system1_66_0@1.66.0-12.3.1 | SUSE-SU-2025:02536-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libboost_thread1_66_0 | libboost_thread1_66_0@1.66.0-12.3.1 | SUSE-SU-2025:02536-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libbrotlicommon1 | libbrotlicommon1@1.0.7-3.3.1 | SUSE-SU-2025:03268-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libnghttp2-14 | libnghttp2-14@1.64.0-150700.1.5 | SUSE-SU-2026:1074-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.10.1 | SUSE-SU-2026:0309-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.10.1 | SUSE-SU-2025:03546-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.10.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.10.1 | SUSE-SU-2026:0309-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.10.1 | SUSE-SU-2025:03546-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.10.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.32-150600.8.10.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.49.1-150000.3.27.1 | SUSE-SU-2025:02672-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.49.1-150000.3.27.1 | SUSE-SU-2026:2528-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libxml2-2 | libxml2-2@2.12.10-150700.4.3.1 | SUSE-SU-2025:02617-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libzypp | libzypp@17.37.5-150600.3.60.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | login_defs | login_defs@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.10.1 | SUSE-SU-2026:0309-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.10.1 | SUSE-SU-2025:03546-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.10.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | shadow | shadow@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | zypper | zypper@1.14.90-150600.10.34.3 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | boost-license1_66_0 | boost-license1_66_0@1.66.0-12.3.1 | SUSE-SU-2025:02536-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | curl | curl@8.6.0-150600.4.21.1 | SUSE-SU-2025:03198-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | curl | curl@8.6.0-150600.4.21.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.32.1 | SUSE-SU-2026:0371-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.32.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.32.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libboost_system1_66_0 | libboost_system1_66_0@1.66.0-12.3.1 | SUSE-SU-2025:02536-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libbrotlicommon1 | libbrotlicommon1@1.0.7-3.3.1 | SUSE-SU-2025:03268-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libbrotlidec1 | libbrotlidec1@1.0.7-3.3.1 | SUSE-SU-2025:03268-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libglib-2_0-0 | libglib-2_0-0@2.78.6-150600.4.16.1 | SUSE-SU-2026:0018-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libglib-2_0-0 | libglib-2_0-0@2.78.6-150600.4.16.1 | SUSE-SU-2026:0373-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libgnutls30 | libgnutls30@3.8.3-150600.4.6.2 | SUSE-SU-2025:02595-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libgnutls30 | libgnutls30@3.8.3-150600.4.6.2 | SUSE-SU-2026:2115-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.10.1 | SUSE-SU-2026:0309-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.10.1 | SUSE-SU-2025:03546-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.10.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.10.1 | SUSE-SU-2026:0309-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.10.1 | SUSE-SU-2025:03546-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.10.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.32-150600.8.10.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.49.1-150000.3.27.1 | SUSE-SU-2026:2528-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libudev1 | libudev1@254.25-150600.4.40.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libxml2-2 | libxml2-2@2.12.10-150700.4.3.1 | SUSE-SU-2025:02617-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libzypp | libzypp@17.37.5-150600.3.60.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.10.1 | SUSE-SU-2026:0309-1 | CRITICAL | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.10.1 | SUSE-SU-2025:03546-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.10.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | qemu-img | qemu-img@9.2.4-150700.3.5.1 | SUSE-SU-2026:0288-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | qemu-img | qemu-img@9.2.4-150700.3.5.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | shadow | shadow@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | zypper | zypper@1.14.90-150600.10.34.3 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | curl | curl@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.40.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.40.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libgnutls30 | libgnutls30@3.8.3-150600.4.12.1 | SUSE-SU-2026:2115-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libnghttp2-14 | libnghttp2-14@1.64.0-150700.1.5 | SUSE-SU-2026:1074-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libntfs-3g87 | libntfs-3g87@2022.5.17-150000.3.21.1 | SUSE-SU-2026:1571-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libopenssl1_1 | libopenssl1_1@1.1.1w-150700.11.11.1 | SUSE-SU-2026:1386-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libopenssl1_1 | libopenssl1_1@1.1.1w-150700.11.11.1 | SUSE-SU-2026:2392-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libpng16-16 | libpng16-16@1.6.40-150600.3.9.1 | SUSE-SU-2026:0597-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libpng16-16 | libpng16-16@1.6.40-150600.3.9.1 | SUSE-SU-2026:1368-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libpython3_6m1_0 | libpython3_6m1_0@3.6.15-150300.10.103.1 | SUSE-SU-2026:0664-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libpython3_6m1_0 | libpython3_6m1_0@3.6.15-150300.10.103.1 | SUSE-SU-2026:1090-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libpython3_6m1_0 | libpython3_6m1_0@3.6.15-150300.10.103.1 | SUSE-SU-2026:1715-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-150700.11.5.2 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libsoup-3_0-0 | libsoup-3_0-0@3.4.4-150600.3.31.1 | SUSE-SU-2026:0690-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libsoup-3_0-0 | libsoup-3_0-0@3.4.4-150600.3.31.1 | SUSE-SU-2026:0788-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libsoup-3_0-0 | libsoup-3_0-0@3.4.4-150600.3.31.1 | SUSE-SU-2026:2314-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.50.2-150000.3.33.1 | SUSE-SU-2026:2528-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libsystemd0 | libsystemd0@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libudev1 | libudev1@254.27-150600.4.46.2 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libvirt-libs | libvirt-libs@11.0.0-150700.4.13.1 | SUSE-SU-2026:1169-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libzypp | libzypp@17.37.18-150700.6.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | login_defs | login_defs@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | ntfs-3g | ntfs-3g@2022.5.17-150000.3.21.1 | SUSE-SU-2026:1571-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | ntfsprogs | ntfsprogs@2022.5.17-150000.3.21.1 | SUSE-SU-2026:1571-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | python3-base | python3-base@3.6.15-150300.10.103.1 | SUSE-SU-2026:0664-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | python3-base | python3-base@3.6.15-150300.10.103.1 | SUSE-SU-2026:1090-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | python3-base | python3-base@3.6.15-150300.10.103.1 | SUSE-SU-2026:1715-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu | qemu@9.2.4-150700.3.14.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu-accel-tcg-x86 | qemu-accel-tcg-x86@9.2.4-150700.3.14.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu-hw-display-virtio-gpu | qemu-hw-display-virtio-gpu@9.2.4-150700.3.14.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu-hw-display-virtio-gpu-pci | qemu-hw-display-virtio-gpu-pci@9.2.4-150700.3.14.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu-hw-display-virtio-vga | qemu-hw-display-virtio-vga@9.2.4-150700.3.14.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu-img | qemu-img@9.2.4-150700.3.14.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu-ipxe | qemu-ipxe@9.2.4-150700.3.14.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu-ovmf-x86_64 | qemu-ovmf-x86_64@202408-150700.3.12.1 | SUSE-SU-2026:1952-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu-pr-helper | qemu-pr-helper@9.2.4-150700.3.14.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu-seabios | qemu-seabios@9.2.41.16.3_3_g3d33c746-150700.3.14.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu-tools | qemu-tools@9.2.4-150700.3.14.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu-vgabios | qemu-vgabios@9.2.41.16.3_3_g3d33c746-150700.3.14.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu-vmsr-helper | qemu-vmsr-helper@9.2.4-150700.3.14.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu-x86 | qemu-x86@9.2.4-150700.3.14.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | shadow | shadow@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | udev | udev@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | virtiofsd | virtiofsd@1.12.0-150700.1.8 | SUSE-SU-2026:0819-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | wicked | wicked@0.6.78-150700.1.4 | SUSE-SU-2026:2349-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | wicked-service | wicked-service@0.6.78-150700.1.4 | SUSE-SU-2026:2349-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | xen-libs | xen-libs@4.20.2_04-150700.3.22.1 | SUSE-SU-2026:1093-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | xen-libs | xen-libs@4.20.2_04-150700.3.22.1 | SUSE-SU-2026:1743-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | xen-libs | xen-libs@4.20.2_04-150700.3.22.1 | SUSE-SU-2026:1998-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | xen-libs | xen-libs@4.20.2_04-150700.3.22.1 | SUSE-SU-2026:2364-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | xz | xz@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-150700.13.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-api:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.40.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-api:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.40.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-api:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-api:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-api:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-api:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libnghttp2-14 | libnghttp2-14@1.64.0-150700.1.5 | SUSE-SU-2026:1074-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-api:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-api:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-150700.11.5.2 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-api:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.50.2-150000.3.33.1 | SUSE-SU-2026:2528-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-api:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libudev1 | libudev1@254.27-150600.4.46.2 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-api:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libzypp | libzypp@17.37.18-150700.6.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-api:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | login_defs | login_defs@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-api:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-api:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-150700.13.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-controller:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | curl | curl@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-controller:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.40.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-controller:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.40.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-controller:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-controller:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-controller:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-controller:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libnghttp2-14 | libnghttp2-14@1.64.0-150700.1.5 | SUSE-SU-2026:1074-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-controller:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-controller:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-controller:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-150700.11.5.2 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-controller:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.50.2-150000.3.33.1 | SUSE-SU-2026:2528-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-controller:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libzypp | libzypp@17.37.18-150700.6.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-controller:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | login_defs | login_defs@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-controller:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-controller:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-150700.13.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-handler:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.40.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-handler:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.40.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-handler:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-handler:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-handler:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libgnutls30 | libgnutls30@3.8.3-150600.4.12.1 | SUSE-SU-2026:2115-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-handler:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-handler:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libnghttp2-14 | libnghttp2-14@1.64.0-150700.1.5 | SUSE-SU-2026:1074-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-handler:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-handler:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-handler:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-150700.11.5.2 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-handler:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.50.2-150000.3.33.1 | SUSE-SU-2026:2528-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-handler:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libsystemd0 | libsystemd0@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-handler:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libudev1 | libudev1@254.27-150600.4.46.2 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-handler:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libzypp | libzypp@17.37.18-150700.6.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-handler:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | login_defs | login_defs@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-handler:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-handler:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu-img | qemu-img@9.2.4-150700.3.14.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-handler:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | shadow | shadow@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-handler:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | systemd | systemd@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-handler:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-150700.13.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | curl | curl@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.40.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.40.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | gnutls | gnutls@3.8.3-150600.4.12.1 | SUSE-SU-2026:2115-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libcap-progs | libcap-progs@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libgnutls30 | libgnutls30@3.8.3-150600.4.12.1 | SUSE-SU-2026:2115-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libnghttp2-14 | libnghttp2-14@1.64.0-150700.1.5 | SUSE-SU-2026:1074-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libpng16-16 | libpng16-16@1.6.40-150600.3.9.1 | SUSE-SU-2026:0597-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libpng16-16 | libpng16-16@1.6.40-150600.3.9.1 | SUSE-SU-2026:1368-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-150700.11.5.2 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.50.2-150000.3.33.1 | SUSE-SU-2026:2528-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libsystemd0 | libsystemd0@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libudev1 | libudev1@254.27-150600.4.46.2 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libvirt-client | libvirt-client@11.0.0-150700.4.13.1 | SUSE-SU-2026:1169-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libvirt-daemon-common | libvirt-daemon-common@11.0.0-150700.4.13.1 | SUSE-SU-2026:1169-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libvirt-daemon-driver-qemu | libvirt-daemon-driver-qemu@11.0.0-150700.4.13.1 | SUSE-SU-2026:1169-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libvirt-daemon-log | libvirt-daemon-log@11.0.0-150700.4.13.1 | SUSE-SU-2026:1169-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libvirt-libs | libvirt-libs@11.0.0-150700.4.13.1 | SUSE-SU-2026:1169-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libzypp | libzypp@17.37.18-150700.6.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | login_defs | login_defs@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu | qemu@9.2.4-150700.3.14.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu-accel-tcg-x86 | qemu-accel-tcg-x86@9.2.4-150700.3.14.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu-hw-display-virtio-gpu | qemu-hw-display-virtio-gpu@9.2.4-150700.3.14.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu-hw-display-virtio-gpu-pci | qemu-hw-display-virtio-gpu-pci@9.2.4-150700.3.14.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu-hw-display-virtio-vga | qemu-hw-display-virtio-vga@9.2.4-150700.3.14.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu-hw-usb-host | qemu-hw-usb-host@9.2.4-150700.3.14.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu-hw-usb-redirect | qemu-hw-usb-redirect@9.2.4-150700.3.14.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu-img | qemu-img@9.2.4-150700.3.14.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu-ovmf-x86_64 | qemu-ovmf-x86_64@202408-150700.3.12.1 | SUSE-SU-2026:1952-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu-x86 | qemu-x86@9.2.4-150700.3.14.1 | SUSE-SU-2026:2385-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | shadow | shadow@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | systemd | systemd@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | virtiofsd | virtiofsd@1.12.0-150700.1.8 | SUSE-SU-2026:0819-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | xz | xz@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-150700.13.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-operator:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | curl | curl@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-operator:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.40.1 | SUSE-SU-2026:1369-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-operator:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | glibc | glibc@2.38-150600.14.40.1 | SUSE-SU-2026:2231-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-operator:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-operator:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-operator:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-operator:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-operator:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libsolv-tools-base | libsolv-tools-base@0.7.35-150700.11.5.2 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-operator:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.50.2-150000.3.33.1 | SUSE-SU-2026:2528-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-operator:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libudev1 | libudev1@254.27-150600.4.46.2 | SUSE-SU-2026:1040-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-operator:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libzypp | libzypp@17.37.18-150700.6.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-operator:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-operator:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | shadow | shadow@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | HIGH | affected | sles | |
| registry.suse.com/suse/sles/15.7/virt-operator:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | zypper | zypper@1.14.94-150700.13.3.1 | SUSE-SU-2026:2531-1 | HIGH | affected | sles | |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | ip-control-loop | golang.org/x/net@v0.49.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | ip-control-loop | golang.org/x/net@v0.49.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | ip-control-loop | golang.org/x/net@v0.49.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | ip-control-loop | golang.org/x/net@v0.49.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | ip-control-loop | golang.org/x/net@v0.49.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | ip-control-loop | stdlib@v1.25.6 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | ip-control-loop | stdlib@v1.25.6 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | ip-control-loop | stdlib@v1.25.6 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | ip-control-loop | stdlib@v1.25.6 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | ip-control-loop | stdlib@v1.25.6 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | node-slice-controller | golang.org/x/net@v0.49.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | node-slice-controller | golang.org/x/net@v0.49.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | node-slice-controller | golang.org/x/net@v0.49.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | node-slice-controller | golang.org/x/net@v0.49.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | node-slice-controller | golang.org/x/net@v0.49.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | node-slice-controller | stdlib@v1.25.6 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | node-slice-controller | stdlib@v1.25.6 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | node-slice-controller | stdlib@v1.25.6 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | node-slice-controller | stdlib@v1.25.6 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | node-slice-controller | stdlib@v1.25.6 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | whereabouts | golang.org/x/net@v0.49.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | whereabouts | golang.org/x/net@v0.49.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | whereabouts | golang.org/x/net@v0.49.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | whereabouts | golang.org/x/net@v0.49.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | whereabouts | golang.org/x/net@v0.49.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | whereabouts | stdlib@v1.25.6 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | whereabouts | stdlib@v1.25.6 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | whereabouts | stdlib@v1.25.6 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | whereabouts | stdlib@v1.25.6 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| ghcr.io/k8snetworkplumbingwg/whereabouts:v0.9.3 | false | Harvester v1.8.0 | whereabouts | stdlib@v1.25.6 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn | golang.org/x/net@v0.44.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn | golang.org/x/net@v0.44.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn | golang.org/x/net@v0.44.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn | golang.org/x/net@v0.44.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn | golang.org/x/net@v0.44.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn | stdlib@v1.25.1 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn | stdlib@v1.25.1 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-cmd | go.opentelemetry.io/otel/sdk@v1.37.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-cmd | go.opentelemetry.io/otel/sdk@v1.37.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-cmd | golang.org/x/net@v0.44.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-cmd | golang.org/x/net@v0.44.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-cmd | golang.org/x/net@v0.44.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-cmd | golang.org/x/net@v0.44.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-cmd | golang.org/x/net@v0.44.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-cmd | stdlib@v1.25.1 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-cmd | stdlib@v1.25.1 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-controller | go.opentelemetry.io/otel/sdk@v1.37.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-controller | go.opentelemetry.io/otel/sdk@v1.37.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-controller | golang.org/x/net@v0.44.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-controller | golang.org/x/net@v0.44.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-controller | golang.org/x/net@v0.44.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-controller | golang.org/x/net@v0.44.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-controller | golang.org/x/net@v0.44.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-controller | stdlib@v1.25.1 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-controller | stdlib@v1.25.1 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | github.com/containerd/containerd/v2@v2.1.3 | CVE-2024-25621 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | github.com/containerd/containerd/v2@v2.1.3 | CVE-2026-46680 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | go.opentelemetry.io/otel/sdk@v1.37.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | go.opentelemetry.io/otel/sdk@v1.37.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | golang.org/x/net@v0.44.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | golang.org/x/net@v0.44.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | golang.org/x/net@v0.44.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | golang.org/x/net@v0.44.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | golang.org/x/net@v0.44.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | stdlib@v1.25.1 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | kube-ovn/kube-ovn-daemon | stdlib@v1.25.1 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | loopback | stdlib@v1.25.1 | CVE-2025-68121 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | loopback | stdlib@v1.25.1 | CVE-2025-61726 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | loopback | stdlib@v1.25.1 | CVE-2025-61729 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | loopback | stdlib@v1.25.1 | CVE-2026-25679 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | loopback | stdlib@v1.25.1 | CVE-2026-27145 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | loopback | stdlib@v1.25.1 | CVE-2026-32280 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | loopback | stdlib@v1.25.1 | CVE-2026-32281 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | loopback | stdlib@v1.25.1 | CVE-2026-32283 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | loopback | stdlib@v1.25.1 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | loopback | stdlib@v1.25.1 | CVE-2026-33814 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | loopback | stdlib@v1.25.1 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | loopback | stdlib@v1.25.1 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | loopback | stdlib@v1.25.1 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | loopback | stdlib@v1.25.1 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | loopback | stdlib@v1.25.1 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | loopback | stdlib@v1.25.1 | CVE-2026-42504 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | macvlan | stdlib@v1.25.1 | CVE-2025-68121 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | macvlan | stdlib@v1.25.1 | CVE-2025-61726 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | macvlan | stdlib@v1.25.1 | CVE-2025-61729 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | macvlan | stdlib@v1.25.1 | CVE-2026-25679 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | macvlan | stdlib@v1.25.1 | CVE-2026-27145 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | macvlan | stdlib@v1.25.1 | CVE-2026-32280 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | macvlan | stdlib@v1.25.1 | CVE-2026-32281 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | macvlan | stdlib@v1.25.1 | CVE-2026-32283 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | macvlan | stdlib@v1.25.1 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | macvlan | stdlib@v1.25.1 | CVE-2026-33814 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | macvlan | stdlib@v1.25.1 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | macvlan | stdlib@v1.25.1 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | macvlan | stdlib@v1.25.1 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | macvlan | stdlib@v1.25.1 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | macvlan | stdlib@v1.25.1 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | macvlan | stdlib@v1.25.1 | CVE-2026-42504 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | portmap | stdlib@v1.25.1 | CVE-2025-68121 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | portmap | stdlib@v1.25.1 | CVE-2025-61726 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | portmap | stdlib@v1.25.1 | CVE-2025-61729 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | portmap | stdlib@v1.25.1 | CVE-2026-25679 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | portmap | stdlib@v1.25.1 | CVE-2026-27145 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | portmap | stdlib@v1.25.1 | CVE-2026-32280 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | portmap | stdlib@v1.25.1 | CVE-2026-32281 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | portmap | stdlib@v1.25.1 | CVE-2026-32283 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | portmap | stdlib@v1.25.1 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | portmap | stdlib@v1.25.1 | CVE-2026-33814 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | portmap | stdlib@v1.25.1 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | portmap | stdlib@v1.25.1 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | portmap | stdlib@v1.25.1 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | portmap | stdlib@v1.25.1 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | portmap | stdlib@v1.25.1 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | portmap | stdlib@v1.25.1 | CVE-2026-42504 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/gobgp | golang.org/x/net@v0.38.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/gobgp | golang.org/x/net@v0.38.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/gobgp | golang.org/x/net@v0.38.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/gobgp | golang.org/x/net@v0.38.0 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/gobgp | golang.org/x/net@v0.38.0 | CVE-2026-39821 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/gobgp | golang.org/x/net@v0.38.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/gobgp | golang.org/x/net@v0.38.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/gobgp | stdlib@v1.25.1 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/gobgp | stdlib@v1.25.1 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/gobgp | stdlib@v1.25.1 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/gobgp | stdlib@v1.25.1 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| kubeovn/kube-ovn:v1.14.10 | false | Harvester v1.8.0 | usr/bin/gobgp | stdlib@v1.25.1 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | libexpat1 | libexpat1@2.7.1-150700.3.9.2 | SUSE-SU-2026:1352-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | libopenssl1_1 | libopenssl1_1@1.1.1w-150700.11.11.1 | SUSE-SU-2026:1386-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | libpython3_6m1_0 | libpython3_6m1_0@3.6.15-150300.10.106.1 | SUSE-SU-2026:1090-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | libpython3_6m1_0 | libpython3_6m1_0@3.6.15-150300.10.106.1 | SUSE-SU-2026:1715-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | libsystemd0 | libsystemd0@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | login_defs | login_defs@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | python3-base | python3-base@3.6.15-150300.10.106.1 | SUSE-SU-2026:1090-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | python3-base | python3-base@3.6.15-150300.10.106.1 | SUSE-SU-2026:1715-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | qemu-pr-helper | qemu-pr-helper@9.2.4-150700.3.17.1 | SUSE-SU-2026:2385-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | qemu-vmsr-helper | qemu-vmsr-helper@9.2.4-150700.3.17.1 | SUSE-SU-2026:2385-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | shadow | shadow@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | tar | tar@1.34-150000.3.34.1 | SUSE-SU-2026:1177-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | udev | udev@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/backing-image-manager | golang.org/x/net@v0.49.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/backing-image-manager | golang.org/x/net@v0.49.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/backing-image-manager | golang.org/x/net@v0.49.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/backing-image-manager | golang.org/x/net@v0.49.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/backing-image-manager | golang.org/x/net@v0.49.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/backing-image-manager | stdlib@v1.25.8 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/backing-image-manager | stdlib@v1.25.8 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| longhornio/backing-image-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/backing-image-manager | stdlib@v1.25.8 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/csi-attacher:v4.11.0 | false | Harvester v1.8.0 | csi-attacher | golang.org/x/crypto@v0.45.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-attacher:v4.11.0 | false | Harvester v1.8.0 | csi-attacher | golang.org/x/crypto@v0.45.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-attacher:v4.11.0 | false | Harvester v1.8.0 | csi-attacher | golang.org/x/crypto@v0.45.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-attacher:v4.11.0 | false | Harvester v1.8.0 | csi-attacher | golang.org/x/crypto@v0.45.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-attacher:v4.11.0 | false | Harvester v1.8.0 | csi-attacher | golang.org/x/crypto@v0.45.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-attacher:v4.11.0 | false | Harvester v1.8.0 | csi-attacher | golang.org/x/crypto@v0.45.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-attacher:v4.11.0 | false | Harvester v1.8.0 | csi-attacher | golang.org/x/crypto@v0.45.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-attacher:v4.11.0 | false | Harvester v1.8.0 | csi-attacher | golang.org/x/crypto@v0.45.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-attacher:v4.11.0 | false | Harvester v1.8.0 | csi-attacher | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-attacher:v4.11.0 | false | Harvester v1.8.0 | csi-attacher | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-attacher:v4.11.0 | false | Harvester v1.8.0 | csi-attacher | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-attacher:v4.11.0 | false | Harvester v1.8.0 | csi-attacher | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-attacher:v4.11.0 | false | Harvester v1.8.0 | csi-attacher | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-attacher:v4.11.0 | false | Harvester v1.8.0 | csi-attacher | google.golang.org/grpc@v1.72.2 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/csi-attacher:v4.11.0 | false | Harvester v1.8.0 | csi-attacher | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/csi-node-driver-registrar:v2.16.0 | false | Harvester v1.8.0 | csi-node-driver-registrar | golang.org/x/net@v0.49.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-node-driver-registrar:v2.16.0 | false | Harvester v1.8.0 | csi-node-driver-registrar | golang.org/x/net@v0.49.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-node-driver-registrar:v2.16.0 | false | Harvester v1.8.0 | csi-node-driver-registrar | golang.org/x/net@v0.49.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-node-driver-registrar:v2.16.0 | false | Harvester v1.8.0 | csi-node-driver-registrar | golang.org/x/net@v0.49.0 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/csi-node-driver-registrar:v2.16.0 | false | Harvester v1.8.0 | csi-node-driver-registrar | golang.org/x/net@v0.49.0 | CVE-2026-39821 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/csi-node-driver-registrar:v2.16.0 | false | Harvester v1.8.0 | csi-node-driver-registrar | golang.org/x/net@v0.49.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-node-driver-registrar:v2.16.0 | false | Harvester v1.8.0 | csi-node-driver-registrar | golang.org/x/net@v0.49.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-node-driver-registrar:v2.16.0 | false | Harvester v1.8.0 | csi-node-driver-registrar | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-node-driver-registrar:v2.16.0 | false | Harvester v1.8.0 | csi-node-driver-registrar | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/csi-node-driver-registrar:v2.16.0 | false | Harvester v1.8.0 | csi-node-driver-registrar | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-node-driver-registrar:v2.16.0 | false | Harvester v1.8.0 | csi-node-driver-registrar | stdlib@v1.25.7 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/csi-provisioner:v5.3.0-20260225 | false | Harvester v1.8.0 | csi-provisioner | golang.org/x/net@v0.40.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-provisioner:v5.3.0-20260225 | false | Harvester v1.8.0 | csi-provisioner | golang.org/x/net@v0.40.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-provisioner:v5.3.0-20260225 | false | Harvester v1.8.0 | csi-provisioner | golang.org/x/net@v0.40.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-provisioner:v5.3.0-20260225 | false | Harvester v1.8.0 | csi-provisioner | golang.org/x/net@v0.40.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-provisioner:v5.3.0-20260225 | false | Harvester v1.8.0 | csi-provisioner | golang.org/x/net@v0.40.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-provisioner:v5.3.0-20260225 | false | Harvester v1.8.0 | csi-provisioner | google.golang.org/grpc@v1.72.1 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/csi-provisioner:v5.3.0-20260225 | false | Harvester v1.8.0 | csi-provisioner | stdlib@v1.24.13 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-provisioner:v5.3.0-20260225 | false | Harvester v1.8.0 | csi-provisioner | stdlib@v1.24.13 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/csi-provisioner:v5.3.0-20260225 | false | Harvester v1.8.0 | csi-provisioner | stdlib@v1.24.13 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-resizer:v2.1.0 | false | Harvester v1.8.0 | csi-resizer | golang.org/x/crypto@v0.46.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-resizer:v2.1.0 | false | Harvester v1.8.0 | csi-resizer | golang.org/x/crypto@v0.46.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-resizer:v2.1.0 | false | Harvester v1.8.0 | csi-resizer | golang.org/x/crypto@v0.46.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-resizer:v2.1.0 | false | Harvester v1.8.0 | csi-resizer | golang.org/x/crypto@v0.46.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-resizer:v2.1.0 | false | Harvester v1.8.0 | csi-resizer | golang.org/x/crypto@v0.46.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-resizer:v2.1.0 | false | Harvester v1.8.0 | csi-resizer | golang.org/x/crypto@v0.46.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-resizer:v2.1.0 | false | Harvester v1.8.0 | csi-resizer | golang.org/x/crypto@v0.46.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-resizer:v2.1.0 | false | Harvester v1.8.0 | csi-resizer | golang.org/x/crypto@v0.46.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-resizer:v2.1.0 | false | Harvester v1.8.0 | csi-resizer | golang.org/x/net@v0.48.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-resizer:v2.1.0 | false | Harvester v1.8.0 | csi-resizer | golang.org/x/net@v0.48.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-resizer:v2.1.0 | false | Harvester v1.8.0 | csi-resizer | golang.org/x/net@v0.48.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-resizer:v2.1.0 | false | Harvester v1.8.0 | csi-resizer | golang.org/x/net@v0.48.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-resizer:v2.1.0 | false | Harvester v1.8.0 | csi-resizer | golang.org/x/net@v0.48.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-resizer:v2.1.0 | false | Harvester v1.8.0 | csi-resizer | google.golang.org/grpc@v1.78.0 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/csi-resizer:v2.1.0 | false | Harvester v1.8.0 | csi-resizer | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/csi-snapshotter:v8.5.0 | false | Harvester v1.8.0 | csi-snapshotter | go.opentelemetry.io/otel/sdk@v1.40.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-snapshotter:v8.5.0 | false | Harvester v1.8.0 | csi-snapshotter | golang.org/x/crypto@v0.47.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-snapshotter:v8.5.0 | false | Harvester v1.8.0 | csi-snapshotter | golang.org/x/crypto@v0.47.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-snapshotter:v8.5.0 | false | Harvester v1.8.0 | csi-snapshotter | golang.org/x/crypto@v0.47.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-snapshotter:v8.5.0 | false | Harvester v1.8.0 | csi-snapshotter | golang.org/x/crypto@v0.47.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-snapshotter:v8.5.0 | false | Harvester v1.8.0 | csi-snapshotter | golang.org/x/crypto@v0.47.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-snapshotter:v8.5.0 | false | Harvester v1.8.0 | csi-snapshotter | golang.org/x/crypto@v0.47.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-snapshotter:v8.5.0 | false | Harvester v1.8.0 | csi-snapshotter | golang.org/x/crypto@v0.47.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-snapshotter:v8.5.0 | false | Harvester v1.8.0 | csi-snapshotter | golang.org/x/crypto@v0.47.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-snapshotter:v8.5.0 | false | Harvester v1.8.0 | csi-snapshotter | golang.org/x/net@v0.49.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-snapshotter:v8.5.0 | false | Harvester v1.8.0 | csi-snapshotter | golang.org/x/net@v0.49.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-snapshotter:v8.5.0 | false | Harvester v1.8.0 | csi-snapshotter | golang.org/x/net@v0.49.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-snapshotter:v8.5.0 | false | Harvester v1.8.0 | csi-snapshotter | golang.org/x/net@v0.49.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-snapshotter:v8.5.0 | false | Harvester v1.8.0 | csi-snapshotter | golang.org/x/net@v0.49.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| longhornio/csi-snapshotter:v8.5.0 | false | Harvester v1.8.0 | csi-snapshotter | google.golang.org/grpc@v1.78.0 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/csi-snapshotter:v8.5.0 | false | Harvester v1.8.0 | csi-snapshotter | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/livenessprobe:v2.18.0 | false | Harvester v1.8.0 | livenessprobe | golang.org/x/net@v0.49.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| longhornio/livenessprobe:v2.18.0 | false | Harvester v1.8.0 | livenessprobe | golang.org/x/net@v0.49.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| longhornio/livenessprobe:v2.18.0 | false | Harvester v1.8.0 | livenessprobe | golang.org/x/net@v0.49.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| longhornio/livenessprobe:v2.18.0 | false | Harvester v1.8.0 | livenessprobe | golang.org/x/net@v0.49.0 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/livenessprobe:v2.18.0 | false | Harvester v1.8.0 | livenessprobe | golang.org/x/net@v0.49.0 | CVE-2026-39821 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/livenessprobe:v2.18.0 | false | Harvester v1.8.0 | livenessprobe | golang.org/x/net@v0.49.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| longhornio/livenessprobe:v2.18.0 | false | Harvester v1.8.0 | livenessprobe | golang.org/x/net@v0.49.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| longhornio/livenessprobe:v2.18.0 | false | Harvester v1.8.0 | livenessprobe | google.golang.org/grpc@v1.78.0 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/livenessprobe:v2.18.0 | false | Harvester v1.8.0 | livenessprobe | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| longhornio/livenessprobe:v2.18.0 | false | Harvester v1.8.0 | livenessprobe | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/livenessprobe:v2.18.0 | false | Harvester v1.8.0 | livenessprobe | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| longhornio/livenessprobe:v2.18.0 | false | Harvester v1.8.0 | livenessprobe | stdlib@v1.25.7 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | curl | curl@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | login_defs | login_defs@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | shadow | shadow@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | tar | tar@1.34-150000.3.34.1 | SUSE-SU-2026:1177-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl | stdlib@v1.25.8 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl | stdlib@v1.25.8 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl | stdlib@v1.25.8 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl | stdlib@v1.25.8 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl | stdlib@v1.25.8 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl-local | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl-local | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl-local | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl-local | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl-local | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl-local | stdlib@v1.25.8 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl-local | stdlib@v1.25.8 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl-local | stdlib@v1.25.8 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl-local | stdlib@v1.25.8 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-cli:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhornctl-local | stdlib@v1.25.8 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | libexpat1 | libexpat1@2.7.1-150700.3.9.2 | SUSE-SU-2026:1352-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | libnghttp2-14 | libnghttp2-14@1.64.0-150700.1.5 | SUSE-SU-2026:1074-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | libpython3_6m1_0 | libpython3_6m1_0@3.6.15-150300.10.106.1 | SUSE-SU-2026:1090-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | libpython3_6m1_0 | libpython3_6m1_0@3.6.15-150300.10.106.1 | SUSE-SU-2026:1715-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | login_defs | login_defs@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | python3-base | python3-base@3.6.15-150300.10.106.1 | SUSE-SU-2026:1090-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | python3-base | python3-base@3.6.15-150300.10.106.1 | SUSE-SU-2026:1715-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | qemu-vmsr-helper | qemu-vmsr-helper@9.2.4-150700.3.17.1 | SUSE-SU-2026:2385-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | shadow | shadow@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | tar | tar@1.34-150000.3.34.1 | SUSE-SU-2026:1177-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | golang.org/x/net@v0.48.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | golang.org/x/net@v0.48.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | golang.org/x/net@v0.48.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | golang.org/x/net@v0.48.0 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | golang.org/x/net@v0.48.0 | CVE-2026-39821 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | golang.org/x/net@v0.48.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | golang.org/x/net@v0.48.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | google.golang.org/grpc@v1.79.1 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | stdlib@v1.25.8 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | stdlib@v1.25.8 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | stdlib@v1.25.8 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | stdlib@v1.25.8 | CVE-2026-39823 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | stdlib@v1.25.8 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | stdlib@v1.25.8 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | stdlib@v1.25.8 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn | golang.org/x/net@v0.49.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn | golang.org/x/net@v0.49.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn | golang.org/x/net@v0.49.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn | golang.org/x/net@v0.49.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn | golang.org/x/net@v0.49.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn | stdlib@v1.25.8 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn | stdlib@v1.25.8 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn | stdlib@v1.25.8 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn | stdlib@v1.25.8 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | golang.org/x/net@v0.49.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | golang.org/x/net@v0.49.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | golang.org/x/net@v0.49.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | golang.org/x/net@v0.49.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | golang.org/x/net@v0.49.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | stdlib@v1.25.8 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | stdlib@v1.25.8 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | stdlib@v1.25.8 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-engine:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | stdlib@v1.25.8 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | glibc-devel | glibc-devel@2.38-150600.14.43.1 | SUSE-SU-2026:1369-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | glibc-devel | glibc-devel@2.38-150600.14.43.1 | SUSE-SU-2026:2231-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | libexpat1 | libexpat1@2.7.1-150700.3.9.2 | SUSE-SU-2026:1352-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | libldb2 | libldb2@4.21.10+git.449.dcced69e1b5-150700.3.19.1 | SUSE-SU-2026:2076-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | libopenssl-3-devel | libopenssl-3-devel@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | libopenssl1_1 | libopenssl1_1@1.1.1w-150700.11.11.1 | SUSE-SU-2026:1386-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | libpython3_6m1_0 | libpython3_6m1_0@3.6.15-150300.10.106.1 | SUSE-SU-2026:1090-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | libpython3_6m1_0 | libpython3_6m1_0@3.6.15-150300.10.106.1 | SUSE-SU-2026:1715-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | login_defs | login_defs@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | python3-base | python3-base@3.6.15-150300.10.106.1 | SUSE-SU-2026:1090-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | python3-base | python3-base@3.6.15-150300.10.106.1 | SUSE-SU-2026:1715-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | python311-base | python311-base@3.11.14-150600.3.44.1 | SUSE-SU-2026:1349-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | qemu-vmsr-helper | qemu-vmsr-helper@9.2.4-150700.3.17.1 | SUSE-SU-2026:2385-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | shadow | shadow@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | tar | tar@1.34-150000.3.34.1 | SUSE-SU-2026:1177-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/go-spdk-helper | stdlib@v1.25.8 | CVE-2026-27145 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/go-spdk-helper | stdlib@v1.25.8 | CVE-2026-32280 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/go-spdk-helper | stdlib@v1.25.8 | CVE-2026-32281 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/go-spdk-helper | stdlib@v1.25.8 | CVE-2026-32283 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/go-spdk-helper | stdlib@v1.25.8 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/go-spdk-helper | stdlib@v1.25.8 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/go-spdk-helper | stdlib@v1.25.8 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/go-spdk-helper | stdlib@v1.25.8 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/go-spdk-helper | stdlib@v1.25.8 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/go-spdk-helper | stdlib@v1.25.8 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/go-spdk-helper | stdlib@v1.25.8 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | golang.org/x/net@v0.48.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | golang.org/x/net@v0.48.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | golang.org/x/net@v0.48.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | golang.org/x/net@v0.48.0 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | golang.org/x/net@v0.48.0 | CVE-2026-39821 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | golang.org/x/net@v0.48.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | golang.org/x/net@v0.48.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | google.golang.org/grpc@v1.79.1 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | stdlib@v1.25.8 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | stdlib@v1.25.8 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | stdlib@v1.25.8 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | stdlib@v1.25.8 | CVE-2026-39823 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | stdlib@v1.25.8 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | stdlib@v1.25.8 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/grpc_health_probe | stdlib@v1.25.8 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | golang.org/x/net@v0.49.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | golang.org/x/net@v0.49.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | golang.org/x/net@v0.49.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | golang.org/x/net@v0.49.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | golang.org/x/net@v0.49.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | stdlib@v1.25.8 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | stdlib@v1.25.8 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | stdlib@v1.25.8 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-instance-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/bin/longhorn-instance-manager | stdlib@v1.25.8 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | bind-utils | bind-utils@9.20.18-150700.3.15.1 | SUSE-SU-2026:1351-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | libexpat1 | libexpat1@2.7.1-150700.3.9.2 | SUSE-SU-2026:1352-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | libgnutls30 | libgnutls30@3.8.3-150600.4.17.1 | SUSE-SU-2026:2115-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | libnghttp2-14 | libnghttp2-14@1.64.0-150700.1.5 | SUSE-SU-2026:1074-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | libopenssl1_1 | libopenssl1_1@1.1.1w-150700.11.11.1 | SUSE-SU-2026:1386-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | libsystemd0 | libsystemd0@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | login_defs | login_defs@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | python3-base | python3-base@3.6.15-150300.10.106.1 | SUSE-SU-2026:1090-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | python3-base | python3-base@3.6.15-150300.10.106.1 | SUSE-SU-2026:1715-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | shadow | shadow@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | tar | tar@1.34-150000.3.34.1 | SUSE-SU-2026:1177-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/sbin/longhorn-manager | golang.org/x/crypto@v0.47.0 | CVE-2026-39827 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/sbin/longhorn-manager | golang.org/x/crypto@v0.47.0 | CVE-2026-39828 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/sbin/longhorn-manager | golang.org/x/crypto@v0.47.0 | CVE-2026-39829 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/sbin/longhorn-manager | golang.org/x/crypto@v0.47.0 | CVE-2026-39830 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/sbin/longhorn-manager | golang.org/x/crypto@v0.47.0 | CVE-2026-39835 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/sbin/longhorn-manager | golang.org/x/crypto@v0.47.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/sbin/longhorn-manager | golang.org/x/crypto@v0.47.0 | CVE-2026-46595 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/sbin/longhorn-manager | golang.org/x/crypto@v0.47.0 | CVE-2026-46597 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/sbin/longhorn-manager | golang.org/x/net@v0.49.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/sbin/longhorn-manager | golang.org/x/net@v0.49.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/sbin/longhorn-manager | golang.org/x/net@v0.49.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/sbin/longhorn-manager | golang.org/x/net@v0.49.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/sbin/longhorn-manager | golang.org/x/net@v0.49.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/sbin/longhorn-manager | stdlib@v1.25.8 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/sbin/longhorn-manager | stdlib@v1.25.8 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-manager:v1.11.1 | false | Harvester v1.8.0 | usr/local/sbin/longhorn-manager | stdlib@v1.25.8 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | libexpat1 | libexpat1@2.7.1-150700.3.9.2 | SUSE-SU-2026:1352-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | login_defs | login_defs@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | shadow | shadow@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | tar | tar@1.34-150000.3.34.1 | SUSE-SU-2026:1177-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | longhorn-share-manager | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | longhorn-share-manager | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | longhorn-share-manager | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | longhorn-share-manager | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | longhorn-share-manager | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | longhorn-share-manager | stdlib@v1.25.8 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | longhorn-share-manager | stdlib@v1.25.8 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | longhorn-share-manager | stdlib@v1.25.8 | CVE-2026-39823 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | longhorn-share-manager | stdlib@v1.25.8 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/longhorn-share-manager:v1.11.1 | false | Harvester v1.8.0 | longhorn-share-manager | stdlib@v1.25.8 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| longhornio/longhorn-ui:v1.11.1 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-ui:v1.11.1 | false | Harvester v1.8.0 | libexpat1 | libexpat1@2.7.1-150700.3.9.2 | SUSE-SU-2026:1352-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-ui:v1.11.1 | false | Harvester v1.8.0 | login_defs | login_defs@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-ui:v1.11.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-ui:v1.11.1 | false | Harvester v1.8.0 | shadow | shadow@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/longhorn-ui:v1.11.1 | false | Harvester v1.8.0 | tar | tar@1.34-150000.3.34.1 | SUSE-SU-2026:1177-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | login_defs | login_defs@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | shadow | shadow@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | tar | tar@1.34-150000.3.34.1 | SUSE-SU-2026:1177-1 | none | not affected | vulnerable code not in execute path | sles |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/support-bundle-kit | go.opentelemetry.io/otel/sdk@v1.41.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/support-bundle-kit | golang.org/x/crypto@v0.48.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/support-bundle-kit | golang.org/x/crypto@v0.48.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/support-bundle-kit | golang.org/x/crypto@v0.48.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/support-bundle-kit | golang.org/x/crypto@v0.48.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/support-bundle-kit | golang.org/x/crypto@v0.48.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/support-bundle-kit | golang.org/x/crypto@v0.48.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/support-bundle-kit | golang.org/x/crypto@v0.48.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/support-bundle-kit | golang.org/x/crypto@v0.48.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/support-bundle-kit | golang.org/x/net@v0.50.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/support-bundle-kit | golang.org/x/net@v0.50.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/support-bundle-kit | golang.org/x/net@v0.50.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/support-bundle-kit | golang.org/x/net@v0.50.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/support-bundle-kit | golang.org/x/net@v0.50.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/support-bundle-kit | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/yq | golang.org/x/net@v0.50.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/yq | golang.org/x/net@v0.50.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/yq | golang.org/x/net@v0.50.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/yq | golang.org/x/net@v0.50.0 | CVE-2026-39821 | none | not affected | vulnerable code not present | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/yq | golang.org/x/net@v0.50.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/yq | golang.org/x/net@v0.50.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-25679 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-27137 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-32280 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-32281 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-32283 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-33810 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| longhornio/support-bundle-kit:v0.0.81 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | usr/bin/alertmanager | golang.org/x/crypto@v0.31.0 | CVE-2025-22869 | none | not affected | vulnerable code not present | gobinary |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | usr/bin/alertmanager | golang.org/x/crypto@v0.31.0 | CVE-2025-47913 | none | not affected | vulnerable code not present | gobinary |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | usr/bin/alertmanager | golang.org/x/crypto@v0.31.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | usr/bin/alertmanager | golang.org/x/crypto@v0.31.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | usr/bin/alertmanager | golang.org/x/crypto@v0.31.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | usr/bin/alertmanager | golang.org/x/crypto@v0.31.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | usr/bin/alertmanager | golang.org/x/crypto@v0.31.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | usr/bin/alertmanager | golang.org/x/crypto@v0.31.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | usr/bin/alertmanager | golang.org/x/crypto@v0.31.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | usr/bin/alertmanager | golang.org/x/crypto@v0.31.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | usr/bin/alertmanager | golang.org/x/net@v0.33.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | usr/bin/alertmanager | golang.org/x/net@v0.33.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | usr/bin/alertmanager | golang.org/x/net@v0.33.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | usr/bin/alertmanager | golang.org/x/net@v0.33.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | usr/bin/alertmanager | golang.org/x/net@v0.33.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/appco-alertmanager:0.28.1-12.7 | false | Harvester v1.8.0 | usr/bin/alertmanager | golang.org/x/oauth2@v0.24.0 | CVE-2025-22868 | none | not affected | vulnerable code not present | gobinary |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | github.com/buger/jsonparser@v1.1.1 | CVE-2026-32285 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/appco-grafana:12.1.1-2.2 | false | Harvester v1.8.0 | usr/share/grafana/bin/grafana | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/appco-k8s-sidecar:1.30.7-11.3 | false | Harvester v1.8.0 | libexpat1 | libexpat1@2.7.1-150400.3.28.1 | SUSE-SU-2025:03624-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/appco-k8s-sidecar:1.30.7-11.3 | false | Harvester v1.8.0 | libexpat1 | libexpat1@2.7.1-150400.3.28.1 | SUSE-SU-2026:1166-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/appco-k8s-sidecar:1.30.7-11.3 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | usr/bin/kube-state-metrics | go.opentelemetry.io/otel/sdk@v1.33.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/appco-kube-state-metrics:2.17.0-10.7 | false | Harvester v1.8.0 | usr/bin/kube-state-metrics | go.opentelemetry.io/otel/sdk@v1.33.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/appco-node-exporter:1.9.1-11.3 | false | Harvester v1.8.0 | usr/bin/node_exporter | golang.org/x/crypto@v0.36.0 | CVE-2025-47913 | none | not affected | vulnerable code not present | gobinary |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | go.opentelemetry.io/otel/sdk@v1.34.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | go.opentelemetry.io/otel/sdk@v1.34.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.45.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.45.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.45.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.45.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.45.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.45.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.45.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.45.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/cluster-api-controller:v1.12.2 | false | Harvester v1.8.0 | manager | stdlib@v1.24.6 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetagent | golang.org/x/crypto@v0.48.0 | CVE-2026-39827 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetagent | golang.org/x/crypto@v0.48.0 | CVE-2026-39828 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetagent | golang.org/x/crypto@v0.48.0 | CVE-2026-46595 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetagent | golang.org/x/net@v0.50.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetagent | golang.org/x/net@v0.50.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetagent | golang.org/x/net@v0.50.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetagent | golang.org/x/net@v0.50.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetagent | golang.org/x/net@v0.50.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetagent | stdlib@v1.25.8 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetagent | stdlib@v1.25.8 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetagent | stdlib@v1.25.8 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet-agent:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetagent | stdlib@v1.25.8 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | libexpat1 | libexpat1@2.7.1-150700.3.9.2 | SUSE-SU-2026:1352-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | libnghttp2-14 | libnghttp2-14@1.64.0-150700.1.5 | SUSE-SU-2026:1074-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | libudev1 | libudev1@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | login_defs | login_defs@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | openssh-clients | openssh-clients@9.6p1-150600.6.34.1 | SUSE-SU-2026:1876-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | openssh-clients | openssh-clients@9.6p1-150600.6.34.1 | SUSE-SU-2026:2371-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | openssh-common | openssh-common@9.6p1-150600.6.34.1 | SUSE-SU-2026:1876-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | shadow | shadow@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | tar | tar@1.34-150000.3.34.1 | SUSE-SU-2026:1177-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | github.com/moby/spdystream@v0.5.0 | CVE-2026-35469 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | golang.org/x/crypto@v0.48.0 | CVE-2026-39827 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | golang.org/x/crypto@v0.48.0 | CVE-2026-39828 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | golang.org/x/crypto@v0.48.0 | CVE-2026-46595 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | golang.org/x/net@v0.50.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | golang.org/x/net@v0.50.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | golang.org/x/net@v0.50.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | golang.org/x/net@v0.50.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | golang.org/x/net@v0.50.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | stdlib@v1.25.8 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | stdlib@v1.25.8 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | stdlib@v1.25.8 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleet | stdlib@v1.25.8 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | golang.org/x/crypto@v0.48.0 | CVE-2026-39827 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | golang.org/x/crypto@v0.48.0 | CVE-2026-39828 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | golang.org/x/crypto@v0.48.0 | CVE-2026-46595 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | golang.org/x/net@v0.50.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | golang.org/x/net@v0.50.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | golang.org/x/net@v0.50.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | golang.org/x/net@v0.50.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | golang.org/x/net@v0.50.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | stdlib@v1.25.8 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | stdlib@v1.25.8 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | stdlib@v1.25.8 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/fleet:v0.15.0 | false | Harvester v1.8.0 | usr/bin/fleetcontroller | stdlib@v1.25.8 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-addon-resizer:1.8.23-build20260206 | false | Harvester v1.8.0 | pod_nanny | golang.org/x/net@v0.33.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-addon-resizer:1.8.23-build20260206 | false | Harvester v1.8.0 | pod_nanny | golang.org/x/net@v0.33.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-addon-resizer:1.8.23-build20260206 | false | Harvester v1.8.0 | pod_nanny | golang.org/x/net@v0.33.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-addon-resizer:1.8.23-build20260206 | false | Harvester v1.8.0 | pod_nanny | golang.org/x/net@v0.33.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-addon-resizer:1.8.23-build20260206 | false | Harvester v1.8.0 | pod_nanny | golang.org/x/net@v0.33.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-addon-resizer:1.8.23-build20260206 | false | Harvester v1.8.0 | pod_nanny | golang.org/x/oauth2@v0.24.0 | CVE-2025-22868 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-addon-resizer:1.8.23-build20260206 | false | Harvester v1.8.0 | pod_nanny | stdlib@v1.24.13 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-addon-resizer:1.8.23-build20260206 | false | Harvester v1.8.0 | pod_nanny | stdlib@v1.24.13 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-addon-resizer:1.8.23-build20260206 | false | Harvester v1.8.0 | pod_nanny | stdlib@v1.24.13 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-addon-resizer:1.8.23-build20260206 | false | Harvester v1.8.0 | pod_nanny | stdlib@v1.24.13 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-addon-resizer:1.8.23-build20260206 | false | Harvester v1.8.0 | pod_nanny | stdlib@v1.24.13 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cluster-autoscaler:v1.10.3-build20260206 | false | Harvester v1.8.0 | cluster-proportional-autoscaler | golang.org/x/net@v0.36.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cluster-autoscaler:v1.10.3-build20260206 | false | Harvester v1.8.0 | cluster-proportional-autoscaler | golang.org/x/net@v0.36.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cluster-autoscaler:v1.10.3-build20260206 | false | Harvester v1.8.0 | cluster-proportional-autoscaler | golang.org/x/net@v0.36.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cluster-autoscaler:v1.10.3-build20260206 | false | Harvester v1.8.0 | cluster-proportional-autoscaler | golang.org/x/net@v0.36.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cluster-autoscaler:v1.10.3-build20260206 | false | Harvester v1.8.0 | cluster-proportional-autoscaler | golang.org/x/net@v0.36.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cluster-autoscaler:v1.10.3-build20260206 | false | Harvester v1.8.0 | cluster-proportional-autoscaler | golang.org/x/oauth2@v0.23.0 | CVE-2025-22868 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cluster-autoscaler:v1.10.3-build20260206 | false | Harvester v1.8.0 | cluster-proportional-autoscaler | stdlib@v1.24.13 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cluster-autoscaler:v1.10.3-build20260206 | false | Harvester v1.8.0 | cluster-proportional-autoscaler | stdlib@v1.24.13 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cluster-autoscaler:v1.10.3-build20260206 | false | Harvester v1.8.0 | cluster-proportional-autoscaler | stdlib@v1.24.13 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cluster-autoscaler:v1.10.3-build20260206 | false | Harvester v1.8.0 | cluster-proportional-autoscaler | stdlib@v1.24.13 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cluster-autoscaler:v1.10.3-build20260206 | false | Harvester v1.8.0 | cluster-proportional-autoscaler | stdlib@v1.24.13 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bandwidth | stdlib@v1.25.7 | CVE-2026-25679 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bandwidth | stdlib@v1.25.7 | CVE-2026-27145 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bandwidth | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bandwidth | stdlib@v1.25.7 | CVE-2026-32281 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bandwidth | stdlib@v1.25.7 | CVE-2026-32283 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bandwidth | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bandwidth | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bandwidth | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bandwidth | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bandwidth | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bandwidth | stdlib@v1.25.7 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bandwidth | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bandwidth | stdlib@v1.25.7 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bond | stdlib@v1.25.7 | CVE-2026-25679 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bond | stdlib@v1.25.7 | CVE-2026-27145 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bond | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bond | stdlib@v1.25.7 | CVE-2026-32281 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bond | stdlib@v1.25.7 | CVE-2026-32283 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bond | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bond | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bond | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bond | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bond | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bond | stdlib@v1.25.7 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bond | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bond | stdlib@v1.25.7 | CVE-2026-42504 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bridge | stdlib@v1.25.7 | CVE-2026-25679 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bridge | stdlib@v1.25.7 | CVE-2026-27145 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bridge | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bridge | stdlib@v1.25.7 | CVE-2026-32281 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bridge | stdlib@v1.25.7 | CVE-2026-32283 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bridge | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bridge | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bridge | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bridge | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bridge | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bridge | stdlib@v1.25.7 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bridge | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/bridge | stdlib@v1.25.7 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dhcp | golang.org/x/net@v0.43.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dhcp | golang.org/x/net@v0.43.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dhcp | golang.org/x/net@v0.43.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dhcp | golang.org/x/net@v0.43.0 | CVE-2026-33814 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dhcp | golang.org/x/net@v0.43.0 | CVE-2026-39821 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dhcp | golang.org/x/net@v0.43.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dhcp | golang.org/x/net@v0.43.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dhcp | stdlib@v1.25.7 | CVE-2026-25679 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dhcp | stdlib@v1.25.7 | CVE-2026-27145 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dhcp | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dhcp | stdlib@v1.25.7 | CVE-2026-32281 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dhcp | stdlib@v1.25.7 | CVE-2026-32283 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dhcp | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dhcp | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dhcp | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dhcp | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dhcp | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dhcp | stdlib@v1.25.7 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dhcp | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dhcp | stdlib@v1.25.7 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dummy | stdlib@v1.25.7 | CVE-2026-25679 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dummy | stdlib@v1.25.7 | CVE-2026-27145 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dummy | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dummy | stdlib@v1.25.7 | CVE-2026-32281 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dummy | stdlib@v1.25.7 | CVE-2026-32283 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dummy | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dummy | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dummy | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dummy | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dummy | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dummy | stdlib@v1.25.7 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dummy | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/dummy | stdlib@v1.25.7 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/firewall | stdlib@v1.25.7 | CVE-2026-25679 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/firewall | stdlib@v1.25.7 | CVE-2026-27145 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/firewall | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/firewall | stdlib@v1.25.7 | CVE-2026-32281 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/firewall | stdlib@v1.25.7 | CVE-2026-32283 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/firewall | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/firewall | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/firewall | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/firewall | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/firewall | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/firewall | stdlib@v1.25.7 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/firewall | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/firewall | stdlib@v1.25.7 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/flannel | stdlib@v1.25.7 | CVE-2026-25679 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/flannel | stdlib@v1.25.7 | CVE-2026-27145 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/flannel | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/flannel | stdlib@v1.25.7 | CVE-2026-32281 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/flannel | stdlib@v1.25.7 | CVE-2026-32283 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/flannel | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/flannel | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/flannel | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/flannel | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/flannel | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/flannel | stdlib@v1.25.7 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/flannel | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/flannel | stdlib@v1.25.7 | CVE-2026-42504 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/host-device | stdlib@v1.25.7 | CVE-2026-25679 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/host-device | stdlib@v1.25.7 | CVE-2026-27145 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/host-device | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/host-device | stdlib@v1.25.7 | CVE-2026-32281 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/host-device | stdlib@v1.25.7 | CVE-2026-32283 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/host-device | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/host-device | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/host-device | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/host-device | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/host-device | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/host-device | stdlib@v1.25.7 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/host-device | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/host-device | stdlib@v1.25.7 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/host-local | stdlib@v1.25.7 | CVE-2026-25679 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/host-local | stdlib@v1.25.7 | CVE-2026-27145 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/host-local | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/host-local | stdlib@v1.25.7 | CVE-2026-32281 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/host-local | stdlib@v1.25.7 | CVE-2026-32283 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/host-local | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/host-local | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/host-local | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/host-local | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/host-local | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/host-local | stdlib@v1.25.7 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/host-local | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/host-local | stdlib@v1.25.7 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/ipvlan | stdlib@v1.25.7 | CVE-2026-25679 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/ipvlan | stdlib@v1.25.7 | CVE-2026-27145 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/ipvlan | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/ipvlan | stdlib@v1.25.7 | CVE-2026-32281 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/ipvlan | stdlib@v1.25.7 | CVE-2026-32283 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/ipvlan | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/ipvlan | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/ipvlan | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/ipvlan | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/ipvlan | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/ipvlan | stdlib@v1.25.7 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/ipvlan | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/ipvlan | stdlib@v1.25.7 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/loopback | stdlib@v1.25.7 | CVE-2026-25679 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/loopback | stdlib@v1.25.7 | CVE-2026-27145 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/loopback | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/loopback | stdlib@v1.25.7 | CVE-2026-32281 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/loopback | stdlib@v1.25.7 | CVE-2026-32283 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/loopback | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/loopback | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/loopback | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/loopback | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/loopback | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/loopback | stdlib@v1.25.7 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/loopback | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/loopback | stdlib@v1.25.7 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/macvlan | stdlib@v1.25.7 | CVE-2026-25679 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/macvlan | stdlib@v1.25.7 | CVE-2026-27145 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/macvlan | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/macvlan | stdlib@v1.25.7 | CVE-2026-32281 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/macvlan | stdlib@v1.25.7 | CVE-2026-32283 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/macvlan | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/macvlan | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/macvlan | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/macvlan | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/macvlan | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/macvlan | stdlib@v1.25.7 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/macvlan | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/macvlan | stdlib@v1.25.7 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/portmap | stdlib@v1.25.7 | CVE-2026-25679 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/portmap | stdlib@v1.25.7 | CVE-2026-27145 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/portmap | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/portmap | stdlib@v1.25.7 | CVE-2026-32281 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/portmap | stdlib@v1.25.7 | CVE-2026-32283 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/portmap | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/portmap | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/portmap | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/portmap | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/portmap | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/portmap | stdlib@v1.25.7 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/portmap | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/portmap | stdlib@v1.25.7 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/ptp | stdlib@v1.25.7 | CVE-2026-25679 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/ptp | stdlib@v1.25.7 | CVE-2026-27145 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/ptp | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/ptp | stdlib@v1.25.7 | CVE-2026-32281 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/ptp | stdlib@v1.25.7 | CVE-2026-32283 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/ptp | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/ptp | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/ptp | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/ptp | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/ptp | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/ptp | stdlib@v1.25.7 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/ptp | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/ptp | stdlib@v1.25.7 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/sbr | stdlib@v1.25.7 | CVE-2026-25679 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/sbr | stdlib@v1.25.7 | CVE-2026-27145 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/sbr | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/sbr | stdlib@v1.25.7 | CVE-2026-32281 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/sbr | stdlib@v1.25.7 | CVE-2026-32283 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/sbr | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/sbr | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/sbr | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/sbr | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/sbr | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/sbr | stdlib@v1.25.7 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/sbr | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/sbr | stdlib@v1.25.7 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/static | stdlib@v1.25.7 | CVE-2026-25679 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/static | stdlib@v1.25.7 | CVE-2026-27145 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/static | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/static | stdlib@v1.25.7 | CVE-2026-32281 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/static | stdlib@v1.25.7 | CVE-2026-32283 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/static | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/static | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/static | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/static | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/static | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/static | stdlib@v1.25.7 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/static | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/static | stdlib@v1.25.7 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/tap | github.com/opencontainers/selinux@v1.12.0 | CVE-2025-52881 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/tap | stdlib@v1.25.7 | CVE-2026-25679 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/tap | stdlib@v1.25.7 | CVE-2026-27145 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/tap | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/tap | stdlib@v1.25.7 | CVE-2026-32281 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/tap | stdlib@v1.25.7 | CVE-2026-32283 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/tap | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/tap | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/tap | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/tap | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/tap | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/tap | stdlib@v1.25.7 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/tap | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/tap | stdlib@v1.25.7 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/tuning | stdlib@v1.25.7 | CVE-2026-25679 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/tuning | stdlib@v1.25.7 | CVE-2026-27145 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/tuning | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/tuning | stdlib@v1.25.7 | CVE-2026-32281 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/tuning | stdlib@v1.25.7 | CVE-2026-32283 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/tuning | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/tuning | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/tuning | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/tuning | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/tuning | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/tuning | stdlib@v1.25.7 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/tuning | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/tuning | stdlib@v1.25.7 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/vlan | stdlib@v1.25.7 | CVE-2026-25679 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/vlan | stdlib@v1.25.7 | CVE-2026-27145 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/vlan | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/vlan | stdlib@v1.25.7 | CVE-2026-32281 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/vlan | stdlib@v1.25.7 | CVE-2026-32283 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/vlan | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/vlan | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/vlan | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/vlan | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/vlan | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/vlan | stdlib@v1.25.7 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/vlan | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/vlan | stdlib@v1.25.7 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/vrf | stdlib@v1.25.7 | CVE-2026-25679 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/vrf | stdlib@v1.25.7 | CVE-2026-27145 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/vrf | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/vrf | stdlib@v1.25.7 | CVE-2026-32281 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/vrf | stdlib@v1.25.7 | CVE-2026-32283 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/vrf | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/vrf | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/vrf | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/vrf | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/vrf | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/vrf | stdlib@v1.25.7 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/vrf | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cni-plugins:v1.9.0-build20260206 | false | Harvester v1.8.0 | opt/cni/bin/vrf | stdlib@v1.25.7 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | busybox | busybox@1.37.0-150700.18.12.1 | SUSE-SU-2026:2054-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | go.opentelemetry.io/otel/sdk@v1.38.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | go.opentelemetry.io/otel/sdk@v1.38.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | golang.org/x/crypto@v0.47.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | golang.org/x/crypto@v0.47.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | golang.org/x/crypto@v0.47.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | golang.org/x/crypto@v0.47.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | golang.org/x/crypto@v0.47.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | golang.org/x/crypto@v0.47.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | golang.org/x/crypto@v0.47.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | golang.org/x/crypto@v0.47.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | golang.org/x/net@v0.49.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | golang.org/x/net@v0.49.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | golang.org/x/net@v0.49.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | golang.org/x/net@v0.49.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | golang.org/x/net@v0.49.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | stdlib@v1.24.13 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | stdlib@v1.24.13 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | stdlib@v1.24.13 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-coredns:v1.14.1-build20260206 | false | Harvester v1.8.0 | coredns | stdlib@v1.24.13 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | busybox | busybox@1.37.0-150700.18.12.1 | SUSE-SU-2026:2054-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | go.opentelemetry.io/otel/sdk@v1.37.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | go.opentelemetry.io/otel/sdk@v1.37.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | golang.org/x/crypto@v0.43.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | golang.org/x/crypto@v0.43.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | golang.org/x/crypto@v0.43.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | golang.org/x/crypto@v0.43.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | golang.org/x/crypto@v0.43.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | golang.org/x/crypto@v0.43.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | golang.org/x/crypto@v0.43.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | golang.org/x/crypto@v0.43.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | golang.org/x/net@v0.46.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | golang.org/x/net@v0.46.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | golang.org/x/net@v0.46.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | golang.org/x/net@v0.46.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | golang.org/x/net@v0.46.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | stdlib@v1.24.13 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | stdlib@v1.24.13 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | stdlib@v1.24.13 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-dns-node-cache:1.26.7-build20260206 | false | Harvester v1.8.0 | node-cache | stdlib@v1.24.13 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcd | go.opentelemetry.io/otel/sdk@v1.34.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcd | go.opentelemetry.io/otel/sdk@v1.34.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcd | golang.org/x/crypto@v0.42.0 | CVE-2025-47913 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcd | golang.org/x/crypto@v0.42.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcd | golang.org/x/crypto@v0.42.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcd | golang.org/x/crypto@v0.42.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcd | golang.org/x/crypto@v0.42.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcd | golang.org/x/crypto@v0.42.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcd | golang.org/x/crypto@v0.42.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcd | golang.org/x/crypto@v0.42.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcd | golang.org/x/crypto@v0.42.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcd | golang.org/x/net@v0.45.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcd | golang.org/x/net@v0.45.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcd | golang.org/x/net@v0.45.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcd | golang.org/x/net@v0.45.0 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcd | golang.org/x/net@v0.45.0 | CVE-2026-39821 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcd | golang.org/x/net@v0.45.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcd | golang.org/x/net@v0.45.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcd | google.golang.org/grpc@v1.71.1 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcd | stdlib@v1.24.13 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcd | stdlib@v1.24.13 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcd | stdlib@v1.24.13 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcd | stdlib@v1.24.13 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcd | stdlib@v1.24.13 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcdctl | golang.org/x/net@v0.45.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcdctl | golang.org/x/net@v0.45.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcdctl | golang.org/x/net@v0.45.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcdctl | golang.org/x/net@v0.45.0 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcdctl | golang.org/x/net@v0.45.0 | CVE-2026-39821 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcdctl | golang.org/x/net@v0.45.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcdctl | golang.org/x/net@v0.45.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcdctl | google.golang.org/grpc@v1.71.1 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcdctl | stdlib@v1.24.13 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcdctl | stdlib@v1.24.13 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcdctl | stdlib@v1.24.13 | CVE-2026-39823 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcdctl | stdlib@v1.24.13 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcdctl | stdlib@v1.24.13 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/etcdctl | stdlib@v1.24.13 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | busybox | busybox@1.37.0-150700.18.12.1 | SUSE-SU-2026:0759-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | busybox | busybox@1.37.0-150700.18.12.1 | SUSE-SU-2026:2054-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | opt/bin/flanneld | golang.org/x/crypto@v0.45.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | opt/bin/flanneld | golang.org/x/crypto@v0.45.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | opt/bin/flanneld | golang.org/x/crypto@v0.45.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | opt/bin/flanneld | golang.org/x/crypto@v0.45.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | opt/bin/flanneld | golang.org/x/crypto@v0.45.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | opt/bin/flanneld | golang.org/x/crypto@v0.45.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | opt/bin/flanneld | golang.org/x/crypto@v0.45.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | opt/bin/flanneld | golang.org/x/crypto@v0.45.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | opt/bin/flanneld | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | opt/bin/flanneld | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | opt/bin/flanneld | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | opt/bin/flanneld | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | opt/bin/flanneld | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | opt/bin/flanneld | google.golang.org/grpc@v1.71.1 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | opt/bin/flanneld | stdlib@v1.24.13 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | opt/bin/flanneld | stdlib@v1.24.13 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | opt/bin/flanneld | stdlib@v1.24.13 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-flannel:v0.28.1-build20260206 | false | Harvester v1.8.0 | opt/bin/flanneld | stdlib@v1.24.13 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | go.opentelemetry.io/otel/sdk@v1.35.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | go.opentelemetry.io/otel/sdk@v1.35.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | golang.org/x/crypto@v0.38.0 | CVE-2025-47913 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | golang.org/x/crypto@v0.38.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | golang.org/x/crypto@v0.38.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | golang.org/x/crypto@v0.38.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | golang.org/x/crypto@v0.38.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | golang.org/x/crypto@v0.38.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | golang.org/x/crypto@v0.38.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | golang.org/x/crypto@v0.38.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | golang.org/x/crypto@v0.38.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | golang.org/x/net@v0.40.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | golang.org/x/net@v0.40.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | golang.org/x/net@v0.40.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | golang.org/x/net@v0.40.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | golang.org/x/net@v0.40.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | google.golang.org/grpc@v1.72.0 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | stdlib@v1.24.13 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260206 | false | Harvester v1.8.0 | metrics-server | stdlib@v1.24.13 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | login_defs | login_defs@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | shadow | shadow@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | tar | tar@1.34-150000.3.34.1 | SUSE-SU-2026:1177-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-apiserver | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-apiserver | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-apiserver | golang.org/x/crypto@v0.45.0 | CVE-2026-39827 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-apiserver | golang.org/x/crypto@v0.45.0 | CVE-2026-39828 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-apiserver | golang.org/x/crypto@v0.45.0 | CVE-2026-39835 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-apiserver | golang.org/x/crypto@v0.45.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-apiserver | golang.org/x/crypto@v0.45.0 | CVE-2026-46595 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-apiserver | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-apiserver | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-apiserver | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-apiserver | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-apiserver | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-apiserver | google.golang.org/grpc@v1.72.2 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-apiserver | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-apiserver | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-apiserver | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-controller-manager | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-controller-manager | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-controller-manager | golang.org/x/crypto@v0.45.0 | CVE-2026-39827 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-controller-manager | golang.org/x/crypto@v0.45.0 | CVE-2026-39828 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-controller-manager | golang.org/x/crypto@v0.45.0 | CVE-2026-39835 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-controller-manager | golang.org/x/crypto@v0.45.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-controller-manager | golang.org/x/crypto@v0.45.0 | CVE-2026-46595 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-controller-manager | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-controller-manager | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-controller-manager | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-controller-manager | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-controller-manager | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-controller-manager | google.golang.org/grpc@v1.72.2 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-controller-manager | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-controller-manager | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-controller-manager | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-proxy | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-proxy | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-proxy | golang.org/x/crypto@v0.45.0 | CVE-2026-39827 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-proxy | golang.org/x/crypto@v0.45.0 | CVE-2026-39828 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-proxy | golang.org/x/crypto@v0.45.0 | CVE-2026-39835 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-proxy | golang.org/x/crypto@v0.45.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-proxy | golang.org/x/crypto@v0.45.0 | CVE-2026-46595 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-proxy | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-proxy | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-proxy | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-proxy | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-proxy | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-proxy | google.golang.org/grpc@v1.72.2 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-proxy | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-proxy | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-proxy | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-scheduler | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-scheduler | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-scheduler | golang.org/x/crypto@v0.45.0 | CVE-2026-39827 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-scheduler | golang.org/x/crypto@v0.45.0 | CVE-2026-39828 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-scheduler | golang.org/x/crypto@v0.45.0 | CVE-2026-39835 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-scheduler | golang.org/x/crypto@v0.45.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-scheduler | golang.org/x/crypto@v0.45.0 | CVE-2026-46595 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-scheduler | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-scheduler | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-scheduler | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-scheduler | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-scheduler | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-scheduler | google.golang.org/grpc@v1.72.2 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-scheduler | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-scheduler | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kube-scheduler | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubectl | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubectl | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubectl | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubelet | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubelet | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubelet | golang.org/x/crypto@v0.45.0 | CVE-2026-39827 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubelet | golang.org/x/crypto@v0.45.0 | CVE-2026-39828 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubelet | golang.org/x/crypto@v0.45.0 | CVE-2026-39835 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubelet | golang.org/x/crypto@v0.45.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubelet | golang.org/x/crypto@v0.45.0 | CVE-2026-46595 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubelet | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubelet | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubelet | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubelet | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubelet | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubelet | google.golang.org/grpc@v1.72.2 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubelet | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubelet | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.2-rke2r1-build20260227 | false | Harvester v1.8.0 | usr/local/bin/kubelet | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | cert-approver | golang.org/x/net@v0.41.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | cert-approver | golang.org/x/net@v0.41.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | cert-approver | golang.org/x/net@v0.41.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | cert-approver | golang.org/x/net@v0.41.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | cert-approver | golang.org/x/net@v0.41.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | cert-approver | stdlib@v1.24.13 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | cert-approver | stdlib@v1.24.13 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | cert-approver | stdlib@v1.24.13 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | cert-approver | stdlib@v1.24.13 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | install_multus | stdlib@v1.24.13 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | install_multus | stdlib@v1.24.13 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | install_multus | stdlib@v1.24.13 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | install_multus | stdlib@v1.24.13 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | kubeconfig_generator | golang.org/x/net@v0.41.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | kubeconfig_generator | golang.org/x/net@v0.41.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | kubeconfig_generator | golang.org/x/net@v0.41.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | kubeconfig_generator | golang.org/x/net@v0.41.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | kubeconfig_generator | golang.org/x/net@v0.41.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | kubeconfig_generator | google.golang.org/grpc@v1.73.0 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | kubeconfig_generator | stdlib@v1.24.13 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | kubeconfig_generator | stdlib@v1.24.13 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | kubeconfig_generator | stdlib@v1.24.13 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | kubeconfig_generator | stdlib@v1.24.13 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | thin_entrypoint | stdlib@v1.24.13 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | thin_entrypoint | stdlib@v1.24.13 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | thin_entrypoint | stdlib@v1.24.13 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | thin_entrypoint | stdlib@v1.24.13 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | usr/src/multus-cni/bin/multus | golang.org/x/net@v0.41.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | usr/src/multus-cni/bin/multus | golang.org/x/net@v0.41.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | usr/src/multus-cni/bin/multus | golang.org/x/net@v0.41.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | usr/src/multus-cni/bin/multus | golang.org/x/net@v0.41.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | usr/src/multus-cni/bin/multus | golang.org/x/net@v0.41.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | usr/src/multus-cni/bin/multus | google.golang.org/grpc@v1.73.0 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | usr/src/multus-cni/bin/multus | stdlib@v1.24.13 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | usr/src/multus-cni/bin/multus | stdlib@v1.24.13 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | usr/src/multus-cni/bin/multus | stdlib@v1.24.13 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-multus-cni:v4.2.3-build20260206 | false | Harvester v1.8.0 | usr/src/multus-cni/bin/multus | stdlib@v1.24.13 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-snapshot-controller:v8.4.0-build20260205 | false | Harvester v1.8.0 | snapshot-controller | go.opentelemetry.io/otel/sdk@v1.34.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-snapshot-controller:v8.4.0-build20260205 | false | Harvester v1.8.0 | snapshot-controller | go.opentelemetry.io/otel/sdk@v1.34.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-snapshot-controller:v8.4.0-build20260205 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/crypto@v0.37.0 | CVE-2025-47913 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-snapshot-controller:v8.4.0-build20260205 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/crypto@v0.37.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-snapshot-controller:v8.4.0-build20260205 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/crypto@v0.37.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-snapshot-controller:v8.4.0-build20260205 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/crypto@v0.37.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-snapshot-controller:v8.4.0-build20260205 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/crypto@v0.37.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-snapshot-controller:v8.4.0-build20260205 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/crypto@v0.37.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-snapshot-controller:v8.4.0-build20260205 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/crypto@v0.37.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-snapshot-controller:v8.4.0-build20260205 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/crypto@v0.37.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-snapshot-controller:v8.4.0-build20260205 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/crypto@v0.37.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-snapshot-controller:v8.4.0-build20260205 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/net@v0.39.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-snapshot-controller:v8.4.0-build20260205 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/net@v0.39.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-snapshot-controller:v8.4.0-build20260205 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/net@v0.39.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-snapshot-controller:v8.4.0-build20260205 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/net@v0.39.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-snapshot-controller:v8.4.0-build20260205 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/net@v0.39.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-snapshot-controller:v8.4.0-build20260205 | false | Harvester v1.8.0 | snapshot-controller | google.golang.org/grpc@v1.72.1 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-snapshot-controller:v8.4.0-build20260205 | false | Harvester v1.8.0 | snapshot-controller | stdlib@v1.24.13 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-cluster-repo:v1.8.0 | false | Harvester v1.8.0 | libcap2 | libcap2@2.73-160000.2.2 | SUSE-SU-2026:21373-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-cluster-repo:v1.8.0 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-cluster-repo:v1.8.0 | false | Harvester v1.8.0 | libudev1 | libudev1@257.10-160000.1.1 | SUSE-SU-2026:21144-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-cluster-repo:v1.8.0 | false | Harvester v1.8.0 | tar | tar@1.35-160000.2.2 | SUSE-SU-2026:21143-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-cluster-repo:v1.8.0 | false | Harvester v1.8.0 | xz | xz@5.8.1-160000.2.2 | SUSE-SU-2026:21848-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.8.1-160000.2.2 | SUSE-SU-2026:21848-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | usr/bin/eventrouter | github.com/golang-jwt/jwt/v4@v4.2.0 | CVE-2025-30204 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | usr/bin/eventrouter | golang.org/x/crypto@v0.36.0 | CVE-2025-47913 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | usr/bin/eventrouter | golang.org/x/crypto@v0.36.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | usr/bin/eventrouter | golang.org/x/crypto@v0.36.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | usr/bin/eventrouter | golang.org/x/crypto@v0.36.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | usr/bin/eventrouter | golang.org/x/crypto@v0.36.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | usr/bin/eventrouter | golang.org/x/crypto@v0.36.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | usr/bin/eventrouter | golang.org/x/crypto@v0.36.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | usr/bin/eventrouter | golang.org/x/crypto@v0.36.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | usr/bin/eventrouter | golang.org/x/crypto@v0.36.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | usr/bin/eventrouter | golang.org/x/net@v0.38.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | usr/bin/eventrouter | golang.org/x/net@v0.38.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | usr/bin/eventrouter | golang.org/x/net@v0.38.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | usr/bin/eventrouter | golang.org/x/net@v0.38.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | usr/bin/eventrouter | golang.org/x/net@v0.38.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | usr/bin/eventrouter | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | usr/bin/eventrouter | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | usr/bin/eventrouter | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | usr/bin/eventrouter | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-eventrouter:v1.8.0 | false | Harvester v1.8.0 | usr/bin/eventrouter | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.8.1-160000.2.2 | SUSE-SU-2026:21848-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | libudev1 | libudev1@257.10-160000.1.1 | SUSE-SU-2026:21144-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | tar | tar@1.35-160000.2.2 | SUSE-SU-2026:21143-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-kubeovn-operator:v1.15.4 | false | Harvester v1.8.0 | xz | xz@5.8.1-160000.2.2 | SUSE-SU-2026:21848-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | github.com/rancher/rancher@v0.0.0-20250827213702-1daa918b630b | CVE-2019-12274 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | github.com/rancher/rancher@v0.0.0-20250827213702-1daa918b630b | CVE-2021-36775 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | github.com/rancher/rancher@v0.0.0-20250827213702-1daa918b630b | CVE-2025-67601 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | golang.org/x/crypto@v0.40.0 | CVE-2025-47913 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | golang.org/x/crypto@v0.40.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | golang.org/x/crypto@v0.40.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | golang.org/x/crypto@v0.40.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | golang.org/x/crypto@v0.40.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | golang.org/x/crypto@v0.40.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | golang.org/x/crypto@v0.40.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | golang.org/x/crypto@v0.40.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | golang.org/x/crypto@v0.40.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | golang.org/x/net@v0.42.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | golang.org/x/net@v0.42.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | golang.org/x/net@v0.42.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | golang.org/x/net@v0.42.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | golang.org/x/net@v0.42.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-load-balancer-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer-webhook | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-load-balancer:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer | golang.org/x/net@v0.42.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-load-balancer:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer | golang.org/x/net@v0.42.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-load-balancer:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer | golang.org/x/net@v0.42.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-load-balancer:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer | golang.org/x/net@v0.42.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-load-balancer:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer | golang.org/x/net@v0.42.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-load-balancer:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-load-balancer:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-load-balancer:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-load-balancer:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-load-balancer:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-load-balancer | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-network-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-controller | golang.org/x/net@v0.38.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-network-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-controller | golang.org/x/net@v0.38.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-network-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-controller | golang.org/x/net@v0.38.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-network-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-controller | golang.org/x/net@v0.38.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-network-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-controller | golang.org/x/net@v0.38.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-network-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-controller | stdlib@v1.25.0 | CVE-2025-61726 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-network-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-controller | stdlib@v1.25.0 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-network-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-controller | stdlib@v1.25.0 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-network-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-controller | stdlib@v1.25.0 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-network-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-controller | stdlib@v1.25.0 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-network-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-controller | stdlib@v1.25.0 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-network-helper:v1.8.0 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-network-helper:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-helper | golang.org/x/net@v0.38.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-network-helper:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-helper | golang.org/x/net@v0.38.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-network-helper:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-helper | golang.org/x/net@v0.38.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-network-helper:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-helper | golang.org/x/net@v0.38.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-network-helper:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-helper | golang.org/x/net@v0.38.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-network-helper:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-helper | stdlib@v1.25.0 | CVE-2025-61726 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-network-helper:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-helper | stdlib@v1.25.0 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-network-helper:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-helper | stdlib@v1.25.0 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-network-helper:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-helper | stdlib@v1.25.0 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-network-helper:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-helper | stdlib@v1.25.0 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-network-helper:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-helper | stdlib@v1.25.0 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | golang.org/x/crypto@v0.36.0 | CVE-2025-47913 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | golang.org/x/crypto@v0.36.0 | CVE-2026-39827 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | golang.org/x/crypto@v0.36.0 | CVE-2026-39828 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | golang.org/x/crypto@v0.36.0 | CVE-2026-39829 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | golang.org/x/crypto@v0.36.0 | CVE-2026-39830 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | golang.org/x/crypto@v0.36.0 | CVE-2026-39835 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | golang.org/x/crypto@v0.36.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | golang.org/x/crypto@v0.36.0 | CVE-2026-46595 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | golang.org/x/crypto@v0.36.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | golang.org/x/net@v0.38.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | golang.org/x/net@v0.38.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | golang.org/x/net@v0.38.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | golang.org/x/net@v0.38.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | golang.org/x/net@v0.38.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | stdlib@v1.25.0 | CVE-2025-61726 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | stdlib@v1.25.0 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | stdlib@v1.25.0 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | stdlib@v1.25.0 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | stdlib@v1.25.0 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-network-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-network-webhook | stdlib@v1.25.0 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.8.1-160000.2.2 | SUSE-SU-2026:21848-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | tar | tar@1.35-160000.2.2 | SUSE-SU-2026:21143-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | xz | xz@5.8.1-160000.2.2 | SUSE-SU-2026:21848-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/networkfs-manager | golang.org/x/net@v0.49.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/networkfs-manager | golang.org/x/net@v0.49.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/networkfs-manager | golang.org/x/net@v0.49.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/networkfs-manager | golang.org/x/net@v0.49.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/networkfs-manager | golang.org/x/net@v0.49.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/networkfs-manager | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/networkfs-manager | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/networkfs-manager | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/networkfs-manager | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-networkfs-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/networkfs-manager | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | libcap2 | libcap2@2.73-160000.2.2 | SUSE-SU-2026:21373-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | libudev1 | libudev1@257.10-160000.1.1 | SUSE-SU-2026:21144-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | tar | tar@1.35-160000.2.2 | SUSE-SU-2026:21143-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | xz | xz@5.8.1-160000.2.2 | SUSE-SU-2026:21848-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager-webhook | github.com/harvester/harvester@v1.5.1 | CVE-2025-71261 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager-webhook | golang.org/x/crypto@v0.47.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager-webhook | golang.org/x/crypto@v0.47.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager-webhook | golang.org/x/crypto@v0.47.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager-webhook | golang.org/x/crypto@v0.47.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager-webhook | golang.org/x/crypto@v0.47.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager-webhook | golang.org/x/crypto@v0.47.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager-webhook | golang.org/x/crypto@v0.47.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager-webhook | golang.org/x/crypto@v0.47.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager-webhook | golang.org/x/net@v0.49.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager-webhook | golang.org/x/net@v0.49.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager-webhook | golang.org/x/net@v0.49.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager-webhook | golang.org/x/net@v0.49.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager-webhook | golang.org/x/net@v0.49.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager-webhook | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager-webhook | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager-webhook | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager-webhook | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-disk-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager-webhook | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | glibc-locale-base | glibc-locale-base@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | tar | tar@1.35-160000.2.2 | SUSE-SU-2026:21143-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager | github.com/harvester/harvester@v1.5.1 | CVE-2025-71261 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager | golang.org/x/net@v0.49.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager | golang.org/x/net@v0.49.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager | golang.org/x/net@v0.49.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager | golang.org/x/net@v0.49.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager | golang.org/x/net@v0.49.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-disk-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/node-disk-manager | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | tar | tar@1.35-160000.2.2 | SUSE-SU-2026:21143-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager-webhook | golang.org/x/crypto@v0.36.0 | CVE-2025-47913 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager-webhook | golang.org/x/crypto@v0.36.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager-webhook | golang.org/x/crypto@v0.36.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager-webhook | golang.org/x/crypto@v0.36.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager-webhook | golang.org/x/crypto@v0.36.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager-webhook | golang.org/x/crypto@v0.36.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager-webhook | golang.org/x/crypto@v0.36.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager-webhook | golang.org/x/crypto@v0.36.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager-webhook | golang.org/x/crypto@v0.36.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager-webhook | golang.org/x/net@v0.38.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager-webhook | golang.org/x/net@v0.38.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager-webhook | golang.org/x/net@v0.38.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager-webhook | golang.org/x/net@v0.38.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager-webhook | golang.org/x/net@v0.38.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager-webhook | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager-webhook | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager-webhook | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-manager-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager-webhook | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | tar | tar@1.35-160000.2.2 | SUSE-SU-2026:21143-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager | golang.org/x/net@v0.38.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager | golang.org/x/net@v0.38.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager | golang.org/x/net@v0.38.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager | golang.org/x/net@v0.38.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager | golang.org/x/net@v0.38.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-node-manager:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-node-manager | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.8.1-160000.2.2 | SUSE-SU-2026:21848-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | tar | tar@1.35-160000.2.2 | SUSE-SU-2026:21143-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | xz | xz@5.8.1-160000.2.2 | SUSE-SU-2026:21848-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | usr/bin/pcidevices | github.com/harvester/harvester@v0.0.2-0.20250725061328-e679a719d15d | CVE-2025-71261 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | usr/bin/pcidevices | golang.org/x/crypto@v0.38.0 | CVE-2025-47913 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | usr/bin/pcidevices | golang.org/x/crypto@v0.38.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | usr/bin/pcidevices | golang.org/x/crypto@v0.38.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | usr/bin/pcidevices | golang.org/x/crypto@v0.38.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | usr/bin/pcidevices | golang.org/x/crypto@v0.38.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | usr/bin/pcidevices | golang.org/x/crypto@v0.38.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | usr/bin/pcidevices | golang.org/x/crypto@v0.38.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | usr/bin/pcidevices | golang.org/x/crypto@v0.38.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | usr/bin/pcidevices | golang.org/x/crypto@v0.38.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | usr/bin/pcidevices | golang.org/x/net@v0.23.0 | CVE-2024-45338 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | usr/bin/pcidevices | golang.org/x/net@v0.23.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | usr/bin/pcidevices | golang.org/x/net@v0.23.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | usr/bin/pcidevices | golang.org/x/net@v0.23.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | usr/bin/pcidevices | golang.org/x/net@v0.23.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | usr/bin/pcidevices | golang.org/x/net@v0.23.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | usr/bin/pcidevices | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | usr/bin/pcidevices | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | usr/bin/pcidevices | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-pcidevices:v1.8.0 | false | Harvester v1.8.0 | usr/bin/pcidevices | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | gpg2 | gpg2@2.4.4-150600.3.9.1 | SUSE-SU-2026:0215-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | gpg2 | gpg2@2.4.4-150600.3.9.1 | SUSE-SU-2026:0434-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | libglib-2_0-0 | libglib-2_0-0@2.78.6-150600.4.22.1 | SUSE-SU-2026:0018-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | libglib-2_0-0 | libglib-2_0-0@2.78.6-150600.4.22.1 | SUSE-SU-2026:0373-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | libnghttp2-14 | libnghttp2-14@1.40.0-150600.23.2 | SUSE-SU-2026:1350-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | tar | tar@1.34-150000.3.34.1 | SUSE-SU-2026:1177-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | bin/manager | golang.org/x/crypto@v0.44.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | bin/manager | golang.org/x/crypto@v0.44.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | bin/manager | golang.org/x/crypto@v0.44.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | bin/manager | golang.org/x/crypto@v0.44.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | bin/manager | golang.org/x/crypto@v0.44.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | bin/manager | golang.org/x/crypto@v0.44.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | bin/manager | golang.org/x/crypto@v0.44.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | bin/manager | golang.org/x/crypto@v0.44.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | bin/manager | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | bin/manager | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | bin/manager | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | bin/manager | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | bin/manager | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | bin/manager | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | bin/manager | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | bin/manager | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | bin/manager | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | bin/manager | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-seeder:v1.8.0 | false | Harvester v1.8.0 | bin/manager | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | tar | tar@1.35-160000.2.2 | SUSE-SU-2026:21143-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/kubectl | golang.org/x/net@v0.38.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/kubectl | golang.org/x/net@v0.38.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/kubectl | golang.org/x/net@v0.38.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/kubectl | golang.org/x/net@v0.38.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/kubectl | golang.org/x/net@v0.38.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.24.11 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.24.11 | CVE-2026-39823 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | github.com/docker/cli@v27.1.1+incompatible | CVE-2025-15558 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | golang.org/x/crypto@v0.36.0 | CVE-2025-47913 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | golang.org/x/crypto@v0.36.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | golang.org/x/crypto@v0.36.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | golang.org/x/crypto@v0.36.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | golang.org/x/crypto@v0.36.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | golang.org/x/crypto@v0.36.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | golang.org/x/crypto@v0.36.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | golang.org/x/crypto@v0.36.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | golang.org/x/crypto@v0.36.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | golang.org/x/net@v0.38.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | golang.org/x/net@v0.38.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | golang.org/x/net@v0.38.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | golang.org/x/net@v0.38.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | golang.org/x/net@v0.38.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | google.golang.org/grpc@v1.68.1 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | stdlib@v1.24.2 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | stdlib@v1.24.2 | CVE-2026-39820 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | stdlib@v1.24.2 | CVE-2026-39823 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | stdlib@v1.24.2 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | stdlib@v1.24.2 | CVE-2026-42499 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/wharfie | stdlib@v1.24.2 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/yq | golang.org/x/net@v0.50.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/yq | golang.org/x/net@v0.50.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/yq | golang.org/x/net@v0.50.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/yq | golang.org/x/net@v0.50.0 | CVE-2026-39821 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/yq | golang.org/x/net@v0.50.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/yq | golang.org/x/net@v0.50.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-25679 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-27137 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-32280 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-32281 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-32283 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-33810 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/bin/yq | stdlib@v1.26.0 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | github.com/containerd/containerd@v1.7.12 | CVE-2024-25621 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | github.com/distribution/distribution@v2.8.1+incompatible | CVE-2026-35172 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | github.com/docker/cli@v23.0.4+incompatible | CVE-2025-15558 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | github.com/docker/docker@v23.0.8+incompatible | CVE-2024-41110 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | github.com/docker/docker@v23.0.8+incompatible | CVE-2026-34040 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | github.com/docker/docker@v23.0.8+incompatible | CVE-2026-41567 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | github.com/docker/docker@v23.0.8+incompatible | CVE-2026-42306 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | github.com/go-git/go-billy/v5@v5.5.0 | CVE-2026-44973 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | github.com/go-git/go-git/v5@v5.11.0 | CVE-2025-21613 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | github.com/go-git/go-git/v5@v5.11.0 | CVE-2025-21614 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | github.com/go-git/go-git/v5@v5.11.0 | CVE-2026-45022 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | github.com/moby/moby@v25.0.1+incompatible | CVE-2024-36623 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | github.com/moby/moby@v25.0.1+incompatible | CVE-2026-34040 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | github.com/moby/moby@v25.0.1+incompatible | CVE-2026-41567 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | github.com/moby/moby@v25.0.1+incompatible | CVE-2026-42306 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | golang.org/x/crypto@v0.18.0 | CVE-2024-45337 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | golang.org/x/crypto@v0.18.0 | CVE-2025-22869 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | stdlib@v1.25.9 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | stdlib@v1.25.9 | CVE-2026-39820 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/elemental | stdlib@v1.25.9 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/harvester-installer | github.com/docker/cli@v27.1.1+incompatible | CVE-2025-15558 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/harvester-installer | golang.org/x/crypto@v0.31.0 | CVE-2025-22869 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/harvester-installer | golang.org/x/crypto@v0.31.0 | CVE-2025-47913 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/harvester-installer | golang.org/x/crypto@v0.31.0 | CVE-2026-39827 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/harvester-installer | golang.org/x/crypto@v0.31.0 | CVE-2026-39828 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/harvester-installer | golang.org/x/crypto@v0.31.0 | CVE-2026-39830 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/harvester-installer | golang.org/x/crypto@v0.31.0 | CVE-2026-39835 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/harvester-installer | golang.org/x/crypto@v0.31.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/harvester-installer | golang.org/x/crypto@v0.31.0 | CVE-2026-46595 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/harvester-installer | golang.org/x/crypto@v0.31.0 | CVE-2026-46597 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/harvester-installer | golang.org/x/net@v0.33.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/harvester-installer | golang.org/x/net@v0.33.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/harvester-installer | golang.org/x/net@v0.33.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/harvester-installer | golang.org/x/net@v0.33.0 | CVE-2026-33814 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/harvester-installer | golang.org/x/net@v0.33.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/harvester-installer | golang.org/x/net@v0.33.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/harvester-installer | stdlib@v1.25.9 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/harvester-installer | stdlib@v1.25.9 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/harvester-installer | stdlib@v1.25.9 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/harvester-installer | stdlib@v1.25.9 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/harvester-installer | stdlib@v1.25.9 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/harvester-installer | stdlib@v1.25.9 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/harvester-installer | stdlib@v1.25.9 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/upgrade-helper | golang.org/x/crypto@v0.47.0 | CVE-2026-39827 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/upgrade-helper | golang.org/x/crypto@v0.47.0 | CVE-2026-39828 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/upgrade-helper | golang.org/x/crypto@v0.47.0 | CVE-2026-39830 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/upgrade-helper | golang.org/x/crypto@v0.47.0 | CVE-2026-39835 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/upgrade-helper | golang.org/x/crypto@v0.47.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/upgrade-helper | golang.org/x/crypto@v0.47.0 | CVE-2026-46595 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/upgrade-helper | golang.org/x/crypto@v0.47.0 | CVE-2026-46597 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/upgrade-helper | golang.org/x/net@v0.49.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/upgrade-helper | golang.org/x/net@v0.49.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/upgrade-helper | golang.org/x/net@v0.49.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/upgrade-helper | golang.org/x/net@v0.49.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/upgrade-helper | golang.org/x/net@v0.49.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-upgrade:v1.8.0 | false | Harvester v1.8.0 | usr/local/bin/upgrade-helper | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.8.1-160000.2.2 | SUSE-SU-2026:21848-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | qemu-pr-helper | qemu-pr-helper@10.0.8-160000.1.1 | SUSE-SU-2026:21354-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | qemu-vmsr-helper | qemu-vmsr-helper@10.0.8-160000.1.1 | SUSE-SU-2026:21354-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | tar | tar@1.35-160000.2.2 | SUSE-SU-2026:21143-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/vm-import-controller | github.com/harvester/harvester@v1.8.0-dev-20260301.0.20260309085342-92352be5ca39 | CVE-2025-71261 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/vm-import-controller | golang.org/x/crypto@v0.48.0 | CVE-2026-39827 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/vm-import-controller | golang.org/x/crypto@v0.48.0 | CVE-2026-39828 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/vm-import-controller | golang.org/x/crypto@v0.48.0 | CVE-2026-39829 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/vm-import-controller | golang.org/x/crypto@v0.48.0 | CVE-2026-39830 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/vm-import-controller | golang.org/x/crypto@v0.48.0 | CVE-2026-39835 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/vm-import-controller | golang.org/x/crypto@v0.48.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/vm-import-controller | golang.org/x/crypto@v0.48.0 | CVE-2026-46595 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/vm-import-controller | golang.org/x/crypto@v0.48.0 | CVE-2026-46597 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/vm-import-controller | golang.org/x/net@v0.49.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/vm-import-controller | golang.org/x/net@v0.49.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/vm-import-controller | golang.org/x/net@v0.49.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/vm-import-controller | golang.org/x/net@v0.49.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/vm-import-controller | golang.org/x/net@v0.49.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/vm-import-controller | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/vm-import-controller | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/vm-import-controller | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/vm-import-controller | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-vm-import-controller:v1.8.0 | false | Harvester v1.8.0 | usr/bin/vm-import-controller | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.8.1-160000.2.2 | SUSE-SU-2026:21848-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | libudev1 | libudev1@257.10-160000.1.1 | SUSE-SU-2026:21144-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | tar | tar@1.35-160000.2.2 | SUSE-SU-2026:21143-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | xz | xz@5.8.1-160000.2.2 | SUSE-SU-2026:21848-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | github.com/docker/cli@v25.0.3+incompatible | CVE-2025-15558 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | github.com/docker/docker@v25.0.6+incompatible | CVE-2026-34040 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | github.com/docker/docker@v25.0.6+incompatible | CVE-2026-41567 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | github.com/docker/docker@v25.0.6+incompatible | CVE-2026-42306 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | github.com/moby/spdystream@v0.5.0 | CVE-2026-35469 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | github.com/rancher/rancher@v0.0.0-20250828140533-07a90f09a491 | CVE-2019-12274 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | github.com/rancher/rancher@v0.0.0-20250828140533-07a90f09a491 | CVE-2021-36775 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | github.com/rancher/rancher@v0.0.0-20250828140533-07a90f09a491 | CVE-2025-67601 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | go.opentelemetry.io/otel/sdk@v1.37.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | go.opentelemetry.io/otel/sdk@v1.37.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | golang.org/x/crypto@v0.47.0 | CVE-2026-39827 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | golang.org/x/crypto@v0.47.0 | CVE-2026-39828 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | golang.org/x/crypto@v0.47.0 | CVE-2026-39830 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | golang.org/x/crypto@v0.47.0 | CVE-2026-39835 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | golang.org/x/crypto@v0.47.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | golang.org/x/crypto@v0.47.0 | CVE-2026-46595 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | golang.org/x/crypto@v0.47.0 | CVE-2026-46597 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | golang.org/x/net@v0.49.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | golang.org/x/net@v0.49.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | golang.org/x/net@v0.49.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | golang.org/x/net@v0.49.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | golang.org/x/net@v0.49.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | google.golang.org/grpc@v1.75.1 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester-webhook:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester-webhook | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | github.com/docker/cli@v25.0.3+incompatible | CVE-2025-15558 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | github.com/docker/docker@v25.0.6+incompatible | CVE-2026-34040 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | github.com/docker/docker@v25.0.6+incompatible | CVE-2026-41567 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | github.com/docker/docker@v25.0.6+incompatible | CVE-2026-42306 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | github.com/moby/spdystream@v0.5.0 | CVE-2026-35469 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | github.com/rancher/rancher@v0.0.0-20250828140533-07a90f09a491 | CVE-2019-12274 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | github.com/rancher/rancher@v0.0.0-20250828140533-07a90f09a491 | CVE-2021-36775 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | github.com/rancher/rancher@v0.0.0-20250828140533-07a90f09a491 | CVE-2025-67601 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | go.opentelemetry.io/otel/sdk@v1.37.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | go.opentelemetry.io/otel/sdk@v1.37.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | golang.org/x/crypto@v0.47.0 | CVE-2026-39827 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | golang.org/x/crypto@v0.47.0 | CVE-2026-39828 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | golang.org/x/crypto@v0.47.0 | CVE-2026-39830 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | golang.org/x/crypto@v0.47.0 | CVE-2026-39835 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | golang.org/x/crypto@v0.47.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | golang.org/x/crypto@v0.47.0 | CVE-2026-46595 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | golang.org/x/crypto@v0.47.0 | CVE-2026-46597 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | golang.org/x/net@v0.49.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | golang.org/x/net@v0.49.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | golang.org/x/net@v0.49.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | golang.org/x/net@v0.49.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | golang.org/x/net@v0.49.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | google.golang.org/grpc@v1.75.1 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/harvester:v1.8.0 | false | Harvester v1.8.0 | usr/bin/harvester | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.5-r0 | CVE-2026-31789 | none | not affected | vulnerable code not in execute path | alpine |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.5-r0 | CVE-2026-28387 | none | not affected | vulnerable code not in execute path | alpine |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.5-r0 | CVE-2026-28388 | none | not affected | vulnerable code not in execute path | alpine |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.5-r0 | CVE-2026-28389 | none | not affected | vulnerable code not in execute path | alpine |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.5-r0 | CVE-2026-28390 | none | not affected | vulnerable code not in execute path | alpine |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | libssl3 | libssl3@3.5.5-r0 | CVE-2026-31789 | none | not affected | vulnerable code not in execute path | alpine |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | libssl3 | libssl3@3.5.5-r0 | CVE-2026-28387 | none | not affected | vulnerable code not in execute path | alpine |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | libssl3 | libssl3@3.5.5-r0 | CVE-2026-28388 | none | not affected | vulnerable code not in execute path | alpine |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | libssl3 | libssl3@3.5.5-r0 | CVE-2026-28389 | none | not affected | vulnerable code not in execute path | alpine |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | libssl3 | libssl3@3.5.5-r0 | CVE-2026-28390 | none | not affected | vulnerable code not in execute path | alpine |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | zlib | zlib@1.3.1-r2 | CVE-2026-22184 | none | not affected | vulnerable code not present | alpine |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | github.com/moby/spdystream@v0.5.0 | CVE-2026-35469 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | golang.org/x/crypto@v0.45.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | golang.org/x/crypto@v0.45.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | golang.org/x/crypto@v0.45.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | golang.org/x/crypto@v0.45.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | golang.org/x/crypto@v0.45.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | golang.org/x/crypto@v0.45.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | golang.org/x/crypto@v0.45.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | golang.org/x/crypto@v0.45.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | google.golang.org/grpc@v1.72.1 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | google.golang.org/grpc@v1.72.1 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | usr/bin/helm | github.com/moby/spdystream@v0.5.0 | CVE-2026-35469 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | usr/bin/helm | golang.org/x/crypto@v0.45.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | usr/bin/helm | golang.org/x/crypto@v0.45.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | usr/bin/helm | golang.org/x/crypto@v0.45.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | usr/bin/helm | golang.org/x/crypto@v0.45.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | usr/bin/helm | golang.org/x/crypto@v0.45.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | usr/bin/helm | golang.org/x/crypto@v0.45.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | usr/bin/helm | golang.org/x/crypto@v0.45.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | usr/bin/helm | golang.org/x/crypto@v0.45.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | usr/bin/helm | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | usr/bin/helm | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | usr/bin/helm | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | usr/bin/helm | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | usr/bin/helm | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | usr/bin/helm | google.golang.org/grpc@v1.72.1 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | usr/bin/helm | stdlib@v1.24.11 | CVE-2025-68121 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | usr/bin/helm | stdlib@v1.24.11 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | usr/bin/helm | stdlib@v1.24.11 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | usr/bin/helm | stdlib@v1.24.11 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260210 | false | Harvester v1.8.0 | usr/bin/helm | stdlib@v1.24.11 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/klipper-lb:v0.4.14 | false | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.5-r0 | CVE-2026-31789 | none | not affected | vulnerable code not in execute path | alpine |
| rancher/klipper-lb:v0.4.14 | false | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.5-r0 | CVE-2026-28387 | none | not affected | vulnerable code not in execute path | alpine |
| rancher/klipper-lb:v0.4.14 | false | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.5-r0 | CVE-2026-28388 | none | not affected | vulnerable code not in execute path | alpine |
| rancher/klipper-lb:v0.4.14 | false | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.5-r0 | CVE-2026-28389 | none | not affected | vulnerable code not in execute path | alpine |
| rancher/klipper-lb:v0.4.14 | false | Harvester v1.8.0 | libcrypto3 | libcrypto3@3.5.5-r0 | CVE-2026-28390 | none | not affected | vulnerable code not in execute path | alpine |
| rancher/klipper-lb:v0.4.14 | false | Harvester v1.8.0 | libssl3 | libssl3@3.5.5-r0 | CVE-2026-31789 | none | not affected | vulnerable code not in execute path | alpine |
| rancher/klipper-lb:v0.4.14 | false | Harvester v1.8.0 | libssl3 | libssl3@3.5.5-r0 | CVE-2026-28387 | none | not affected | vulnerable code not in execute path | alpine |
| rancher/klipper-lb:v0.4.14 | false | Harvester v1.8.0 | libssl3 | libssl3@3.5.5-r0 | CVE-2026-28388 | none | not affected | vulnerable code not in execute path | alpine |
| rancher/klipper-lb:v0.4.14 | false | Harvester v1.8.0 | libssl3 | libssl3@3.5.5-r0 | CVE-2026-28389 | none | not affected | vulnerable code not in execute path | alpine |
| rancher/klipper-lb:v0.4.14 | false | Harvester v1.8.0 | libssl3 | libssl3@3.5.5-r0 | CVE-2026-28390 | none | not affected | vulnerable code not in execute path | alpine |
| rancher/klipper-lb:v0.4.14 | false | Harvester v1.8.0 | zlib | zlib@1.3.1-r2 | CVE-2026-22184 | none | not affected | vulnerable code not present | alpine |
| rancher/kubectl:v1.35.1 | false | Harvester v1.8.0 | bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kubectl:v1.35.1 | false | Harvester v1.8.0 | bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kubectl:v1.35.1 | false | Harvester v1.8.0 | bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kubectl:v1.35.1 | false | Harvester v1.8.0 | bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kubectl:v1.35.1 | false | Harvester v1.8.0 | bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kubectl:v1.35.1 | false | Harvester v1.8.0 | bin/kubectl | stdlib@v1.25.6 | CVE-2026-32280 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kubectl:v1.35.1 | false | Harvester v1.8.0 | bin/kubectl | stdlib@v1.25.6 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | bin/kuberlr | golang.org/x/net@v0.38.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | bin/kuberlr | golang.org/x/net@v0.38.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | bin/kuberlr | golang.org/x/net@v0.38.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | bin/kuberlr | golang.org/x/net@v0.38.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | bin/kuberlr | golang.org/x/net@v0.38.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | bin/kuberlr | stdlib@v1.24.4 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | bin/kuberlr | stdlib@v1.24.4 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | bin/kuberlr | stdlib@v1.24.4 | CVE-2026-39823 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | bin/kuberlr | stdlib@v1.24.4 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | bin/kuberlr | stdlib@v1.24.4 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.33.9 | golang.org/x/net@v0.38.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.33.9 | golang.org/x/net@v0.38.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.33.9 | golang.org/x/net@v0.38.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.33.9 | golang.org/x/net@v0.38.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.33.9 | golang.org/x/net@v0.38.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.33.9 | stdlib@v1.24.13 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.33.9 | stdlib@v1.24.13 | CVE-2026-39823 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.34.5 | golang.org/x/net@v0.38.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.34.5 | golang.org/x/net@v0.38.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.34.5 | golang.org/x/net@v0.38.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.34.5 | golang.org/x/net@v0.38.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.34.5 | golang.org/x/net@v0.38.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.34.5 | stdlib@v1.24.13 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.34.5 | stdlib@v1.24.13 | CVE-2026-39823 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.35.2 | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.35.2 | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.35.2 | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.35.2 | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.35.2 | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.35.2 | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.35.2 | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/kuberlr-kubectl:v7.0.3 | false | Harvester v1.8.0 | usr/bin/kubectl1.35.2 | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-kube-logging-logging-operator:4.10.0 | true | Harvester v1.8.0 | manager | golang.org/x/net@v0.29.0 | CVE-2024-45338 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-kube-logging-logging-operator:4.10.0 | true | Harvester v1.8.0 | manager | golang.org/x/net@v0.29.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-kube-logging-logging-operator:4.10.0 | true | Harvester v1.8.0 | manager | golang.org/x/net@v0.29.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-kube-logging-logging-operator:4.10.0 | true | Harvester v1.8.0 | manager | golang.org/x/net@v0.29.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-kube-logging-logging-operator:4.10.0 | true | Harvester v1.8.0 | manager | golang.org/x/net@v0.29.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-kube-logging-logging-operator:4.10.0 | true | Harvester v1.8.0 | manager | golang.org/x/net@v0.29.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-kube-logging-logging-operator:4.10.0 | true | Harvester v1.8.0 | manager | golang.org/x/oauth2@v0.21.0 | CVE-2025-22868 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-kube-logging-logging-operator:4.10.0 | true | Harvester v1.8.0 | manager | stdlib@v1.23.1 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-kube-logging-logging-operator:4.10.0 | true | Harvester v1.8.0 | manager | stdlib@v1.23.1 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-kube-logging-logging-operator:4.10.0 | true | Harvester v1.8.0 | manager | stdlib@v1.23.1 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-kube-logging-logging-operator:4.10.0 | true | Harvester v1.8.0 | manager | stdlib@v1.23.1 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | kube-vip | golang.org/x/crypto@v0.45.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | kube-vip | golang.org/x/crypto@v0.45.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | kube-vip | golang.org/x/crypto@v0.45.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | kube-vip | golang.org/x/crypto@v0.45.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | kube-vip | golang.org/x/crypto@v0.45.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | kube-vip | golang.org/x/crypto@v0.45.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | kube-vip | golang.org/x/crypto@v0.45.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | kube-vip | golang.org/x/crypto@v0.45.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | kube-vip | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | kube-vip | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | kube-vip | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | kube-vip | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | kube-vip | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | kube-vip | stdlib@v1.25.6 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | kube-vip | stdlib@v1.25.6 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | kube-vip | stdlib@v1.25.6 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-kube-vip-kube-vip-iptables:v1.0.4 | true | Harvester v1.8.0 | kube-vip | stdlib@v1.25.6 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | go.opentelemetry.io/otel/sdk@v1.21.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | go.opentelemetry.io/otel/sdk@v1.21.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | golang.org/x/crypto@v0.22.0 | CVE-2024-45337 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | golang.org/x/crypto@v0.22.0 | CVE-2025-22869 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | golang.org/x/crypto@v0.22.0 | CVE-2025-47913 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | golang.org/x/crypto@v0.22.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | golang.org/x/crypto@v0.22.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | golang.org/x/crypto@v0.22.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | golang.org/x/crypto@v0.22.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | golang.org/x/crypto@v0.22.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | golang.org/x/crypto@v0.22.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | golang.org/x/crypto@v0.22.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | golang.org/x/crypto@v0.22.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | golang.org/x/net@v0.24.0 | CVE-2024-45338 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | golang.org/x/net@v0.24.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | golang.org/x/net@v0.24.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | golang.org/x/net@v0.24.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | golang.org/x/net@v0.24.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | golang.org/x/net@v0.24.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | golang.org/x/oauth2@v0.18.0 | CVE-2025-22868 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | stdlib@v1.22.2 | CVE-2024-34156 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | stdlib@v1.22.2 | CVE-2026-32280 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-adapter-prometheus-adapter:v0.12.0 | true | Harvester v1.8.0 | adapter | stdlib@v1.22.2 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-admission-webhook:v0.85.0 | true | Harvester v1.8.0 | bin/admission-webhook | golang.org/x/net@v0.43.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-admission-webhook:v0.85.0 | true | Harvester v1.8.0 | bin/admission-webhook | golang.org/x/net@v0.43.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-admission-webhook:v0.85.0 | true | Harvester v1.8.0 | bin/admission-webhook | golang.org/x/net@v0.43.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-admission-webhook:v0.85.0 | true | Harvester v1.8.0 | bin/admission-webhook | golang.org/x/net@v0.43.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-admission-webhook:v0.85.0 | true | Harvester v1.8.0 | bin/admission-webhook | golang.org/x/net@v0.43.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-admission-webhook:v0.85.0 | true | Harvester v1.8.0 | bin/admission-webhook | stdlib@v1.24.6 | CVE-2025-61726 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-admission-webhook:v0.85.0 | true | Harvester v1.8.0 | bin/admission-webhook | stdlib@v1.24.6 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-admission-webhook:v0.85.0 | true | Harvester v1.8.0 | bin/admission-webhook | stdlib@v1.24.6 | CVE-2026-39820 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-admission-webhook:v0.85.0 | true | Harvester v1.8.0 | bin/admission-webhook | stdlib@v1.24.6 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-admission-webhook:v0.85.0 | true | Harvester v1.8.0 | bin/admission-webhook | stdlib@v1.24.6 | CVE-2026-42499 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | golang.org/x/crypto@v0.32.0 | CVE-2025-22869 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | golang.org/x/crypto@v0.32.0 | CVE-2025-47913 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | golang.org/x/crypto@v0.32.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | golang.org/x/crypto@v0.32.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | golang.org/x/crypto@v0.32.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | golang.org/x/crypto@v0.32.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | golang.org/x/crypto@v0.32.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | golang.org/x/crypto@v0.32.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | golang.org/x/crypto@v0.32.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | golang.org/x/crypto@v0.32.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | golang.org/x/net@v0.34.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | golang.org/x/net@v0.34.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | golang.org/x/net@v0.34.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | golang.org/x/net@v0.34.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | golang.org/x/net@v0.34.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | golang.org/x/oauth2@v0.25.0 | CVE-2025-22868 | none | not affected | vulnerable code not present | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | stdlib@v1.23.6 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | stdlib@v1.23.6 | CVE-2026-39820 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | stdlib@v1.23.6 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-config-reloader:v0.80.1 | true | Harvester v1.8.0 | bin/prometheus-config-reloader | stdlib@v1.23.6 | CVE-2026-42499 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-operator:v0.85.0 | true | Harvester v1.8.0 | bin/operator | golang.org/x/net@v0.43.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-operator:v0.85.0 | true | Harvester v1.8.0 | bin/operator | golang.org/x/net@v0.43.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-operator:v0.85.0 | true | Harvester v1.8.0 | bin/operator | golang.org/x/net@v0.43.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-operator:v0.85.0 | true | Harvester v1.8.0 | bin/operator | golang.org/x/net@v0.43.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-operator:v0.85.0 | true | Harvester v1.8.0 | bin/operator | golang.org/x/net@v0.43.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-operator:v0.85.0 | true | Harvester v1.8.0 | bin/operator | stdlib@v1.24.6 | CVE-2025-61726 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-operator:v0.85.0 | true | Harvester v1.8.0 | bin/operator | stdlib@v1.24.6 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-operator:v0.85.0 | true | Harvester v1.8.0 | bin/operator | stdlib@v1.24.6 | CVE-2026-39820 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-operator:v0.85.0 | true | Harvester v1.8.0 | bin/operator | stdlib@v1.24.6 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/mirrored-prometheus-operator-prometheus-operator:v0.85.0 | true | Harvester v1.8.0 | bin/operator | stdlib@v1.24.6 | CVE-2026-42499 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | golang.org/x/crypto@v0.39.0 | CVE-2025-47913 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | golang.org/x/crypto@v0.39.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | golang.org/x/crypto@v0.39.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | golang.org/x/crypto@v0.39.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | golang.org/x/crypto@v0.39.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | golang.org/x/crypto@v0.39.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | golang.org/x/crypto@v0.39.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | golang.org/x/crypto@v0.39.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | golang.org/x/crypto@v0.39.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | golang.org/x/net@v0.41.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | golang.org/x/net@v0.41.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | golang.org/x/net@v0.41.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | golang.org/x/net@v0.41.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | golang.org/x/net@v0.41.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/prometheus | stdlib@v1.24.5 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | golang.org/x/crypto@v0.39.0 | CVE-2025-47913 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | golang.org/x/crypto@v0.39.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | golang.org/x/crypto@v0.39.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | golang.org/x/crypto@v0.39.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | golang.org/x/crypto@v0.39.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | golang.org/x/crypto@v0.39.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | golang.org/x/crypto@v0.39.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | golang.org/x/crypto@v0.39.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | golang.org/x/crypto@v0.39.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | golang.org/x/net@v0.41.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | golang.org/x/net@v0.41.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | golang.org/x/net@v0.41.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | golang.org/x/net@v0.41.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | golang.org/x/net@v0.41.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/prom-prometheus:v3.5.0 | false | Harvester v1.8.0 | bin/promtool | stdlib@v1.24.5 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | bind-utils | bind-utils@9.20.18-150700.3.15.1 | SUSE-SU-2026:1351-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | libexpat1 | libexpat1@2.7.1-150700.3.9.2 | SUSE-SU-2026:1352-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | github.com/docker/docker@v25.0.13+incompatible | CVE-2026-34040 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | go.opentelemetry.io/otel/sdk@v1.38.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | go.opentelemetry.io/otel/sdk@v1.38.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | golang.org/x/crypto@v0.48.0 | CVE-2026-39827 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | golang.org/x/crypto@v0.48.0 | CVE-2026-39828 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | golang.org/x/crypto@v0.48.0 | CVE-2026-39835 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | golang.org/x/crypto@v0.48.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | golang.org/x/crypto@v0.48.0 | CVE-2026-46595 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | golang.org/x/net@v0.51.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | golang.org/x/net@v0.51.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | golang.org/x/net@v0.51.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | golang.org/x/net@v0.51.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/agent | golang.org/x/net@v0.51.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.25.6 | CVE-2026-32280 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher-agent:v2.14.0 | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.25.6 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher-webhook:v0.10.0 | false | Harvester v1.8.0 | usr/bin/webhook | golang.org/x/crypto@v0.49.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher-webhook:v0.10.0 | false | Harvester v1.8.0 | usr/bin/webhook | golang.org/x/crypto@v0.49.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher-webhook:v0.10.0 | false | Harvester v1.8.0 | usr/bin/webhook | golang.org/x/crypto@v0.49.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher-webhook:v0.10.0 | false | Harvester v1.8.0 | usr/bin/webhook | golang.org/x/crypto@v0.49.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher-webhook:v0.10.0 | false | Harvester v1.8.0 | usr/bin/webhook | golang.org/x/crypto@v0.49.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher-webhook:v0.10.0 | false | Harvester v1.8.0 | usr/bin/webhook | golang.org/x/crypto@v0.49.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher-webhook:v0.10.0 | false | Harvester v1.8.0 | usr/bin/webhook | golang.org/x/crypto@v0.49.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher-webhook:v0.10.0 | false | Harvester v1.8.0 | usr/bin/webhook | golang.org/x/crypto@v0.49.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher-webhook:v0.10.0 | false | Harvester v1.8.0 | usr/bin/webhook | golang.org/x/net@v0.52.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher-webhook:v0.10.0 | false | Harvester v1.8.0 | usr/bin/webhook | golang.org/x/net@v0.52.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher-webhook:v0.10.0 | false | Harvester v1.8.0 | usr/bin/webhook | golang.org/x/net@v0.52.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher-webhook:v0.10.0 | false | Harvester v1.8.0 | usr/bin/webhook | golang.org/x/net@v0.52.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher-webhook:v0.10.0 | false | Harvester v1.8.0 | usr/bin/webhook | golang.org/x/net@v0.52.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | libexpat1 | libexpat1@2.7.1-150700.3.9.2 | SUSE-SU-2026:1352-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | login_defs | login_defs@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | shadow | shadow@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-harvester | github.com/harvester/harvester@v0.0.0-20251016061812-c537e12b7f09 | CVE-2025-71261 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-harvester | golang.org/x/crypto@v0.40.0 | CVE-2025-47913 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-harvester | golang.org/x/crypto@v0.40.0 | CVE-2026-39827 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-harvester | golang.org/x/crypto@v0.40.0 | CVE-2026-39828 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-harvester | golang.org/x/crypto@v0.40.0 | CVE-2026-39829 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-harvester | golang.org/x/crypto@v0.40.0 | CVE-2026-39830 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-harvester | golang.org/x/crypto@v0.40.0 | CVE-2026-39835 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-harvester | golang.org/x/crypto@v0.40.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-harvester | golang.org/x/crypto@v0.40.0 | CVE-2026-46595 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-harvester | golang.org/x/crypto@v0.40.0 | CVE-2026-46597 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-harvester | golang.org/x/net@v0.38.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-harvester | golang.org/x/net@v0.38.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-harvester | golang.org/x/net@v0.38.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-harvester | golang.org/x/net@v0.38.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-harvester | golang.org/x/net@v0.38.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-harvester | stdlib@v1.25.5 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-harvester | stdlib@v1.25.5 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-harvester | stdlib@v1.25.5 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | opt/drivers/management-state/bin/docker-machine-driver-harvester | stdlib@v1.25.5 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | github.com/buger/jsonparser@v1.1.1 | CVE-2026-32285 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | github.com/docker/cli@v28.3.2+incompatible | CVE-2025-15558 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | github.com/docker/docker@v25.0.8+incompatible | CVE-2026-34040 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | github.com/jackc/pgx/v5@v5.8.0 | CVE-2026-33816 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | go.opentelemetry.io/otel/sdk@v1.38.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | go.opentelemetry.io/otel/sdk@v1.38.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | golang.org/x/crypto@v0.45.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | golang.org/x/crypto@v0.45.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | golang.org/x/crypto@v0.45.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | golang.org/x/crypto@v0.45.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | golang.org/x/crypto@v0.45.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | golang.org/x/crypto@v0.45.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | golang.org/x/crypto@v0.45.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | golang.org/x/crypto@v0.45.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd | stdlib@v1.25.6 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd-shim-runc-v2 | github.com/containerd/containerd/v2@v2.1.5-k3s1 | CVE-2024-25621 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd-shim-runc-v2 | github.com/containerd/containerd/v2@v2.1.5-k3s1 | CVE-2026-46680 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd-shim-runc-v2 | golang.org/x/net@v0.38.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd-shim-runc-v2 | golang.org/x/net@v0.38.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd-shim-runc-v2 | golang.org/x/net@v0.38.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd-shim-runc-v2 | golang.org/x/net@v0.38.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd-shim-runc-v2 | golang.org/x/net@v0.38.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd-shim-runc-v2 | google.golang.org/grpc@v1.73.0 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd-shim-runc-v2 | stdlib@v1.25.6 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd-shim-runc-v2 | stdlib@v1.25.6 | CVE-2026-39820 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd-shim-runc-v2 | stdlib@v1.25.6 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/containerd-shim-runc-v2 | stdlib@v1.25.6 | CVE-2026-42499 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/etcdctl | golang.org/x/net@v0.45.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/etcdctl | golang.org/x/net@v0.45.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/etcdctl | golang.org/x/net@v0.45.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/etcdctl | golang.org/x/net@v0.45.0 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/etcdctl | golang.org/x/net@v0.45.0 | CVE-2026-39821 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/etcdctl | golang.org/x/net@v0.45.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/etcdctl | golang.org/x/net@v0.45.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/etcdctl | google.golang.org/grpc@v1.71.1 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/etcdctl | stdlib@v1.24.11 | CVE-2025-61726 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/etcdctl | stdlib@v1.24.11 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/etcdctl | stdlib@v1.24.11 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/etcdctl | stdlib@v1.24.11 | CVE-2026-39823 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/etcdctl | stdlib@v1.24.11 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/etcdctl | stdlib@v1.24.11 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/etcdctl | stdlib@v1.24.11 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | github.com/buger/jsonparser@v1.1.1 | CVE-2026-32285 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | github.com/docker/cli@v28.3.2+incompatible | CVE-2025-15558 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | github.com/docker/docker@v25.0.8+incompatible | CVE-2026-34040 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | github.com/jackc/pgx/v5@v5.8.0 | CVE-2026-33816 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | go.opentelemetry.io/otel/sdk@v1.38.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | go.opentelemetry.io/otel/sdk@v1.38.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | golang.org/x/crypto@v0.45.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | golang.org/x/crypto@v0.45.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | golang.org/x/crypto@v0.45.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | golang.org/x/crypto@v0.45.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | golang.org/x/crypto@v0.45.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | golang.org/x/crypto@v0.45.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | golang.org/x/crypto@v0.45.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | golang.org/x/crypto@v0.45.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/k3s | stdlib@v1.25.6 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | github.com/docker/docker@v25.0.13+incompatible | CVE-2026-34040 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | go.opentelemetry.io/otel/sdk@v1.38.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | go.opentelemetry.io/otel/sdk@v1.38.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | golang.org/x/crypto@v0.48.0 | CVE-2026-39827 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | golang.org/x/crypto@v0.48.0 | CVE-2026-39828 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | golang.org/x/crypto@v0.48.0 | CVE-2026-39835 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | golang.org/x/crypto@v0.48.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | golang.org/x/crypto@v0.48.0 | CVE-2026-46595 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | golang.org/x/net@v0.51.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | golang.org/x/net@v0.51.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | golang.org/x/net@v0.51.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | golang.org/x/net@v0.51.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher | golang.org/x/net@v0.51.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | github.com/golang-jwt/jwt/v4@v4.5.0 | CVE-2025-30204 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | go.opentelemetry.io/otel@v1.36.0 | CVE-2026-29181 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | golang.org/x/crypto@v0.44.0 | CVE-2026-39827 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | golang.org/x/crypto@v0.44.0 | CVE-2026-39828 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | golang.org/x/crypto@v0.44.0 | CVE-2026-39835 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | golang.org/x/crypto@v0.44.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | golang.org/x/crypto@v0.44.0 | CVE-2026-46595 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/rancher-machine | google.golang.org/grpc@v1.72.2 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/runc | golang.org/x/net@v0.43.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/runc | golang.org/x/net@v0.43.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/runc | golang.org/x/net@v0.43.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/runc | golang.org/x/net@v0.43.0 | CVE-2026-33814 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/runc | golang.org/x/net@v0.43.0 | CVE-2026-39821 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/runc | golang.org/x/net@v0.43.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/runc | golang.org/x/net@v0.43.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/runc | stdlib@v1.25.6 | CVE-2025-68121 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/runc | stdlib@v1.25.6 | CVE-2026-32280 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/runc | stdlib@v1.25.6 | CVE-2026-32281 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/runc | stdlib@v1.25.6 | CVE-2026-32283 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/runc | stdlib@v1.25.6 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/runc | stdlib@v1.25.6 | CVE-2026-33814 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/runc | stdlib@v1.25.6 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/runc | stdlib@v1.25.6 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/runc | stdlib@v1.25.6 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/runc | stdlib@v1.25.6 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/bin/runc | stdlib@v1.25.6 | CVE-2026-42504 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | github.com/docker/cli@v28.5.1+incompatible | CVE-2025-15558 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | go.opentelemetry.io/otel/sdk@v1.38.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | go.opentelemetry.io/otel/sdk@v1.38.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | stdlib@v1.26.1 | CVE-2026-32280 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | stdlib@v1.26.1 | CVE-2026-32281 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | stdlib@v1.26.1 | CVE-2026-32283 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | stdlib@v1.26.1 | CVE-2026-33810 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | stdlib@v1.26.1 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | stdlib@v1.26.1 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | stdlib@v1.26.1 | CVE-2026-39820 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | stdlib@v1.26.1 | CVE-2026-39823 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | stdlib@v1.26.1 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | stdlib@v1.26.1 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rancher:v2.14.0 | false | Harvester v1.8.0 | usr/share/rancher/ui/assets/wins.exe | stdlib@v1.26.1 | CVE-2026-42499 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | github.com/docker/cli@v28.3.2+incompatible | CVE-2025-15558 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | github.com/jackc/pgx/v5@v5.8.0 | CVE-2026-33816 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | go.opentelemetry.io/otel/sdk@v1.38.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | go.opentelemetry.io/otel/sdk@v1.38.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | golang.org/x/crypto@v0.45.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | golang.org/x/crypto@v0.45.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | golang.org/x/crypto@v0.45.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | golang.org/x/crypto@v0.45.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | golang.org/x/crypto@v0.45.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | golang.org/x/crypto@v0.45.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | golang.org/x/crypto@v0.45.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | golang.org/x/crypto@v0.45.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | google.golang.org/grpc@v1.72.2 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-cloud-provider:v1.35.1-0.20260211145923-50fa2d70c239-build20260211 | false | Harvester v1.8.0 | usr/local/bin/rke2-cloud-provider | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | github.com/containerd/containerd/v2@v2.1.5-k3s1 | CVE-2024-25621 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | github.com/containerd/containerd/v2@v2.1.5-k3s1 | CVE-2026-46680 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | github.com/docker/cli@v28.3.2+incompatible | CVE-2025-15558 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | github.com/go-jose/go-jose/v4@v4.0.5 | CVE-2026-34986 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | github.com/opencontainers/selinux@v1.12.0 | CVE-2025-52881 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | go.opentelemetry.io/otel/sdk@v1.35.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | go.opentelemetry.io/otel/sdk@v1.35.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | golang.org/x/crypto@v0.36.0 | CVE-2025-47913 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | golang.org/x/crypto@v0.36.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | golang.org/x/crypto@v0.36.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | golang.org/x/crypto@v0.36.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | golang.org/x/crypto@v0.36.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | golang.org/x/crypto@v0.36.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | golang.org/x/crypto@v0.36.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | golang.org/x/crypto@v0.36.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | golang.org/x/crypto@v0.36.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | golang.org/x/net@v0.38.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | golang.org/x/net@v0.38.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | golang.org/x/net@v0.38.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | golang.org/x/net@v0.38.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | golang.org/x/net@v0.38.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | google.golang.org/grpc@v1.73.0 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | stdlib@v1.24.13 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | stdlib@v1.24.13 | CVE-2026-39820 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | stdlib@v1.24.13 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd | stdlib@v1.24.13 | CVE-2026-42499 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd-shim-runc-v2 | github.com/containerd/containerd/v2@v2.1.5-k3s1 | CVE-2024-25621 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd-shim-runc-v2 | github.com/containerd/containerd/v2@v2.1.5-k3s1 | CVE-2026-46680 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd-shim-runc-v2 | golang.org/x/net@v0.38.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd-shim-runc-v2 | golang.org/x/net@v0.38.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd-shim-runc-v2 | golang.org/x/net@v0.38.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd-shim-runc-v2 | golang.org/x/net@v0.38.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd-shim-runc-v2 | golang.org/x/net@v0.38.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd-shim-runc-v2 | google.golang.org/grpc@v1.73.0 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd-shim-runc-v2 | stdlib@v1.24.13 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd-shim-runc-v2 | stdlib@v1.24.13 | CVE-2026-39820 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd-shim-runc-v2 | stdlib@v1.24.13 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/containerd-shim-runc-v2 | stdlib@v1.24.13 | CVE-2026-42499 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/crictl | github.com/buger/jsonparser@v1.1.1 | CVE-2026-32285 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/crictl | github.com/docker/docker@v27.1.1+incompatible | CVE-2026-34040 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/crictl | github.com/docker/docker@v27.1.1+incompatible | CVE-2026-41567 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/crictl | github.com/docker/docker@v27.1.1+incompatible | CVE-2026-42306 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/crictl | go.opentelemetry.io/otel/sdk@v1.37.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/crictl | go.opentelemetry.io/otel/sdk@v1.37.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/crictl | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/crictl | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/crictl | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/crictl | golang.org/x/net@v0.47.0 | CVE-2026-39821 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/crictl | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/crictl | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/crictl | google.golang.org/grpc@v1.75.0 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/crictl | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/crictl | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/crictl | stdlib@v1.25.7 | CVE-2026-39823 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/crictl | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/crictl | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/crictl | stdlib@v1.25.7 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/ctr | github.com/containerd/containerd/v2@v2.1.5-k3s1 | CVE-2024-25621 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/ctr | github.com/containerd/containerd/v2@v2.1.5-k3s1 | CVE-2026-46680 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/ctr | github.com/opencontainers/selinux@v1.12.0 | CVE-2025-52881 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/ctr | golang.org/x/net@v0.38.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/ctr | golang.org/x/net@v0.38.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/ctr | golang.org/x/net@v0.38.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/ctr | golang.org/x/net@v0.38.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/ctr | golang.org/x/net@v0.38.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/ctr | google.golang.org/grpc@v1.73.0 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/ctr | stdlib@v1.24.13 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/ctr | stdlib@v1.24.13 | CVE-2026-39820 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/ctr | stdlib@v1.24.13 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/ctr | stdlib@v1.24.13 | CVE-2026-42499 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubectl | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubectl | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubectl | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubelet | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubelet | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubelet | golang.org/x/crypto@v0.45.0 | CVE-2026-39827 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubelet | golang.org/x/crypto@v0.45.0 | CVE-2026-39828 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubelet | golang.org/x/crypto@v0.45.0 | CVE-2026-39835 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubelet | golang.org/x/crypto@v0.45.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubelet | golang.org/x/crypto@v0.45.0 | CVE-2026-46595 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubelet | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubelet | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubelet | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubelet | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubelet | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubelet | google.golang.org/grpc@v1.72.2 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubelet | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubelet | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/kubelet | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/runc | golang.org/x/net@v0.43.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/runc | golang.org/x/net@v0.43.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/runc | golang.org/x/net@v0.43.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/runc | golang.org/x/net@v0.43.0 | CVE-2026-33814 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/runc | golang.org/x/net@v0.43.0 | CVE-2026-39821 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/runc | golang.org/x/net@v0.43.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/runc | golang.org/x/net@v0.43.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/runc | stdlib@v1.24.13 | CVE-2026-25679 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/runc | stdlib@v1.24.13 | CVE-2026-32280 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/runc | stdlib@v1.24.13 | CVE-2026-32281 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/runc | stdlib@v1.24.13 | CVE-2026-32283 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/runc | stdlib@v1.24.13 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/runc | stdlib@v1.24.13 | CVE-2026-33814 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/runc | stdlib@v1.24.13 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/runc | stdlib@v1.24.13 | CVE-2026-39823 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/runc | stdlib@v1.24.13 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/runc | stdlib@v1.24.13 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.2-rke2r1 | false | Harvester v1.8.0 | bin/runc | stdlib@v1.24.13 | CVE-2026-42504 | none | not affected | vulnerable code not present | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | vim | vim@9.2.0110-150500.20.43.1 | SUSE-SU-2026:1607-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | vim | vim@9.2.0110-150500.20.43.1 | SUSE-SU-2026:2236-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | vim-data-common | vim-data-common@9.2.0110-150500.20.43.1 | SUSE-SU-2026:1607-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | vim-data-common | vim-data-common@9.2.0110-150500.20.43.1 | SUSE-SU-2026:2236-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/helm | golang.org/x/crypto@v0.46.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/helm | golang.org/x/crypto@v0.46.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/helm | golang.org/x/crypto@v0.46.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/helm | golang.org/x/crypto@v0.46.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/helm | golang.org/x/crypto@v0.46.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/helm | golang.org/x/crypto@v0.46.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/helm | golang.org/x/crypto@v0.46.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/helm | golang.org/x/crypto@v0.46.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/helm | golang.org/x/net@v0.48.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/helm | golang.org/x/net@v0.48.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/helm | golang.org/x/net@v0.48.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/helm | golang.org/x/net@v0.48.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/helm | golang.org/x/net@v0.48.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/helm | google.golang.org/grpc@v1.72.2 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/helm | stdlib@v1.25.8 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/helm | stdlib@v1.25.8 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/helm | stdlib@v1.25.8 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/helm | stdlib@v1.25.8 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | github.com/docker/cli@v29.1.2+incompatible | CVE-2025-15558 | none | not affected | vulnerable code not present | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | go.opentelemetry.io/otel/sdk@v1.37.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | go.opentelemetry.io/otel/sdk@v1.37.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | golang.org/x/crypto@v0.46.0 | CVE-2026-39827 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | golang.org/x/crypto@v0.46.0 | CVE-2026-39828 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | golang.org/x/crypto@v0.46.0 | CVE-2026-46595 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | golang.org/x/net@v0.48.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | golang.org/x/net@v0.48.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | golang.org/x/net@v0.48.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | golang.org/x/net@v0.48.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | golang.org/x/net@v0.48.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | google.golang.org/grpc@v1.74.0 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | stdlib@v1.25.1 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | stdlib@v1.25.1 | CVE-2026-39823 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/k9s | stdlib@v1.25.1 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/kubectl | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/kubectl | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/kubectl | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/shell:v0.7.0 | false | Harvester v1.8.0 | usr/local/bin/kubectl | stdlib@v1.25.7 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/system-agent-installer-rancher:v2.14.0 | false | Harvester v1.8.0 | helm | golang.org/x/crypto@v0.46.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent-installer-rancher:v2.14.0 | false | Harvester v1.8.0 | helm | golang.org/x/crypto@v0.46.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent-installer-rancher:v2.14.0 | false | Harvester v1.8.0 | helm | golang.org/x/crypto@v0.46.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent-installer-rancher:v2.14.0 | false | Harvester v1.8.0 | helm | golang.org/x/crypto@v0.46.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent-installer-rancher:v2.14.0 | false | Harvester v1.8.0 | helm | golang.org/x/crypto@v0.46.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent-installer-rancher:v2.14.0 | false | Harvester v1.8.0 | helm | golang.org/x/crypto@v0.46.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent-installer-rancher:v2.14.0 | false | Harvester v1.8.0 | helm | golang.org/x/crypto@v0.46.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent-installer-rancher:v2.14.0 | false | Harvester v1.8.0 | helm | golang.org/x/crypto@v0.46.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent-installer-rancher:v2.14.0 | false | Harvester v1.8.0 | helm | golang.org/x/net@v0.48.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent-installer-rancher:v2.14.0 | false | Harvester v1.8.0 | helm | golang.org/x/net@v0.48.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent-installer-rancher:v2.14.0 | false | Harvester v1.8.0 | helm | golang.org/x/net@v0.48.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent-installer-rancher:v2.14.0 | false | Harvester v1.8.0 | helm | golang.org/x/net@v0.48.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent-installer-rancher:v2.14.0 | false | Harvester v1.8.0 | helm | golang.org/x/net@v0.48.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent-installer-rancher:v2.14.0 | false | Harvester v1.8.0 | helm | google.golang.org/grpc@v1.72.2 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/system-agent-installer-rancher:v2.14.0 | false | Harvester v1.8.0 | helm | stdlib@v1.25.6 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/system-agent-installer-rancher:v2.14.0 | false | Harvester v1.8.0 | helm | stdlib@v1.25.6 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent-installer-rancher:v2.14.0 | false | Harvester v1.8.0 | helm | stdlib@v1.25.6 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/system-agent-installer-rancher:v2.14.0 | false | Harvester v1.8.0 | helm | stdlib@v1.25.6 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | opt/rancher-system-agent-suc/rancher-system-agent | github.com/docker/cli@v27.1.1+incompatible | CVE-2025-15558 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | opt/rancher-system-agent-suc/rancher-system-agent | go.opentelemetry.io/otel/sdk@v1.38.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | opt/rancher-system-agent-suc/rancher-system-agent | go.opentelemetry.io/otel/sdk@v1.38.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | opt/rancher-system-agent-suc/rancher-system-agent | golang.org/x/crypto@v0.45.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | opt/rancher-system-agent-suc/rancher-system-agent | golang.org/x/crypto@v0.45.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | opt/rancher-system-agent-suc/rancher-system-agent | golang.org/x/crypto@v0.45.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | opt/rancher-system-agent-suc/rancher-system-agent | golang.org/x/crypto@v0.45.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | opt/rancher-system-agent-suc/rancher-system-agent | golang.org/x/crypto@v0.45.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | opt/rancher-system-agent-suc/rancher-system-agent | golang.org/x/crypto@v0.45.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | opt/rancher-system-agent-suc/rancher-system-agent | golang.org/x/crypto@v0.45.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | opt/rancher-system-agent-suc/rancher-system-agent | golang.org/x/crypto@v0.45.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | opt/rancher-system-agent-suc/rancher-system-agent | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | opt/rancher-system-agent-suc/rancher-system-agent | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | opt/rancher-system-agent-suc/rancher-system-agent | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | opt/rancher-system-agent-suc/rancher-system-agent | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | opt/rancher-system-agent-suc/rancher-system-agent | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | opt/rancher-system-agent-suc/rancher-system-agent | google.golang.org/grpc@v1.75.0 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | usr/bin/kubectl | golang.org/x/net@v0.38.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | usr/bin/kubectl | golang.org/x/net@v0.38.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | usr/bin/kubectl | golang.org/x/net@v0.38.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | usr/bin/kubectl | golang.org/x/net@v0.38.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | usr/bin/kubectl | golang.org/x/net@v0.38.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.24.6 | CVE-2025-61726 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.24.6 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/system-agent:v0.3.15-suc | false | Harvester v1.8.0 | usr/bin/kubectl | stdlib@v1.24.6 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/system-upgrade-controller:v0.19.0 | false | Harvester v1.8.0 | bin/system-upgrade-controller | golang.org/x/net@v0.47.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/system-upgrade-controller:v0.19.0 | false | Harvester v1.8.0 | bin/system-upgrade-controller | golang.org/x/net@v0.47.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/system-upgrade-controller:v0.19.0 | false | Harvester v1.8.0 | bin/system-upgrade-controller | golang.org/x/net@v0.47.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/system-upgrade-controller:v0.19.0 | false | Harvester v1.8.0 | bin/system-upgrade-controller | golang.org/x/net@v0.47.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/system-upgrade-controller:v0.19.0 | false | Harvester v1.8.0 | bin/system-upgrade-controller | golang.org/x/net@v0.47.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/system-upgrade-controller:v0.19.0 | false | Harvester v1.8.0 | bin/system-upgrade-controller | stdlib@v1.25.7 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/system-upgrade-controller:v0.19.0 | false | Harvester v1.8.0 | bin/system-upgrade-controller | stdlib@v1.25.7 | CVE-2026-39820 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/system-upgrade-controller:v0.19.0 | false | Harvester v1.8.0 | bin/system-upgrade-controller | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/system-upgrade-controller:v0.19.0 | false | Harvester v1.8.0 | bin/system-upgrade-controller | stdlib@v1.25.7 | CVE-2026-42499 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/turtles:v0.26.0 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.48.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| rancher/turtles:v0.26.0 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.48.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| rancher/turtles:v0.26.0 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.48.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| rancher/turtles:v0.26.0 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.48.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| rancher/turtles:v0.26.0 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.48.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| rancher/turtles:v0.26.0 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.48.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| rancher/turtles:v0.26.0 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.48.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| rancher/turtles:v0.26.0 | false | Harvester v1.8.0 | manager | golang.org/x/crypto@v0.48.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| rancher/turtles:v0.26.0 | false | Harvester v1.8.0 | manager | golang.org/x/net@v0.51.0 | CVE-2026-25680 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/turtles:v0.26.0 | false | Harvester v1.8.0 | manager | golang.org/x/net@v0.51.0 | CVE-2026-25681 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/turtles:v0.26.0 | false | Harvester v1.8.0 | manager | golang.org/x/net@v0.51.0 | CVE-2026-27136 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/turtles:v0.26.0 | false | Harvester v1.8.0 | manager | golang.org/x/net@v0.51.0 | CVE-2026-42502 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/turtles:v0.26.0 | false | Harvester v1.8.0 | manager | golang.org/x/net@v0.51.0 | CVE-2026-42506 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/turtles:v0.26.0 | false | Harvester v1.8.0 | manager | stdlib@v1.25.8 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/turtles:v0.26.0 | false | Harvester v1.8.0 | manager | stdlib@v1.25.8 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/turtles:v0.26.0 | false | Harvester v1.8.0 | manager | stdlib@v1.25.8 | CVE-2026-39823 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/turtles:v0.26.0 | false | Harvester v1.8.0 | manager | stdlib@v1.25.8 | CVE-2026-39825 | none | not affected | vulnerable code not present | gobinary |
| rancher/turtles:v0.26.0 | false | Harvester v1.8.0 | manager | stdlib@v1.25.8 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | go.opentelemetry.io/otel/sdk@v1.33.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | go.opentelemetry.io/otel/sdk@v1.33.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | golang.org/x/crypto@v0.36.0 | CVE-2025-47913 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | golang.org/x/crypto@v0.36.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | golang.org/x/crypto@v0.36.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | golang.org/x/crypto@v0.36.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | golang.org/x/crypto@v0.36.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | golang.org/x/crypto@v0.36.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | golang.org/x/crypto@v0.36.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | golang.org/x/crypto@v0.36.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | golang.org/x/crypto@v0.36.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | golang.org/x/net@v0.38.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | golang.org/x/net@v0.38.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | golang.org/x/net@v0.38.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | golang.org/x/net@v0.38.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | golang.org/x/net@v0.38.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/descheduler/descheduler:v0.33.0 | false | Harvester v1.8.0 | bin/descheduler | stdlib@v1.24.2 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| registry.k8s.io/sig-storage/snapshot-controller:v8.5.0 | false | Harvester v1.8.0 | snapshot-controller | go.opentelemetry.io/otel/sdk@v1.40.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/sig-storage/snapshot-controller:v8.5.0 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/crypto@v0.47.0 | CVE-2026-39827 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/sig-storage/snapshot-controller:v8.5.0 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/crypto@v0.47.0 | CVE-2026-39828 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/sig-storage/snapshot-controller:v8.5.0 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/crypto@v0.47.0 | CVE-2026-39829 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/sig-storage/snapshot-controller:v8.5.0 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/crypto@v0.47.0 | CVE-2026-39830 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/sig-storage/snapshot-controller:v8.5.0 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/crypto@v0.47.0 | CVE-2026-39835 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/sig-storage/snapshot-controller:v8.5.0 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/crypto@v0.47.0 | CVE-2026-42508 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/sig-storage/snapshot-controller:v8.5.0 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/crypto@v0.47.0 | CVE-2026-46595 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/sig-storage/snapshot-controller:v8.5.0 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/crypto@v0.47.0 | CVE-2026-46597 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/sig-storage/snapshot-controller:v8.5.0 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/net@v0.49.0 | CVE-2026-25680 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/sig-storage/snapshot-controller:v8.5.0 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/net@v0.49.0 | CVE-2026-25681 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/sig-storage/snapshot-controller:v8.5.0 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/net@v0.49.0 | CVE-2026-27136 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/sig-storage/snapshot-controller:v8.5.0 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/net@v0.49.0 | CVE-2026-42502 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/sig-storage/snapshot-controller:v8.5.0 | false | Harvester v1.8.0 | snapshot-controller | golang.org/x/net@v0.49.0 | CVE-2026-42506 | none | not affected | vulnerable code not present | gobinary |
| registry.k8s.io/sig-storage/snapshot-controller:v8.5.0 | false | Harvester v1.8.0 | snapshot-controller | google.golang.org/grpc@v1.78.0 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| registry.k8s.io/sig-storage/snapshot-controller:v8.5.0 | false | Harvester v1.8.0 | snapshot-controller | stdlib@v1.25.7 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | curl | curl@8.6.0-150600.4.21.1 | SUSE-SU-2025:03198-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | curl | curl@8.6.0-150600.4.21.1 | SUSE-SU-2026:0903-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | gpg2 | gpg2@2.4.4-150600.3.9.1 | SUSE-SU-2026:0215-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | gpg2 | gpg2@2.4.4-150600.3.9.1 | SUSE-SU-2026:0434-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libglib-2_0-0 | libglib-2_0-0@2.78.6-150600.4.16.1 | SUSE-SU-2026:0018-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libglib-2_0-0 | libglib-2_0-0@2.78.6-150600.4.16.1 | SUSE-SU-2026:0373-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libnghttp2-14 | libnghttp2-14@1.64.0-150700.1.5 | SUSE-SU-2026:1074-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.10.1 | SUSE-SU-2026:0309-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.10.1 | SUSE-SU-2025:03546-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl3 | libopenssl3@3.2.3-150700.5.10.1 | SUSE-SU-2026:1375-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.49.1-150000.3.27.1 | SUSE-SU-2025:02672-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.10.1 | SUSE-SU-2026:0309-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.10.1 | SUSE-SU-2025:03546-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.10.1 | SUSE-SU-2026:1375-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-apiserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | tar | tar@1.34-150000.3.34.1 | SUSE-SU-2026:1177-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | boost-license1_66_0 | boost-license1_66_0@1.66.0-12.3.1 | SUSE-SU-2025:02536-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | gpg2 | gpg2@2.4.4-150600.3.9.1 | SUSE-SU-2026:0215-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | gpg2 | gpg2@2.4.4-150600.3.9.1 | SUSE-SU-2026:0434-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libbrotlicommon1 | libbrotlicommon1@1.0.7-3.3.1 | SUSE-SU-2025:03268-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.10.1 | SUSE-SU-2026:0309-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.10.1 | SUSE-SU-2025:03546-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.10.1 | SUSE-SU-2026:1375-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.49.1-150000.3.27.1 | SUSE-SU-2025:02672-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.10.1 | SUSE-SU-2026:0309-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.10.1 | SUSE-SU-2025:03546-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | openssl-3 | openssl-3@3.2.3-150700.5.10.1 | SUSE-SU-2026:1375-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-cloner:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | tar | tar@1.34-150000.3.34.1 | SUSE-SU-2026:1177-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | gpg2 | gpg2@2.4.4-150600.3.9.1 | SUSE-SU-2026:0215-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | gpg2 | gpg2@2.4.4-150600.3.9.1 | SUSE-SU-2026:0434-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libboost_system1_66_0 | libboost_system1_66_0@1.66.0-12.3.1 | SUSE-SU-2025:02536-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libbrotlidec1 | libbrotlidec1@1.0.7-3.3.1 | SUSE-SU-2025:03268-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.6.0-150600.4.21.1 | SUSE-SU-2025:03198-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.6.0-150600.4.21.1 | SUSE-SU-2026:0903-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libglib-2_0-0 | libglib-2_0-0@2.78.6-150600.4.16.1 | SUSE-SU-2026:0018-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libglib-2_0-0 | libglib-2_0-0@2.78.6-150600.4.16.1 | SUSE-SU-2026:0373-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.10.1 | SUSE-SU-2026:0309-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.10.1 | SUSE-SU-2025:03546-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.10.1 | SUSE-SU-2026:1375-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libudev1 | libudev1@254.25-150600.4.40.1 | SUSE-SU-2026:1040-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | shadow | shadow@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-controller:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | tar | tar@1.34-150000.3.34.1 | SUSE-SU-2026:1177-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | boost-license1_66_0 | boost-license1_66_0@1.66.0-12.3.1 | SUSE-SU-2025:02536-1 | none | not affected | component not present | sles |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | gpg2 | gpg2@2.4.4-150600.3.9.1 | SUSE-SU-2026:0215-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | gpg2 | gpg2@2.4.4-150600.3.9.1 | SUSE-SU-2026:0434-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libboost_thread1_66_0 | libboost_thread1_66_0@1.66.0-12.3.1 | SUSE-SU-2025:02536-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libglib-2_0-0 | libglib-2_0-0@2.78.6-150600.4.16.1 | SUSE-SU-2026:0018-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libglib-2_0-0 | libglib-2_0-0@2.78.6-150600.4.16.1 | SUSE-SU-2026:0373-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.10.1 | SUSE-SU-2026:0309-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.10.1 | SUSE-SU-2025:03546-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.10.1 | SUSE-SU-2026:1375-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | shadow | shadow@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-importer:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | tar | tar@1.34-150000.3.34.1 | SUSE-SU-2026:1177-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | gpg2 | gpg2@2.4.4-150600.3.9.1 | SUSE-SU-2026:0215-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | gpg2 | gpg2@2.4.4-150600.3.9.1 | SUSE-SU-2026:0434-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libboost_system1_66_0 | libboost_system1_66_0@1.66.0-12.3.1 | SUSE-SU-2025:02536-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libbrotlicommon1 | libbrotlicommon1@1.0.7-3.3.1 | SUSE-SU-2025:03268-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libglib-2_0-0 | libglib-2_0-0@2.78.6-150600.4.16.1 | SUSE-SU-2026:0018-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libglib-2_0-0 | libglib-2_0-0@2.78.6-150600.4.16.1 | SUSE-SU-2026:0373-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libnghttp2-14 | libnghttp2-14@1.64.0-150700.1.5 | SUSE-SU-2026:1074-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.49.1-150000.3.27.1 | SUSE-SU-2025:02672-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | login_defs | login_defs@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-operator:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | tar | tar@1.34-150000.3.34.1 | SUSE-SU-2026:1177-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | boost-license1_66_0 | boost-license1_66_0@1.66.0-12.3.1 | SUSE-SU-2025:02536-1 | none | not affected | component not present | sles |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | gpg2 | gpg2@2.4.4-150600.3.9.1 | SUSE-SU-2026:0215-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | gpg2 | gpg2@2.4.4-150600.3.9.1 | SUSE-SU-2026:0434-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libbrotlidec1 | libbrotlidec1@1.0.7-3.3.1 | SUSE-SU-2025:03268-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.6.0-150600.4.21.1 | SUSE-SU-2025:03198-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.6.0-150600.4.21.1 | SUSE-SU-2026:0903-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libglib-2_0-0 | libglib-2_0-0@2.78.6-150600.4.16.1 | SUSE-SU-2026:0018-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libglib-2_0-0 | libglib-2_0-0@2.78.6-150600.4.16.1 | SUSE-SU-2026:0373-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libudev1 | libudev1@254.25-150600.4.40.1 | SUSE-SU-2026:1040-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-uploadproxy:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | tar | tar@1.34-150000.3.34.1 | SUSE-SU-2026:1177-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | gpg2 | gpg2@2.4.4-150600.3.9.1 | SUSE-SU-2026:0215-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | gpg2 | gpg2@2.4.4-150600.3.9.1 | SUSE-SU-2026:0434-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libboost_thread1_66_0 | libboost_thread1_66_0@1.66.0-12.3.1 | SUSE-SU-2025:02536-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libcap2 | libcap2@2.63-150400.3.3.1 | SUSE-SU-2026:1432-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.6.0-150600.4.21.1 | SUSE-SU-2025:03198-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libcurl4 | libcurl4@8.6.0-150600.4.21.1 | SUSE-SU-2026:0903-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libgmodule-2_0-0 | libgmodule-2_0-0@2.78.6-150600.4.16.1 | SUSE-SU-2026:0018-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libgmodule-2_0-0 | libgmodule-2_0-0@2.78.6-150600.4.16.1 | SUSE-SU-2026:0373-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libnghttp2-14 | libnghttp2-14@1.64.0-150700.1.5 | SUSE-SU-2026:1074-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | libsqlite3-0 | libsqlite3-0@3.49.1-150000.3.27.1 | SUSE-SU-2025:02672-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | login_defs | login_defs@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/cdi-uploadserver:1.62.0-150700.9.3.1 | false | Harvester v1.8.0 | tar | tar@1.34-150000.3.34.1 | SUSE-SU-2026:1177-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | bind-utils | bind-utils@9.20.18-150700.3.15.1 | SUSE-SU-2026:1351-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | gpg2 | gpg2@2.4.4-150600.3.12.1 | SUSE-SU-2026:0434-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libexpat1 | libexpat1@2.7.1-150700.3.6.1 | SUSE-SU-2026:1352-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | systemd | systemd@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/libguestfs-tools:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | tar | tar@1.34-150000.3.34.1 | SUSE-SU-2026:1177-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-api:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | curl | curl@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-api:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | gpg2 | gpg2@2.4.4-150600.3.12.1 | SUSE-SU-2026:0434-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-api:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.2.3-150700.5.24.1 | SUSE-SU-2026:1375-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-api:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | shadow | shadow@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-api:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | tar | tar@1.34-150000.3.34.1 | SUSE-SU-2026:1177-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-controller:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | gpg2 | gpg2@2.4.4-150600.3.12.1 | SUSE-SU-2026:0434-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-controller:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libudev1 | libudev1@254.27-150600.4.46.2 | SUSE-SU-2026:1040-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-controller:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | shadow | shadow@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-controller:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | tar | tar@1.34-150000.3.34.1 | SUSE-SU-2026:1177-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-handler:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | curl | curl@8.14.1-150700.7.11.1 | SUSE-SU-2026:0903-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-handler:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | gpg2 | gpg2@2.4.4-150600.3.12.1 | SUSE-SU-2026:0434-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-handler:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libexpat1 | libexpat1@2.7.1-150700.3.6.1 | SUSE-SU-2026:1352-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-handler:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | tar | tar@1.34-150000.3.34.1 | SUSE-SU-2026:1177-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | gpg2 | gpg2@2.4.4-150600.3.12.1 | SUSE-SU-2026:0434-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libexpat1 | libexpat1@2.7.1-150700.3.6.1 | SUSE-SU-2026:1352-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu-ipxe | qemu-ipxe@9.2.4-150700.3.14.1 | SUSE-SU-2026:2385-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu-seabios | qemu-seabios@9.2.41.16.3_3_g3d33c746-150700.3.14.1 | SUSE-SU-2026:2385-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | qemu-vgabios | qemu-vgabios@9.2.41.16.3_3_g3d33c746-150700.3.14.1 | SUSE-SU-2026:2385-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | systemd-container | systemd-container@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | tar | tar@1.34-150000.3.34.1 | SUSE-SU-2026:1177-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | udev | udev@254.27-150600.4.55.1 | SUSE-SU-2026:1040-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | vim-data-common | vim-data-common@9.1.1629-150500.20.38.1 | SUSE-SU-2026:1607-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | vim-data-common | vim-data-common@9.1.1629-150500.20.38.1 | SUSE-SU-2026:2236-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | vim-small | vim-small@9.1.1629-150500.20.38.1 | SUSE-SU-2026:1607-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | vim-small | vim-small@9.1.1629-150500.20.38.1 | SUSE-SU-2026:2236-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | xen-libs | xen-libs@4.20.2_04-150700.3.22.1 | SUSE-SU-2026:1093-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | xen-libs | xen-libs@4.20.2_04-150700.3.22.1 | SUSE-SU-2026:1743-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | xen-libs | xen-libs@4.20.2_04-150700.3.22.1 | SUSE-SU-2026:1998-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-launcher:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | xen-libs | xen-libs@4.20.2_04-150700.3.22.1 | SUSE-SU-2026:2364-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-operator:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | gpg2 | gpg2@2.4.4-150600.3.12.1 | SUSE-SU-2026:0434-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-operator:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-operator:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | libnghttp2-14 | libnghttp2-14@1.64.0-150700.1.5 | SUSE-SU-2026:1074-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-operator:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | login_defs | login_defs@4.8.1-150600.17.9.1 | SUSE-RU-2026:1228-1 | none | not affected | vulnerable code not in execute path | sles |
| registry.suse.com/suse/sles/15.7/virt-operator:1.7.0-150700.3.16.2 | false | Harvester v1.8.0 | tar | tar@1.34-150000.3.34.1 | SUSE-SU-2026:1177-1 | none | not affected | vulnerable code not in execute path | sles |