SUSE Rancher - K3s v1.35.4-rc1 version - CVE Scans - 2026-04-17

How to use this page

Search:

Image Mirrored Release Binary/Package Dependency Vulnerability ID (CVE) Severity Status Justification (for status not affected) Type (language or OS)
rancher/k3s:v1.35.4-rc1-k3s1 false K3s v1.35.4-rc1 bin/k3s github.com/docker/docker@v25.0.15-0.20260325154711-d2dbc0547253+incompatible CVE-2026-34040 HIGH affected gobinary
rancher/k3s:v1.35.4-rc1-k3s1 false K3s v1.35.4-rc1 bin/k3s google.golang.org/grpc@v1.72.2 CVE-2026-33186
HIGH*Severity modified based on SUSE's CVE database and CVSS rating
affected gobinary
rancher/klipper-helm:v0.9.15-build20260324 false K3s v1.35.4-rc1 libcrypto3 libcrypto3@3.5.5-r0 CVE-2026-28390 HIGH affected alpine
rancher/klipper-helm:v0.9.15-build20260324 false K3s v1.35.4-rc1 libssl3 libssl3@3.5.5-r0 CVE-2026-28390 HIGH affected alpine
rancher/klipper-helm:v0.9.15-build20260324 false K3s v1.35.4-rc1 musl musl@1.2.5-r21 CVE-2026-40200 HIGH affected alpine
rancher/klipper-helm:v0.9.15-build20260324 false K3s v1.35.4-rc1 musl-utils musl-utils@1.2.5-r21 CVE-2026-40200 HIGH affected alpine
rancher/klipper-helm:v0.9.15-build20260324 false K3s v1.35.4-rc1 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis google.golang.org/grpc@v1.72.2 CVE-2026-33186
HIGH*Severity modified based on SUSE's CVE database and CVSS rating
affected gobinary
rancher/klipper-helm:v0.9.15-build20260324 false K3s v1.35.4-rc1 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis stdlib@v1.25.8 CVE-2026-32280 HIGH affected gobinary
rancher/klipper-helm:v0.9.15-build20260324 false K3s v1.35.4-rc1 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status stdlib@v1.25.8 CVE-2026-32280 HIGH affected gobinary
rancher/klipper-helm:v0.9.15-build20260324 false K3s v1.35.4-rc1 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status stdlib@v1.25.8 CVE-2026-32282
MEDIUM*Severity modified based on SUSE's CVE database and CVSS rating
affected gobinary
rancher/klipper-helm:v0.9.15-build20260324 false K3s v1.35.4-rc1 usr/bin/helm stdlib@v1.25.8 CVE-2026-32280 HIGH affected gobinary
rancher/klipper-lb:v0.4.15 false K3s v1.35.4-rc1 libcrypto3 libcrypto3@3.5.5-r0 CVE-2026-28390 HIGH affected alpine
rancher/klipper-lb:v0.4.15 false K3s v1.35.4-rc1 libssl3 libssl3@3.5.5-r0 CVE-2026-28390 HIGH affected alpine
rancher/klipper-lb:v0.4.15 false K3s v1.35.4-rc1 musl musl@1.2.5-r21 CVE-2026-40200 HIGH affected alpine
rancher/klipper-lb:v0.4.15 false K3s v1.35.4-rc1 musl-utils musl-utils@1.2.5-r21 CVE-2026-40200 HIGH affected alpine
rancher/local-path-provisioner:v0.0.35 false K3s v1.35.4-rc1 libcrypto3 libcrypto3@3.5.5-r0 CVE-2026-28390 HIGH affected alpine
rancher/local-path-provisioner:v0.0.35 false K3s v1.35.4-rc1 libssl3 libssl3@3.5.5-r0 CVE-2026-28390 HIGH affected alpine
rancher/local-path-provisioner:v0.0.35 false K3s v1.35.4-rc1 musl musl@1.2.5-r21 CVE-2026-40200 HIGH affected alpine
rancher/local-path-provisioner:v0.0.35 false K3s v1.35.4-rc1 musl-utils musl-utils@1.2.5-r21 CVE-2026-40200 HIGH affected alpine
rancher/local-path-provisioner:v0.0.35 false K3s v1.35.4-rc1 usr/bin/local-path-provisioner stdlib@v1.26.1 CVE-2026-32280 HIGH affected gobinary
rancher/local-path-provisioner:v0.0.35 false K3s v1.35.4-rc1 usr/bin/local-path-provisioner stdlib@v1.26.1 CVE-2026-33810
MEDIUM*Severity modified based on SUSE's CVE database and CVSS rating
affected gobinary
rancher/mirrored-coredns-coredns:1.14.2 true K3s v1.35.4-rc1 coredns github.com/coredns/coredns@v0.0.0-20260306044945-dd1df4f5db93 CVE-2023-28452 HIGH affected gobinary
rancher/mirrored-coredns-coredns:1.14.2 true K3s v1.35.4-rc1 coredns github.com/coredns/coredns@v0.0.0-20260306044945-dd1df4f5db93 CVE-2025-47950
MEDIUM*Severity modified based on SUSE's CVE database and CVSS rating
affected gobinary
rancher/mirrored-coredns-coredns:1.14.2 true K3s v1.35.4-rc1 coredns github.com/coredns/coredns@v0.0.0-20260306044945-dd1df4f5db93 CVE-2026-26017 HIGH affected gobinary
rancher/mirrored-coredns-coredns:1.14.2 true K3s v1.35.4-rc1 coredns github.com/coredns/coredns@v0.0.0-20260306044945-dd1df4f5db93 CVE-2026-26018 HIGH affected gobinary
rancher/mirrored-coredns-coredns:1.14.2 true K3s v1.35.4-rc1 coredns github.com/coredns/coredns@v0.0.0-20260306044945-dd1df4f5db93 CVE-2025-68151
HIGH*Severity modified based on SUSE's CVE database and CVSS rating
affected gobinary
rancher/mirrored-coredns-coredns:1.14.2 true K3s v1.35.4-rc1 coredns google.golang.org/grpc@v1.79.1 CVE-2026-33186
HIGH*Severity modified based on SUSE's CVE database and CVSS rating
affected gobinary
rancher/mirrored-coredns-coredns:1.14.2 true K3s v1.35.4-rc1 coredns stdlib@v1.26.1 CVE-2026-32280 HIGH affected gobinary
rancher/mirrored-coredns-coredns:1.14.2 true K3s v1.35.4-rc1 coredns stdlib@v1.26.1 CVE-2026-33810
MEDIUM*Severity modified based on SUSE's CVE database and CVSS rating
affected gobinary
rancher/mirrored-library-traefik:3.6.12 true K3s v1.35.4-rc1 libcrypto3 libcrypto3@3.5.5-r0 CVE-2026-28390 HIGH affected alpine
rancher/mirrored-library-traefik:3.6.12 true K3s v1.35.4-rc1 libssl3 libssl3@3.5.5-r0 CVE-2026-28390 HIGH affected alpine
rancher/mirrored-library-traefik:3.6.12 true K3s v1.35.4-rc1 musl musl@1.2.5-r21 CVE-2026-40200 HIGH affected alpine
rancher/mirrored-library-traefik:3.6.12 true K3s v1.35.4-rc1 musl-utils musl-utils@1.2.5-r21 CVE-2026-40200 HIGH affected alpine
rancher/mirrored-library-traefik:3.6.12 true K3s v1.35.4-rc1 usr/local/bin/traefik github.com/docker/docker@v28.5.2+incompatible CVE-2026-34040 HIGH affected gobinary
rancher/mirrored-library-traefik:3.6.12 true K3s v1.35.4-rc1 usr/local/bin/traefik github.com/go-jose/go-jose/v4@v4.1.3 CVE-2026-34986 HIGH affected gobinary
rancher/mirrored-library-traefik:3.6.12 true K3s v1.35.4-rc1 usr/local/bin/traefik stdlib@v1.25.8 CVE-2026-32280 HIGH affected gobinary
rancher/mirrored-metrics-server:v0.8.1 true K3s v1.35.4-rc1 metrics-server stdlib@v1.24.12 CVE-2025-68121
HIGH*Severity modified based on SUSE's CVE database and CVSS rating
affected gobinary
rancher/mirrored-metrics-server:v0.8.1 true K3s v1.35.4-rc1 metrics-server stdlib@v1.24.12 CVE-2026-25679
LOW*Severity modified based on SUSE's CVE database and CVSS rating
affected gobinary
rancher/mirrored-metrics-server:v0.8.1 true K3s v1.35.4-rc1 metrics-server stdlib@v1.24.12 CVE-2026-32280 HIGH affected gobinary
rancher/k3s:v1.35.4-rc1-k3s1 false K3s v1.35.4-rc1 bin/containerd-shim-runc-v2 google.golang.org/grpc@v1.78.0 CVE-2026-33186 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.9.15-build20260324 false K3s v1.35.4-rc1 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis stdlib@v1.25.8 CVE-2026-32282 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.9.15-build20260324 false K3s v1.35.4-rc1 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis stdlib@v1.25.8 CVE-2026-32288 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.9.15-build20260324 false K3s v1.35.4-rc1 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis stdlib@v1.25.8 CVE-2026-32289 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.9.15-build20260324 false K3s v1.35.4-rc1 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status google.golang.org/grpc@v1.72.2 CVE-2026-33186 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.9.15-build20260324 false K3s v1.35.4-rc1 usr/bin/helm google.golang.org/grpc@v1.72.2 CVE-2026-33186 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.9.15-build20260324 false K3s v1.35.4-rc1 usr/bin/helm stdlib@v1.25.8 CVE-2026-32282 none not affected vulnerable code not in execute path gobinary
rancher/local-path-provisioner:v0.0.35 false K3s v1.35.4-rc1 usr/bin/local-path-provisioner stdlib@v1.26.1 CVE-2026-32282 none not affected vulnerable code not in execute path gobinary
rancher/local-path-provisioner:v0.0.35 false K3s v1.35.4-rc1 usr/bin/local-path-provisioner stdlib@v1.26.1 CVE-2026-32288 none not affected vulnerable code not present gobinary
rancher/local-path-provisioner:v0.0.35 false K3s v1.35.4-rc1 usr/bin/local-path-provisioner stdlib@v1.26.1 CVE-2026-32289 none not affected vulnerable code not present gobinary
rancher/mirrored-coredns-coredns:1.14.2 true K3s v1.35.4-rc1 coredns go.opentelemetry.io/otel/sdk@v1.40.0 CVE-2026-39883 none not affected vulnerable code not present gobinary
rancher/mirrored-coredns-coredns:1.14.2 true K3s v1.35.4-rc1 coredns stdlib@v1.26.1 CVE-2026-32282 none not affected vulnerable code not in execute path gobinary
rancher/mirrored-library-traefik:3.6.12 true K3s v1.35.4-rc1 zlib zlib@1.3.1-r2 CVE-2026-22184 none not affected vulnerable code not present alpine
rancher/mirrored-library-traefik:3.6.12 true K3s v1.35.4-rc1 usr/local/bin/traefik go.opentelemetry.io/otel/sdk@v1.41.0 CVE-2026-39883 none not affected vulnerable code not present gobinary
rancher/mirrored-library-traefik:3.6.12 true K3s v1.35.4-rc1 usr/local/bin/traefik stdlib@v1.25.8 CVE-2026-32282 none not affected vulnerable code not in execute path gobinary
rancher/mirrored-library-traefik:3.6.12 true K3s v1.35.4-rc1 usr/local/bin/traefik stdlib@v1.25.8 CVE-2026-32288 none not affected vulnerable code not in execute path gobinary
rancher/mirrored-metrics-server:v0.8.1 true K3s v1.35.4-rc1 metrics-server go.opentelemetry.io/otel/sdk@v1.35.0 CVE-2026-24051 none not affected vulnerable code not present gobinary
rancher/mirrored-metrics-server:v0.8.1 true K3s v1.35.4-rc1 metrics-server go.opentelemetry.io/otel/sdk@v1.35.0 CVE-2026-39883 none not affected vulnerable code not present gobinary
rancher/mirrored-metrics-server:v0.8.1 true K3s v1.35.4-rc1 metrics-server golang.org/x/crypto@v0.38.0 CVE-2025-47914 none not affected vulnerable code not present gobinary
rancher/mirrored-metrics-server:v0.8.1 true K3s v1.35.4-rc1 metrics-server golang.org/x/crypto@v0.38.0 CVE-2025-58181 none not affected vulnerable code not present gobinary
rancher/mirrored-metrics-server:v0.8.1 true K3s v1.35.4-rc1 metrics-server google.golang.org/grpc@v1.72.0 CVE-2026-33186 none not affected vulnerable code not in execute path gobinary
rancher/mirrored-metrics-server:v0.8.1 true K3s v1.35.4-rc1 metrics-server stdlib@v1.24.12 CVE-2026-32282 none not affected vulnerable code not in execute path gobinary
rancher/mirrored-metrics-server:v0.8.1 true K3s v1.35.4-rc1 metrics-server stdlib@v1.24.12 CVE-2026-32288 none not affected vulnerable code not present gobinary