SUSE Rancher - Longhorn master version - CVE Scans - 2026-09-11

How to use this page

  • You can click a column header to sort by column.
  • Use the search bar below to filter the results by image (and version/tag), if the image is mirrored or made by SUSE (true/false),
    release, affected binary, vulnerable dependency (and its version), vulnerability ID (CVE, GHSA, SUSE-SU etc.), severity,
    status (if affected or not affected/false-positive), justification (for false-positives),
    vulnerability type (related to the programming language or container OS).
  • The search functionality might execute a bit slow depending on the number of vulnerabilities displayed in the page.
  • False-positive CVEs that are removed with VEX have the status as "not affected" with the severity set to "none",
    because they do not affect the binary/package/image. The justification explains why they are false-positives,
    according to the VEX statuses as explained in KB 000021573.
  • For further instructions about scanned versions, scanning frequency, tooling and false-positives, please consult the main instructions.
  • The severity (CVSS rating) of some CVEs in the portal might differ from the original severity reported by some vendors and security scanners.
    This happens, because SUSE recalculates the CVSS rating of CVEs based on criteria, like: applicability and difficulty of the issue being
    exploited in the wild; how it can actually affect the confidentiality, integrity and availability of SUSE's products etc. CVEs that had their CVSS
    severity rating changed, either decreased or increased, will have the distinctive tag '*' close to its severity.
Image Mirrored Release Binary/Package Dependency Vulnerability ID (CVE) Severity Status Justification (for status not affected) Type (language or OS)
longhornio/csi-attacher:v4.12.0 false Longhorn master csi-attacher stdlib@v1.26.3 CVE-2026-33818 HIGH affected gobinary
longhornio/csi-attacher:v4.12.0 false Longhorn master csi-attacher golang.org/x/net@v0.54.0 CVE-2026-39821 HIGH affected gobinary
longhornio/csi-attacher:v4.12.0 false Longhorn master csi-attacher stdlib@v1.26.3 CVE-2026-39821 HIGH affected gobinary
longhornio/csi-attacher:v4.12.0 false Longhorn master csi-attacher stdlib@v1.26.3 CVE-2026-56853 HIGH affected gobinary
longhornio/csi-attacher:v4.12.0 false Longhorn master csi-attacher stdlib@v1.26.3 CVE-2026-56859 HIGH affected gobinary
longhornio/csi-attacher:v4.12.0 false Longhorn master csi-attacher stdlib@v1.26.3 CVE-2026-56862 HIGH affected gobinary
longhornio/csi-attacher:v4.12.0 false Longhorn master csi-attacher google.golang.org/grpc@v1.81.1 CVE-2026-84303 CRITICAL*Severity modified based on SUSE's CVE database and CVSS rating affected gobinary
longhornio/csi-attacher:v4.12.0 false Longhorn master csi-attacher google.golang.org/grpc@v1.81.1 CVE-2026-84304 HIGH affected gobinary
longhornio/csi-attacher:v4.12.0 false Longhorn master csi-attacher google.golang.org/grpc@v1.81.1 CVE-2026-84445 HIGH affected gobinary
longhornio/csi-attacher:v4.12.0 false Longhorn master csi-attacher google.golang.org/grpc@v1.81.1 GHSA-hrxh-6v49-42gf HIGH affected gobinary
longhornio/csi-node-driver-registrar:v2.17.0 false Longhorn master csi-node-driver-registrar stdlib@v1.26.3 CVE-2026-33818 HIGH affected gobinary
longhornio/csi-node-driver-registrar:v2.17.0 false Longhorn master csi-node-driver-registrar stdlib@v1.26.3 CVE-2026-39821 HIGH affected gobinary
longhornio/csi-node-driver-registrar:v2.17.0 false Longhorn master csi-node-driver-registrar stdlib@v1.26.3 CVE-2026-56853 HIGH affected gobinary
longhornio/csi-node-driver-registrar:v2.17.0 false Longhorn master csi-node-driver-registrar stdlib@v1.26.3 CVE-2026-56862 HIGH affected gobinary
longhornio/csi-node-driver-registrar:v2.17.0 false Longhorn master csi-node-driver-registrar google.golang.org/grpc@v1.81.1 CVE-2026-84303 CRITICAL*Severity modified based on SUSE's CVE database and CVSS rating affected gobinary
longhornio/csi-node-driver-registrar:v2.17.0 false Longhorn master csi-node-driver-registrar google.golang.org/grpc@v1.81.1 CVE-2026-84304 HIGH affected gobinary
longhornio/csi-node-driver-registrar:v2.17.0 false Longhorn master csi-node-driver-registrar google.golang.org/grpc@v1.81.1 CVE-2026-84445 HIGH affected gobinary
longhornio/csi-node-driver-registrar:v2.17.0 false Longhorn master csi-node-driver-registrar google.golang.org/grpc@v1.81.1 GHSA-hrxh-6v49-42gf HIGH affected gobinary
longhornio/csi-provisioner:v6.3.0 false Longhorn master csi-provisioner stdlib@v1.26.3 CVE-2026-33818 HIGH affected gobinary
longhornio/csi-provisioner:v6.3.0 false Longhorn master csi-provisioner stdlib@v1.26.3 CVE-2026-39821 HIGH affected gobinary
longhornio/csi-provisioner:v6.3.0 false Longhorn master csi-provisioner stdlib@v1.26.3 CVE-2026-56853 HIGH affected gobinary
longhornio/csi-provisioner:v6.3.0 false Longhorn master csi-provisioner stdlib@v1.26.3 CVE-2026-56859 HIGH affected gobinary
longhornio/csi-provisioner:v6.3.0 false Longhorn master csi-provisioner stdlib@v1.26.3 CVE-2026-56862 HIGH affected gobinary
longhornio/csi-provisioner:v6.3.0 false Longhorn master csi-provisioner google.golang.org/grpc@v1.81.1 CVE-2026-84303 CRITICAL*Severity modified based on SUSE's CVE database and CVSS rating affected gobinary
longhornio/csi-provisioner:v6.3.0 false Longhorn master csi-provisioner google.golang.org/grpc@v1.81.1 CVE-2026-84304 HIGH affected gobinary
longhornio/csi-provisioner:v6.3.0 false Longhorn master csi-provisioner google.golang.org/grpc@v1.81.1 CVE-2026-84445 HIGH affected gobinary
longhornio/csi-provisioner:v6.3.0 false Longhorn master csi-provisioner google.golang.org/grpc@v1.81.1 GHSA-hrxh-6v49-42gf HIGH affected gobinary
longhornio/csi-resizer:v2.2.1 false Longhorn master csi-resizer stdlib@v1.26.3 CVE-2026-33818 HIGH affected gobinary
longhornio/csi-resizer:v2.2.1 false Longhorn master csi-resizer stdlib@v1.26.3 CVE-2026-39821 HIGH affected gobinary
longhornio/csi-resizer:v2.2.1 false Longhorn master csi-resizer stdlib@v1.26.3 CVE-2026-56853 HIGH affected gobinary
longhornio/csi-resizer:v2.2.1 false Longhorn master csi-resizer stdlib@v1.26.3 CVE-2026-56859 HIGH affected gobinary
longhornio/csi-resizer:v2.2.1 false Longhorn master csi-resizer stdlib@v1.26.3 CVE-2026-56862 HIGH affected gobinary
longhornio/csi-resizer:v2.2.1 false Longhorn master csi-resizer google.golang.org/grpc@v1.79.3 CVE-2026-84303 CRITICAL*Severity modified based on SUSE's CVE database and CVSS rating affected gobinary
longhornio/csi-resizer:v2.2.1 false Longhorn master csi-resizer google.golang.org/grpc@v1.79.3 CVE-2026-84304 HIGH affected gobinary
longhornio/csi-resizer:v2.2.1 false Longhorn master csi-resizer google.golang.org/grpc@v1.79.3 CVE-2026-84445 HIGH affected gobinary
longhornio/csi-resizer:v2.2.1 false Longhorn master csi-resizer google.golang.org/grpc@v1.79.3 GHSA-hrxh-6v49-42gf HIGH affected gobinary
longhornio/csi-snapshotter:v8.6.0 false Longhorn master csi-snapshotter stdlib@v1.26.3 CVE-2026-33818 HIGH affected gobinary
longhornio/csi-snapshotter:v8.6.0 false Longhorn master csi-snapshotter golang.org/x/net@v0.54.0 CVE-2026-39821 HIGH affected gobinary
longhornio/csi-snapshotter:v8.6.0 false Longhorn master csi-snapshotter stdlib@v1.26.3 CVE-2026-39821 HIGH affected gobinary
longhornio/csi-snapshotter:v8.6.0 false Longhorn master csi-snapshotter stdlib@v1.26.3 CVE-2026-56853 HIGH affected gobinary
longhornio/csi-snapshotter:v8.6.0 false Longhorn master csi-snapshotter stdlib@v1.26.3 CVE-2026-56859 HIGH affected gobinary
longhornio/csi-snapshotter:v8.6.0 false Longhorn master csi-snapshotter stdlib@v1.26.3 CVE-2026-56862 HIGH affected gobinary
longhornio/csi-snapshotter:v8.6.0 false Longhorn master csi-snapshotter google.golang.org/grpc@v1.81.1 CVE-2026-84303 CRITICAL*Severity modified based on SUSE's CVE database and CVSS rating affected gobinary
longhornio/csi-snapshotter:v8.6.0 false Longhorn master csi-snapshotter google.golang.org/grpc@v1.81.1 CVE-2026-84304 HIGH affected gobinary
longhornio/csi-snapshotter:v8.6.0 false Longhorn master csi-snapshotter google.golang.org/grpc@v1.81.1 CVE-2026-84445 HIGH affected gobinary
longhornio/csi-snapshotter:v8.6.0 false Longhorn master csi-snapshotter google.golang.org/grpc@v1.81.1 GHSA-hrxh-6v49-42gf HIGH affected gobinary
longhornio/livenessprobe:v2.19.0 false Longhorn master livenessprobe stdlib@v1.26.3 CVE-2026-33818 HIGH affected gobinary
longhornio/livenessprobe:v2.19.0 false Longhorn master livenessprobe stdlib@v1.26.3 CVE-2026-39821 HIGH affected gobinary
longhornio/livenessprobe:v2.19.0 false Longhorn master livenessprobe stdlib@v1.26.3 CVE-2026-56853 HIGH affected gobinary
longhornio/livenessprobe:v2.19.0 false Longhorn master livenessprobe stdlib@v1.26.3 CVE-2026-56862 HIGH affected gobinary
longhornio/livenessprobe:v2.19.0 false Longhorn master livenessprobe google.golang.org/grpc@v1.81.1 CVE-2026-84303 CRITICAL*Severity modified based on SUSE's CVE database and CVSS rating affected gobinary
longhornio/livenessprobe:v2.19.0 false Longhorn master livenessprobe google.golang.org/grpc@v1.81.1 CVE-2026-84304 HIGH affected gobinary
longhornio/livenessprobe:v2.19.0 false Longhorn master livenessprobe google.golang.org/grpc@v1.81.1 CVE-2026-84445 HIGH affected gobinary
longhornio/livenessprobe:v2.19.0 false Longhorn master livenessprobe google.golang.org/grpc@v1.81.1 GHSA-hrxh-6v49-42gf HIGH affected gobinary
longhornio/longhorn-cli:master-head false Longhorn master usr/local/bin/longhornctl-local google.golang.org/grpc@v1.83.1 CVE-2026-84445 HIGH affected gobinary
longhornio/support-bundle-kit:v0.0.93 false Longhorn master usr/bin/support-bundle-kit google.golang.org/grpc@v1.82.1 CVE-2026-84303 CRITICAL*Severity modified based on SUSE's CVE database and CVSS rating affected gobinary
longhornio/support-bundle-kit:v0.0.93 false Longhorn master usr/bin/support-bundle-kit google.golang.org/grpc@v1.82.1 CVE-2026-84304 HIGH affected gobinary
longhornio/support-bundle-kit:v0.0.93 false Longhorn master usr/bin/support-bundle-kit google.golang.org/grpc@v1.82.1 CVE-2026-84445 HIGH affected gobinary
longhornio/support-bundle-kit:v0.0.93 false Longhorn master openssl openssl@3.2.3-150700.1.1 SUSE-SU-2026:3835-1 HIGH affected sles
longhornio/support-bundle-kit:v0.0.93 false Longhorn master openssl-3 openssl-3@3.2.3-150700.5.40.1 SUSE-SU-2026:3835-1 HIGH affected sles
longhornio/csi-attacher:v4.12.0 false Longhorn master csi-attacher golang.org/x/net@v0.54.0 CVE-2026-25681 none not affected vulnerable code not present gobinary
longhornio/csi-attacher:v4.12.0 false Longhorn master csi-attacher golang.org/x/net@v0.54.0 CVE-2026-27136 none not affected vulnerable code not present gobinary
longhornio/csi-attacher:v4.12.0 false Longhorn master csi-attacher stdlib@v1.26.3 CVE-2026-27145 none not affected vulnerable code not in execute path gobinary
longhornio/csi-attacher:v4.12.0 false Longhorn master csi-attacher stdlib@v1.26.3 CVE-2026-39822 none not affected vulnerable code not in execute path gobinary
longhornio/csi-attacher:v4.12.0 false Longhorn master csi-attacher golang.org/x/crypto@v0.51.0 CVE-2026-39828 none not affected vulnerable code not present gobinary
longhornio/csi-attacher:v4.12.0 false Longhorn master csi-attacher golang.org/x/crypto@v0.51.0 CVE-2026-39829 none not affected vulnerable code not present gobinary
longhornio/csi-attacher:v4.12.0 false Longhorn master csi-attacher golang.org/x/crypto@v0.51.0 CVE-2026-39830 none not affected vulnerable code not present gobinary
longhornio/csi-attacher:v4.12.0 false Longhorn master csi-attacher golang.org/x/crypto@v0.51.0 CVE-2026-39831 none not affected vulnerable code not present gobinary
longhornio/csi-attacher:v4.12.0 false Longhorn master csi-attacher golang.org/x/crypto@v0.51.0 CVE-2026-39832 none not affected vulnerable code not present gobinary
longhornio/csi-attacher:v4.12.0 false Longhorn master csi-attacher golang.org/x/crypto@v0.51.0 CVE-2026-39835 none not affected vulnerable code not present gobinary
longhornio/csi-attacher:v4.12.0 false Longhorn master csi-attacher stdlib@v1.26.3 CVE-2026-42504 none not affected vulnerable code not in execute path gobinary
longhornio/csi-attacher:v4.12.0 false Longhorn master csi-attacher golang.org/x/crypto@v0.51.0 CVE-2026-42508 none not affected vulnerable code not present gobinary
longhornio/csi-attacher:v4.12.0 false Longhorn master csi-attacher golang.org/x/crypto@v0.51.0 CVE-2026-46595 none not affected vulnerable code not present gobinary
longhornio/csi-attacher:v4.12.0 false Longhorn master csi-attacher golang.org/x/crypto@v0.51.0 CVE-2026-46597 none not affected vulnerable code not present gobinary
longhornio/csi-attacher:v4.12.0 false Longhorn master csi-attacher golang.org/x/net@v0.54.0 CVE-2026-46600 none not affected vulnerable code not present gobinary
longhornio/csi-attacher:v4.12.0 false Longhorn master csi-attacher golang.org/x/crypto@v0.51.0 CVE-2026-56854 none not affected vulnerable code not present gobinary
longhornio/csi-node-driver-registrar:v2.17.0 false Longhorn master csi-node-driver-registrar golang.org/x/net@v0.54.0 CVE-2026-25681 none not affected vulnerable code not present gobinary
longhornio/csi-node-driver-registrar:v2.17.0 false Longhorn master csi-node-driver-registrar golang.org/x/net@v0.54.0 CVE-2026-27136 none not affected vulnerable code not present gobinary
longhornio/csi-node-driver-registrar:v2.17.0 false Longhorn master csi-node-driver-registrar stdlib@v1.26.3 CVE-2026-27145 none not affected vulnerable code not in execute path gobinary
longhornio/csi-node-driver-registrar:v2.17.0 false Longhorn master csi-node-driver-registrar golang.org/x/net@v0.54.0 CVE-2026-39821 none not affected vulnerable code not in execute path gobinary
longhornio/csi-node-driver-registrar:v2.17.0 false Longhorn master csi-node-driver-registrar stdlib@v1.26.3 CVE-2026-39822 none not affected vulnerable code not in execute path gobinary
longhornio/csi-node-driver-registrar:v2.17.0 false Longhorn master csi-node-driver-registrar stdlib@v1.26.3 CVE-2026-42504 none not affected vulnerable code not in execute path gobinary
longhornio/csi-node-driver-registrar:v2.17.0 false Longhorn master csi-node-driver-registrar golang.org/x/net@v0.54.0 CVE-2026-46600 none not affected vulnerable code not present gobinary
longhornio/csi-node-driver-registrar:v2.17.0 false Longhorn master csi-node-driver-registrar golang.org/x/text@v0.37.0 CVE-2026-56852 none not affected vulnerable code not in execute path gobinary
longhornio/csi-node-driver-registrar:v2.17.0 false Longhorn master csi-node-driver-registrar stdlib@v1.26.3 CVE-2026-56859 none not affected vulnerable code not present gobinary
longhornio/csi-provisioner:v6.3.0 false Longhorn master csi-provisioner stdlib@v1.26.3 CVE-2026-27145 none not affected vulnerable code not in execute path gobinary
longhornio/csi-provisioner:v6.3.0 false Longhorn master csi-provisioner stdlib@v1.26.3 CVE-2026-39822 none not affected vulnerable code not in execute path gobinary
longhornio/csi-provisioner:v6.3.0 false Longhorn master csi-provisioner stdlib@v1.26.3 CVE-2026-42504 none not affected vulnerable code not in execute path gobinary
longhornio/csi-provisioner:v6.3.0 false Longhorn master csi-provisioner golang.org/x/net@v0.55.0 CVE-2026-46600 none not affected vulnerable code not present gobinary
longhornio/csi-provisioner:v6.3.0 false Longhorn master csi-provisioner golang.org/x/crypto@v0.52.0 CVE-2026-56854 none not affected vulnerable code not in execute path gobinary
longhornio/csi-resizer:v2.2.1 false Longhorn master csi-resizer stdlib@v1.26.3 CVE-2026-27145 none not affected vulnerable code not in execute path gobinary
longhornio/csi-resizer:v2.2.1 false Longhorn master csi-resizer stdlib@v1.26.3 CVE-2026-39822 none not affected vulnerable code not in execute path gobinary
longhornio/csi-resizer:v2.2.1 false Longhorn master csi-resizer go.opentelemetry.io/otel/sdk@v1.40.0 CVE-2026-39883 none not affected vulnerable code not in execute path gobinary
longhornio/csi-resizer:v2.2.1 false Longhorn master csi-resizer stdlib@v1.26.3 CVE-2026-42504 none not affected vulnerable code not in execute path gobinary
longhornio/csi-resizer:v2.2.1 false Longhorn master csi-resizer golang.org/x/net@v0.55.0 CVE-2026-46600 none not affected vulnerable code not present gobinary
longhornio/csi-resizer:v2.2.1 false Longhorn master csi-resizer golang.org/x/crypto@v0.53.0 CVE-2026-56854 none not affected vulnerable code not present gobinary
longhornio/csi-snapshotter:v8.6.0 false Longhorn master csi-snapshotter golang.org/x/net@v0.54.0 CVE-2026-25681 none not affected vulnerable code not present gobinary
longhornio/csi-snapshotter:v8.6.0 false Longhorn master csi-snapshotter golang.org/x/net@v0.54.0 CVE-2026-27136 none not affected vulnerable code not present gobinary
longhornio/csi-snapshotter:v8.6.0 false Longhorn master csi-snapshotter stdlib@v1.26.3 CVE-2026-27145 none not affected vulnerable code not in execute path gobinary
longhornio/csi-snapshotter:v8.6.0 false Longhorn master csi-snapshotter stdlib@v1.26.3 CVE-2026-39822 none not affected vulnerable code not in execute path gobinary
longhornio/csi-snapshotter:v8.6.0 false Longhorn master csi-snapshotter stdlib@v1.26.3 CVE-2026-42504 none not affected vulnerable code not in execute path gobinary
longhornio/csi-snapshotter:v8.6.0 false Longhorn master csi-snapshotter golang.org/x/net@v0.54.0 CVE-2026-46600 none not affected vulnerable code not present gobinary
longhornio/csi-snapshotter:v8.6.0 false Longhorn master csi-snapshotter golang.org/x/crypto@v0.52.0 CVE-2026-56854 none not affected vulnerable code not present gobinary
longhornio/livenessprobe:v2.19.0 false Longhorn master livenessprobe golang.org/x/net@v0.54.0 CVE-2026-25681 none not affected vulnerable code not present gobinary
longhornio/livenessprobe:v2.19.0 false Longhorn master livenessprobe golang.org/x/net@v0.54.0 CVE-2026-27136 none not affected vulnerable code not present gobinary
longhornio/livenessprobe:v2.19.0 false Longhorn master livenessprobe stdlib@v1.26.3 CVE-2026-27145 none not affected vulnerable code not in execute path gobinary
longhornio/livenessprobe:v2.19.0 false Longhorn master livenessprobe golang.org/x/net@v0.54.0 CVE-2026-39821 none not affected vulnerable code not in execute path gobinary
longhornio/livenessprobe:v2.19.0 false Longhorn master livenessprobe stdlib@v1.26.3 CVE-2026-39822 none not affected vulnerable code not in execute path gobinary
longhornio/livenessprobe:v2.19.0 false Longhorn master livenessprobe stdlib@v1.26.3 CVE-2026-42504 none not affected vulnerable code not in execute path gobinary
longhornio/livenessprobe:v2.19.0 false Longhorn master livenessprobe golang.org/x/net@v0.54.0 CVE-2026-46600 none not affected vulnerable code not present gobinary
longhornio/livenessprobe:v2.19.0 false Longhorn master livenessprobe golang.org/x/text@v0.37.0 CVE-2026-56852 none not affected vulnerable code not in execute path gobinary
longhornio/livenessprobe:v2.19.0 false Longhorn master livenessprobe stdlib@v1.26.3 CVE-2026-56859 none not affected vulnerable code not present gobinary
longhornio/longhorn-cli:master-head false Longhorn master usr/local/bin/longhornctl golang.org/x/crypto@v0.54.0 CVE-2026-56854 none not affected vulnerable code not in execute path gobinary
longhornio/longhorn-cli:master-head false Longhorn master usr/local/bin/longhornctl-local golang.org/x/crypto@v0.54.0 CVE-2026-56854 none not affected vulnerable code not in execute path gobinary
longhornio/support-bundle-kit:v0.0.93 false Longhorn master usr/bin/support-bundle-kit golang.org/x/crypto@v0.53.0 CVE-2026-56854 none not affected vulnerable code not present gobinary
longhornio/support-bundle-kit:v0.0.93 false Longhorn master libopenssl-3-fips-provider libopenssl-3-fips-provider@3.2.3-150700.5.40.1 SUSE-SU-2026:3835-1 none not affected vulnerable code not in execute path sles
longhornio/support-bundle-kit:v0.0.93 false Longhorn master libopenssl3 libopenssl3@3.2.3-150700.5.40.1 SUSE-SU-2026:3835-1 none not affected vulnerable code not in execute path sles