SUSE Rancher - K3s v1.36.5-rc2 version - CVE Scans - 2026-09-24

How to use this page

  • You can click a column header to sort by column.
  • Use the search bar below to filter the results by image (and version/tag), if the image is mirrored or made by SUSE (true/false),
    release, affected binary, vulnerable dependency (and its version), vulnerability ID (CVE, GHSA, SUSE-SU etc.), severity,
    status (if affected or not affected/false-positive), justification (for false-positives),
    vulnerability type (related to the programming language or container OS).
  • The search functionality might execute a bit slow depending on the number of vulnerabilities displayed in the page.
  • False-positive CVEs that are removed with VEX have the status as "not affected" with the severity set to "none",
    because they do not affect the binary/package/image. The justification explains why they are false-positives,
    according to the VEX statuses as explained in KB 000021573.
  • For further instructions about scanned versions, scanning frequency, tooling and false-positives, please consult the main instructions.
  • The severity (CVSS rating) of some CVEs in the portal might differ from the original severity reported by some vendors and security scanners.
    This happens, because SUSE recalculates the CVSS rating of CVEs based on criteria, like: applicability and difficulty of the issue being
    exploited in the wild; how it can actually affect the confidentiality, integrity and availability of SUSE's products etc. CVEs that had their CVSS
    severity rating changed, either decreased or increased, will have the distinctive tag '*' close to its severity.
Image Mirrored Release Binary/Package Dependency Vulnerability ID (CVE) Severity Status Justification (for status not affected) Type (language or OS)
rancher/k3s:v1.36.5-rc2-k3s1 false K3s v1.36.5-rc2 bin/k3s github.com/docker/docker@v25.0.15-0.20260325154711-d2dbc0547253+incompatible CVE-2026-33997 HIGH*Severity modified based on SUSE's CVE database and CVSS rating affected gobinary
rancher/k3s:v1.36.5-rc2-k3s1 false K3s v1.36.5-rc2 bin/containerd-shim-runc-v2 google.golang.org/grpc@v1.80.0 CVE-2026-84304 HIGH affected gobinary
rancher/k3s:v1.36.5-rc2-k3s1 false K3s v1.36.5-rc2 bin/containerd-shim-runc-v2 google.golang.org/grpc@v1.80.0 CVE-2026-84445 HIGH affected gobinary
rancher/k3s:v1.36.5-rc2-k3s1 false K3s v1.36.5-rc2 bin/containerd-shim-runc-v2 google.golang.org/grpc@v1.80.0 GHSA-hrxh-6v49-42gf HIGH affected gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 jq jq@1.8.1-r0 CVE-2026-32316 HIGH affected alpine
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis stdlib@v1.26.5 CVE-2026-33818 HIGH affected gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status stdlib@v1.26.5 CVE-2026-33818 HIGH affected gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 usr/bin/helm stdlib@v1.26.5 CVE-2026-33818 HIGH affected gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis stdlib@v1.26.5 CVE-2026-39821 HIGH affected gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status stdlib@v1.26.5 CVE-2026-39821 HIGH affected gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 usr/bin/helm stdlib@v1.26.5 CVE-2026-39821 HIGH affected gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 jq jq@1.8.1-r0 CVE-2026-40164 HIGH affected alpine
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 usr/bin/helm stdlib@v1.26.5 CVE-2026-56853 HIGH affected gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis stdlib@v1.26.5 CVE-2026-56859 HIGH affected gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 usr/bin/helm stdlib@v1.26.5 CVE-2026-56859 HIGH affected gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis stdlib@v1.26.5 CVE-2026-56862 HIGH affected gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status stdlib@v1.26.5 CVE-2026-56862 HIGH affected gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 usr/bin/helm stdlib@v1.26.5 CVE-2026-56862 HIGH affected gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis oras.land/oras-go/v2@v2.6.0 CVE-2026-85731 HIGH affected gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status oras.land/oras-go/v2@v2.6.0 CVE-2026-85731 HIGH affected gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 usr/bin/helm oras.land/oras-go/v2@v2.6.0 CVE-2026-85731 HIGH affected gobinary
rancher/local-path-provisioner:v0.0.37 false K3s v1.36.5-rc2 usr/bin/local-path-provisioner stdlib@v1.26.5 CVE-2026-33818 HIGH affected gobinary
rancher/local-path-provisioner:v0.0.37 false K3s v1.36.5-rc2 usr/bin/local-path-provisioner stdlib@v1.26.5 CVE-2026-39821 HIGH affected gobinary
rancher/local-path-provisioner:v0.0.37 false K3s v1.36.5-rc2 usr/bin/local-path-provisioner stdlib@v1.26.5 CVE-2026-56853 HIGH affected gobinary
rancher/local-path-provisioner:v0.0.37 false K3s v1.36.5-rc2 usr/bin/local-path-provisioner stdlib@v1.26.5 CVE-2026-56862 HIGH affected gobinary
rancher/mirrored-coredns-coredns:1.14.7 true K3s v1.36.5-rc2 coredns github.com/coredns/coredns@v0.0.0-20260819003913-427fc80ed9ca CVE-2023-28452 HIGH affected gobinary
rancher/mirrored-coredns-coredns:1.14.7 true K3s v1.36.5-rc2 coredns github.com/coredns/coredns@v0.0.0-20260819003913-427fc80ed9ca CVE-2025-68151 HIGH*Severity modified based on SUSE's CVE database and CVSS rating affected gobinary
rancher/mirrored-coredns-coredns:1.14.7 true K3s v1.36.5-rc2 coredns github.com/coredns/coredns@v0.0.0-20260819003913-427fc80ed9ca CVE-2026-26017 HIGH affected gobinary
rancher/mirrored-coredns-coredns:1.14.7 true K3s v1.36.5-rc2 coredns github.com/coredns/coredns@v0.0.0-20260819003913-427fc80ed9ca CVE-2026-26018 HIGH affected gobinary
rancher/mirrored-coredns-coredns:1.14.7 true K3s v1.36.5-rc2 coredns github.com/coredns/coredns@v0.0.0-20260819003913-427fc80ed9ca CVE-2026-32934 HIGH affected gobinary
rancher/mirrored-coredns-coredns:1.14.7 true K3s v1.36.5-rc2 coredns github.com/coredns/coredns@v0.0.0-20260819003913-427fc80ed9ca CVE-2026-32936 HIGH affected gobinary
rancher/mirrored-coredns-coredns:1.14.7 true K3s v1.36.5-rc2 coredns github.com/coredns/coredns@v0.0.0-20260819003913-427fc80ed9ca CVE-2026-33190 HIGH affected gobinary
rancher/mirrored-coredns-coredns:1.14.7 true K3s v1.36.5-rc2 coredns github.com/coredns/coredns@v0.0.0-20260819003913-427fc80ed9ca CVE-2026-33489 HIGH affected gobinary
rancher/mirrored-coredns-coredns:1.14.7 true K3s v1.36.5-rc2 coredns github.com/coredns/coredns@v0.0.0-20260819003913-427fc80ed9ca CVE-2026-35579 HIGH affected gobinary
rancher/mirrored-coredns-coredns:1.14.7 true K3s v1.36.5-rc2 coredns github.com/coredns/coredns@v0.0.0-20260819003913-427fc80ed9ca CVE-2026-82399 HIGH affected gobinary
rancher/mirrored-coredns-coredns:1.14.7 true K3s v1.36.5-rc2 coredns google.golang.org/grpc@v1.83.0 CVE-2026-84304 HIGH affected gobinary
rancher/mirrored-coredns-coredns:1.14.7 true K3s v1.36.5-rc2 coredns google.golang.org/grpc@v1.83.0 CVE-2026-84445 HIGH affected gobinary
rancher/mirrored-coredns-coredns:1.14.7 true K3s v1.36.5-rc2 coredns github.com/coredns/coredns@v0.0.0-20260819003913-427fc80ed9ca CVE-2026-86003 HIGH affected gobinary
rancher/mirrored-library-traefik:3.7.13 true K3s v1.36.5-rc2 libcrypto3 libcrypto3@3.5.7-r0 CVE-2026-14456 HIGH affected alpine
rancher/mirrored-library-traefik:3.7.13 true K3s v1.36.5-rc2 libssl3 libssl3@3.5.7-r0 CVE-2026-14456 HIGH affected alpine
rancher/mirrored-metrics-server:v0.9.0 true K3s v1.36.5-rc2 metrics-server stdlib@v1.26.4 CVE-2026-33818 HIGH affected gobinary
rancher/mirrored-metrics-server:v0.9.0 true K3s v1.36.5-rc2 metrics-server stdlib@v1.26.4 CVE-2026-39821 HIGH affected gobinary
rancher/mirrored-metrics-server:v0.9.0 true K3s v1.36.5-rc2 metrics-server stdlib@v1.26.4 CVE-2026-56853 HIGH affected gobinary
rancher/mirrored-metrics-server:v0.9.0 true K3s v1.36.5-rc2 metrics-server golang.org/x/crypto@v0.53.0 CVE-2026-56854 HIGH affected gobinary
rancher/mirrored-metrics-server:v0.9.0 true K3s v1.36.5-rc2 metrics-server golang.org/x/crypto@v0.53.0 CVE-2026-56855 HIGH*Severity modified based on SUSE's CVE database and CVSS rating affected gobinary
rancher/mirrored-metrics-server:v0.9.0 true K3s v1.36.5-rc2 metrics-server stdlib@v1.26.4 CVE-2026-56859 HIGH affected gobinary
rancher/mirrored-metrics-server:v0.9.0 true K3s v1.36.5-rc2 metrics-server stdlib@v1.26.4 CVE-2026-56862 HIGH affected gobinary
rancher/mirrored-metrics-server:v0.9.0 true K3s v1.36.5-rc2 metrics-server golang.org/x/crypto@v0.53.0 CVE-2026-78662 HIGH*Severity modified based on SUSE's CVE database and CVSS rating affected gobinary
rancher/mirrored-metrics-server:v0.9.0 true K3s v1.36.5-rc2 metrics-server google.golang.org/grpc@v1.81.1 CVE-2026-84304 HIGH affected gobinary
rancher/mirrored-metrics-server:v0.9.0 true K3s v1.36.5-rc2 metrics-server google.golang.org/grpc@v1.81.1 CVE-2026-84445 HIGH affected gobinary
rancher/mirrored-metrics-server:v0.9.0 true K3s v1.36.5-rc2 metrics-server google.golang.org/grpc@v1.81.1 GHSA-hrxh-6v49-42gf HIGH affected gobinary
rancher/k3s:v1.36.5-rc2-k3s1 false K3s v1.36.5-rc2 bin/runc golang.org/x/net@v0.43.0 CVE-2026-25681 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.5-rc2-k3s1 false K3s v1.36.5-rc2 bin/runc golang.org/x/net@v0.43.0 CVE-2026-27136 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.5-rc2-k3s1 false K3s v1.36.5-rc2 bin/runc golang.org/x/net@v0.43.0 CVE-2026-33814 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.5-rc2-k3s1 false K3s v1.36.5-rc2 bin/runc golang.org/x/net@v0.43.0 CVE-2026-39821 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.5-rc2-k3s1 false K3s v1.36.5-rc2 bin/k3s golang.org/x/crypto@v0.47.0 CVE-2026-39828 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.5-rc2-k3s1 false K3s v1.36.5-rc2 bin/k3s golang.org/x/crypto@v0.47.0 CVE-2026-39829 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.5-rc2-k3s1 false K3s v1.36.5-rc2 bin/k3s golang.org/x/crypto@v0.47.0 CVE-2026-39830 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.5-rc2-k3s1 false K3s v1.36.5-rc2 bin/k3s golang.org/x/crypto@v0.47.0 CVE-2026-39831 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.5-rc2-k3s1 false K3s v1.36.5-rc2 bin/k3s golang.org/x/crypto@v0.47.0 CVE-2026-39832 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.5-rc2-k3s1 false K3s v1.36.5-rc2 bin/k3s golang.org/x/crypto@v0.47.0 CVE-2026-39835 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.5-rc2-k3s1 false K3s v1.36.5-rc2 bin/k3s github.com/docker/docker@v25.0.15-0.20260325154711-d2dbc0547253+incompatible CVE-2026-41567 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.5-rc2-k3s1 false K3s v1.36.5-rc2 bin/k3s github.com/docker/docker@v25.0.15-0.20260325154711-d2dbc0547253+incompatible CVE-2026-42306 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.5-rc2-k3s1 false K3s v1.36.5-rc2 bin/k3s golang.org/x/crypto@v0.47.0 CVE-2026-42508 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.5-rc2-k3s1 false K3s v1.36.5-rc2 bin/k3s golang.org/x/crypto@v0.47.0 CVE-2026-46595 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.5-rc2-k3s1 false K3s v1.36.5-rc2 bin/k3s golang.org/x/crypto@v0.47.0 CVE-2026-46597 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.5-rc2-k3s1 false K3s v1.36.5-rc2 bin/runc golang.org/x/net@v0.43.0 CVE-2026-46600 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.5-rc2-k3s1 false K3s v1.36.5-rc2 bin/containerd-shim-runc-v2 golang.org/x/net@v0.55.0 CVE-2026-46600 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.5-rc2-k3s1 false K3s v1.36.5-rc2 bin/k3s golang.org/x/net@v0.55.0 CVE-2026-46600 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.5-rc2-k3s1 false K3s v1.36.5-rc2 bin/containerd-shim-runc-v2 golang.org/x/text@v0.38.0 CVE-2026-56852 none not affected vulnerable code not in execute path gobinary
rancher/k3s:v1.36.5-rc2-k3s1 false K3s v1.36.5-rc2 bin/k3s golang.org/x/crypto@v0.47.0 CVE-2026-56854 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.5-rc2-k3s1 false K3s v1.36.5-rc2 bin/k3s golang.org/x/mod@v0.38.0 CVE-2026-56864 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.5-rc2-k3s1 false K3s v1.36.5-rc2 bin/k3s golang.org/x/mod@v0.38.0 CVE-2026-56865 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.51.0 CVE-2026-39828 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.51.0 CVE-2026-39828 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 usr/bin/helm golang.org/x/crypto@v0.51.0 CVE-2026-39828 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.51.0 CVE-2026-39829 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.51.0 CVE-2026-39829 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 usr/bin/helm golang.org/x/crypto@v0.51.0 CVE-2026-39829 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.51.0 CVE-2026-39830 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.51.0 CVE-2026-39830 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 usr/bin/helm golang.org/x/crypto@v0.51.0 CVE-2026-39830 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.51.0 CVE-2026-39831 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.51.0 CVE-2026-39831 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 usr/bin/helm golang.org/x/crypto@v0.51.0 CVE-2026-39831 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.51.0 CVE-2026-39832 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.51.0 CVE-2026-39832 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 usr/bin/helm golang.org/x/crypto@v0.51.0 CVE-2026-39832 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.51.0 CVE-2026-39835 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.51.0 CVE-2026-39835 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 usr/bin/helm golang.org/x/crypto@v0.51.0 CVE-2026-39835 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.51.0 CVE-2026-42508 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.51.0 CVE-2026-42508 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 usr/bin/helm golang.org/x/crypto@v0.51.0 CVE-2026-42508 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.51.0 CVE-2026-46595 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.51.0 CVE-2026-46595 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 usr/bin/helm golang.org/x/crypto@v0.51.0 CVE-2026-46595 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.51.0 CVE-2026-46597 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.51.0 CVE-2026-46597 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 usr/bin/helm golang.org/x/crypto@v0.51.0 CVE-2026-46597 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/net@v0.55.0 CVE-2026-46600 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status stdlib@v1.26.5 CVE-2026-46600 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 usr/bin/helm stdlib@v1.26.5 CVE-2026-46600 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis oras.land/oras-go/v2@v2.6.0 CVE-2026-50151 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status oras.land/oras-go/v2@v2.6.0 CVE-2026-50151 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 usr/bin/helm oras.land/oras-go/v2@v2.6.0 CVE-2026-50151 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis oras.land/oras-go/v2@v2.6.0 CVE-2026-50163 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status oras.land/oras-go/v2@v2.6.0 CVE-2026-50163 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 usr/bin/helm oras.land/oras-go/v2@v2.6.0 CVE-2026-50163 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/text@v0.37.0 CVE-2026-56852 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis stdlib@v1.26.5 CVE-2026-56853 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status stdlib@v1.26.5 CVE-2026-56853 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.51.0 CVE-2026-56854 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.51.0 CVE-2026-56854 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 usr/bin/helm golang.org/x/crypto@v0.51.0 CVE-2026-56854 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis stdlib@v1.26.5 CVE-2026-56858 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status stdlib@v1.26.5 CVE-2026-56858 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status stdlib@v1.26.5 CVE-2026-56859 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/mod@v0.35.0 CVE-2026-56864 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false K3s v1.36.5-rc2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/mod@v0.35.0 CVE-2026-56865 none not affected vulnerable code not present gobinary
rancher/local-path-provisioner:v0.0.37 false K3s v1.36.5-rc2 usr/bin/local-path-provisioner stdlib@v1.26.5 CVE-2026-46600 none not affected vulnerable code not in execute path gobinary
rancher/local-path-provisioner:v0.0.37 false K3s v1.36.5-rc2 usr/bin/local-path-provisioner stdlib@v1.26.5 CVE-2026-56858 none not affected vulnerable code not present gobinary
rancher/local-path-provisioner:v0.0.37 false K3s v1.36.5-rc2 usr/bin/local-path-provisioner stdlib@v1.26.5 CVE-2026-56859 none not affected vulnerable code not in execute path gobinary
rancher/mirrored-coredns-coredns:1.14.7 true K3s v1.36.5-rc2 coredns golang.org/x/crypto@v0.54.0 CVE-2026-56854 none not affected vulnerable code not present gobinary
rancher/mirrored-coredns-coredns:1.14.7 true K3s v1.36.5-rc2 coredns golang.org/x/mod@v0.37.0 CVE-2026-56864 none not affected vulnerable code not present gobinary
rancher/mirrored-coredns-coredns:1.14.7 true K3s v1.36.5-rc2 coredns golang.org/x/mod@v0.37.0 CVE-2026-56865 none not affected vulnerable code not present gobinary
rancher/mirrored-metrics-server:v0.9.0 true K3s v1.36.5-rc2 metrics-server stdlib@v1.26.4 CVE-2026-39822 none not affected vulnerable code not in execute path gobinary