SUSE Rancher - Observability v2.9 dev version - CVE Scans - 2026-05-11

How to use this page

Search:

Image Mirrored Release Binary/Package Dependency Vulnerability ID (CVE) Severity Status Justification (for status not affected) Type (language or OS)
quay.io/stackstate/hadoop:3.4.3-java21-9-6cb836e0-release-386 false Observability v2.9 dev Java io.netty:netty-codec-dns@4.1.127.Final CVE-2026-42579 HIGH affected jar
quay.io/stackstate/hadoop:3.4.3-java21-9-6cb836e0-release-386 false Observability v2.9 dev Java io.netty:netty-codec-dns@4.1.127.Final CVE-2026-42579 HIGH affected jar
quay.io/stackstate/hadoop:3.4.3-java21-9-6cb836e0-release-386 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.133.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/hadoop:3.4.3-java21-9-6cb836e0-release-386 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.133.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/hadoop:3.4.3-java21-9-6cb836e0-release-386 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.133.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/hadoop:3.4.3-java21-9-6cb836e0-release-386 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.133.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/hadoop:3.4.3-java21-9-6cb836e0-release-386 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.133.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/hadoop:3.4.3-java21-9-6cb836e0-release-386 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.133.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/hadoop:3.4.3-java21-9-6cb836e0-release-386 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.133.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/hadoop:3.4.3-java21-9-6cb836e0-release-386 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.133.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/hbase-master:2.5-7.14.12 false Observability v2.9 dev Java com.google.protobuf:protobuf-java@2.5.0 CVE-2021-22569 HIGH affected jar
quay.io/stackstate/hbase-master:2.5-7.14.12 false Observability v2.9 dev Java com.google.protobuf:protobuf-java@2.5.0 CVE-2024-7254 HIGH affected jar
quay.io/stackstate/hbase-master:2.5-7.14.12 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.133.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/hbase-master:2.5-7.14.12 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.133.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/hbase-master:2.5-7.14.12 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.133.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/hbase-master:2.5-7.14.12 false Observability v2.9 dev Java org.apache.thrift:libthrift@0.15.0 CVE-2026-43869 HIGH affected jar
quay.io/stackstate/hbase-regionserver:2.5-7.14.12 false Observability v2.9 dev Java com.google.protobuf:protobuf-java@2.5.0 CVE-2021-22569 HIGH affected jar
quay.io/stackstate/hbase-regionserver:2.5-7.14.12 false Observability v2.9 dev Java com.google.protobuf:protobuf-java@2.5.0 CVE-2024-7254 HIGH affected jar
quay.io/stackstate/hbase-regionserver:2.5-7.14.12 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.133.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/hbase-regionserver:2.5-7.14.12 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.133.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/hbase-regionserver:2.5-7.14.12 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.133.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/hbase-regionserver:2.5-7.14.12 false Observability v2.9 dev Java org.apache.thrift:libthrift@0.15.0 CVE-2026-43869 HIGH affected jar
quay.io/stackstate/jmx-exporter:0.20.0-58a72255-315-release false Observability v2.9 dev java-21-openjdk java-21-openjdk@21.0.10.0-150600.3.23.1 SUSE-SU-2026:1705-1 HIGH affected sles
quay.io/stackstate/jmx-exporter:0.20.0-58a72255-315-release false Observability v2.9 dev java-21-openjdk-headless java-21-openjdk-headless@21.0.10.0-150600.3.23.1 SUSE-SU-2026:1705-1 HIGH affected sles
quay.io/stackstate/kafka:3.9.2-7c9dc1f5-main-39 false Observability v2.9 dev Java io.netty:netty-codec@4.1.125.Final CVE-2026-42583 HIGH affected jar
quay.io/stackstate/kafka:3.9.2-7c9dc1f5-main-39 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.125.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/kafka:3.9.2-7c9dc1f5-main-39 false Observability v2.9 dev Java org.apache.zookeeper:zookeeper@3.8.4 CVE-2026-24281 HIGH affected jar
quay.io/stackstate/kafka:3.9.2-7c9dc1f5-main-39 false Observability v2.9 dev Java org.apache.zookeeper:zookeeper@3.8.4 CVE-2026-24308 HIGH affected jar
quay.io/stackstate/kafka:3.9.2-7c9dc1f5-main-39 false Observability v2.9 dev Java org.codehaus.plexus:plexus-utils@3.5.1 CVE-2025-67030 HIGH affected jar
quay.io/stackstate/kafka:3.9.2-7c9dc1f5-main-39 false Observability v2.9 dev Java org.eclipse.jetty:jetty-http@9.4.57.v20241219 CVE-2026-2332 HIGH affected jar
quay.io/stackstate/s3proxy:3.1.0-7c9dc1f5-main-15 false Observability v2.9 dev java-21-openjdk java-21-openjdk@21.0.10.0-150600.3.23.1 SUSE-SU-2026:1705-1 HIGH affected sles
quay.io/stackstate/s3proxy:3.1.0-7c9dc1f5-main-15 false Observability v2.9 dev java-21-openjdk-headless java-21-openjdk-headless@21.0.10.0-150600.3.23.1 SUSE-SU-2026:1705-1 HIGH affected sles
quay.io/stackstate/s3proxy:3.1.0-7c9dc1f5-main-15 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.133.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/stackgraph-console:2.5-7.14.12 false Observability v2.9 dev Java com.google.protobuf:protobuf-java@2.5.0 CVE-2021-22569 HIGH affected jar
quay.io/stackstate/stackgraph-console:2.5-7.14.12 false Observability v2.9 dev Java com.google.protobuf:protobuf-java@2.5.0 CVE-2024-7254 HIGH affected jar
quay.io/stackstate/stackgraph-console:2.5-7.14.12 false Observability v2.9 dev Java io.netty:netty-codec@4.1.131.Final CVE-2026-42583 HIGH affected jar
quay.io/stackstate/stackgraph-console:2.5-7.14.12 false Observability v2.9 dev Java io.netty:netty-codec-dns@4.1.131.Final CVE-2026-42579 HIGH affected jar
quay.io/stackstate/stackgraph-console:2.5-7.14.12 false Observability v2.9 dev Java io.netty:netty-codec-http@4.1.131.Final CVE-2026-33870 HIGH affected jar
quay.io/stackstate/stackgraph-console:2.5-7.14.12 false Observability v2.9 dev Java io.netty:netty-codec-http@4.1.131.Final CVE-2026-42584 HIGH affected jar
quay.io/stackstate/stackgraph-console:2.5-7.14.12 false Observability v2.9 dev Java io.netty:netty-codec-http@4.1.131.Final CVE-2026-42587 HIGH affected jar
quay.io/stackstate/stackgraph-console:2.5-7.14.12 false Observability v2.9 dev Java io.netty:netty-codec-http2@4.1.131.Final CVE-2026-33871 HIGH affected jar
quay.io/stackstate/stackgraph-console:2.5-7.14.12 false Observability v2.9 dev Java io.netty:netty-codec-http2@4.1.131.Final CVE-2026-42587 HIGH affected jar
quay.io/stackstate/stackgraph-console:2.5-7.14.12 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.131.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/stackgraph-console:2.5-7.14.12 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.133.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/stackgraph-console:2.5-7.14.12 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.133.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/stackgraph-console:2.5-7.14.12 false Observability v2.9 dev Java org.apache.thrift:libthrift@0.15.0 CVE-2026-43869 HIGH affected jar
quay.io/stackstate/stackgraph-hbase:2.5-7.14.12 false Observability v2.9 dev Java com.google.protobuf:protobuf-java@2.5.0 CVE-2021-22569 HIGH affected jar
quay.io/stackstate/stackgraph-hbase:2.5-7.14.12 false Observability v2.9 dev Java com.google.protobuf:protobuf-java@2.5.0 CVE-2024-7254 HIGH affected jar
quay.io/stackstate/stackgraph-hbase:2.5-7.14.12 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.133.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/stackgraph-hbase:2.5-7.14.12 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.133.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/stackgraph-hbase:2.5-7.14.12 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.133.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/stackgraph-hbase:2.5-7.14.12 false Observability v2.9 dev Java org.apache.thrift:libthrift@0.15.0 CVE-2026-43869 HIGH affected jar
quay.io/stackstate/stackstate-correlate:7.0.0-snapshot.20260508152936-master-ad3d22f false Observability v2.9 dev java-21-openjdk java-21-openjdk@21.0.10.0-150600.3.23.1 SUSE-SU-2026:1705-1 HIGH affected sles
quay.io/stackstate/stackstate-correlate:7.0.0-snapshot.20260508152936-master-ad3d22f false Observability v2.9 dev java-21-openjdk-headless java-21-openjdk-headless@21.0.10.0-150600.3.23.1 SUSE-SU-2026:1705-1 HIGH affected sles
quay.io/stackstate/stackstate-kafka-to-es:7.0.0-snapshot.20260508152936-master-ad3d22f false Observability v2.9 dev java-21-openjdk java-21-openjdk@21.0.10.0-150600.3.23.1 SUSE-SU-2026:1705-1 HIGH affected sles
quay.io/stackstate/stackstate-kafka-to-es:7.0.0-snapshot.20260508152936-master-ad3d22f false Observability v2.9 dev java-21-openjdk-headless java-21-openjdk-headless@21.0.10.0-150600.3.23.1 SUSE-SU-2026:1705-1 HIGH affected sles
quay.io/stackstate/stackstate-receiver:7.0.0-snapshot.20260508152936-master-ad3d22f false Observability v2.9 dev java-21-openjdk java-21-openjdk@21.0.10.0-150600.3.23.1 SUSE-SU-2026:1705-1 HIGH affected sles
quay.io/stackstate/stackstate-receiver:7.0.0-snapshot.20260508152936-master-ad3d22f false Observability v2.9 dev java-21-openjdk-headless java-21-openjdk-headless@21.0.10.0-150600.3.23.1 SUSE-SU-2026:1705-1 HIGH affected sles
quay.io/stackstate/stackstate-server:7.0.0-snapshot.20260508152936-master-ad3d22f-2.5 false Observability v2.9 dev java-21-openjdk java-21-openjdk@21.0.10.0-150600.3.23.1 SUSE-SU-2026:1705-1 HIGH affected sles
quay.io/stackstate/stackstate-server:7.0.0-snapshot.20260508152936-master-ad3d22f-2.5 false Observability v2.9 dev java-21-openjdk-headless java-21-openjdk-headless@21.0.10.0-150600.3.23.1 SUSE-SU-2026:1705-1 HIGH affected sles
quay.io/stackstate/stackstate-server:7.0.0-snapshot.20260508152936-master-ad3d22f-2.5 false Observability v2.9 dev Java com.google.protobuf:protobuf-java@2.5.0 CVE-2021-22569 HIGH affected jar
quay.io/stackstate/stackstate-server:7.0.0-snapshot.20260508152936-master-ad3d22f-2.5 false Observability v2.9 dev Java com.google.protobuf:protobuf-java@2.5.0 CVE-2024-7254 HIGH affected jar
quay.io/stackstate/stackstate-server:7.0.0-snapshot.20260508152936-master-ad3d22f-2.5 false Observability v2.9 dev Java io.netty:netty-codec@4.1.131.Final CVE-2026-42583 HIGH affected jar
quay.io/stackstate/stackstate-server:7.0.0-snapshot.20260508152936-master-ad3d22f-2.5 false Observability v2.9 dev Java io.netty:netty-codec@4.1.132.Final CVE-2026-42583 HIGH affected jar
quay.io/stackstate/stackstate-server:7.0.0-snapshot.20260508152936-master-ad3d22f-2.5 false Observability v2.9 dev Java io.netty:netty-codec-dns@4.1.131.Final CVE-2026-42579 HIGH affected jar
quay.io/stackstate/stackstate-server:7.0.0-snapshot.20260508152936-master-ad3d22f-2.5 false Observability v2.9 dev Java io.netty:netty-codec-dns@4.1.132.Final CVE-2026-42579 HIGH affected jar
quay.io/stackstate/stackstate-server:7.0.0-snapshot.20260508152936-master-ad3d22f-2.5 false Observability v2.9 dev Java io.netty:netty-codec-http@4.1.131.Final CVE-2026-33870 HIGH affected jar
quay.io/stackstate/stackstate-server:7.0.0-snapshot.20260508152936-master-ad3d22f-2.5 false Observability v2.9 dev Java io.netty:netty-codec-http@4.1.131.Final CVE-2026-42584 HIGH affected jar
quay.io/stackstate/stackstate-server:7.0.0-snapshot.20260508152936-master-ad3d22f-2.5 false Observability v2.9 dev Java io.netty:netty-codec-http@4.1.131.Final CVE-2026-42587 HIGH affected jar
quay.io/stackstate/stackstate-server:7.0.0-snapshot.20260508152936-master-ad3d22f-2.5 false Observability v2.9 dev Java io.netty:netty-codec-http@4.1.132.Final CVE-2026-42584 HIGH affected jar
quay.io/stackstate/stackstate-server:7.0.0-snapshot.20260508152936-master-ad3d22f-2.5 false Observability v2.9 dev Java io.netty:netty-codec-http@4.1.132.Final CVE-2026-42587 HIGH affected jar
quay.io/stackstate/stackstate-server:7.0.0-snapshot.20260508152936-master-ad3d22f-2.5 false Observability v2.9 dev Java io.netty:netty-codec-http2@4.1.131.Final CVE-2026-33871 HIGH affected jar
quay.io/stackstate/stackstate-server:7.0.0-snapshot.20260508152936-master-ad3d22f-2.5 false Observability v2.9 dev Java io.netty:netty-codec-http2@4.1.131.Final CVE-2026-42587 HIGH affected jar
quay.io/stackstate/stackstate-server:7.0.0-snapshot.20260508152936-master-ad3d22f-2.5 false Observability v2.9 dev Java io.netty:netty-codec-http2@4.1.132.Final CVE-2026-42587 HIGH affected jar
quay.io/stackstate/stackstate-server:7.0.0-snapshot.20260508152936-master-ad3d22f-2.5 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.131.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/stackstate-server:7.0.0-snapshot.20260508152936-master-ad3d22f-2.5 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.132.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/stackstate-server:7.0.0-snapshot.20260508152936-master-ad3d22f-2.5 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.132.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/stackstate-server:7.0.0-snapshot.20260508152936-master-ad3d22f-2.5 false Observability v2.9 dev Java org.apache.thrift:libthrift@0.15.0 CVE-2026-43869 HIGH affected jar
quay.io/stackstate/sts-opentelemetry-collector:v0.0.34 false Observability v2.9 dev usr/bin/sts-opentelemetry-collector github.com/prometheus/prometheus@v0.311.2-0.20260410083055-07c6232d159b CVE-2026-42151 HIGH affected gobinary
quay.io/stackstate/sts-opentelemetry-collector:v0.0.34 false Observability v2.9 dev usr/bin/sts-opentelemetry-collector github.com/prometheus/prometheus@v0.311.2-0.20260410083055-07c6232d159b CVE-2026-42154 HIGH affected gobinary
quay.io/stackstate/tephra-server:2.5-7.14.12 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.133.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/tephra-server:2.5-7.14.12 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.133.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/tephra-server:2.5-7.14.12 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.133.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/tephra-server:2.5-7.14.12 false Observability v2.9 dev Java org.apache.thrift:libthrift@0.15.0 CVE-2026-43869 HIGH affected jar
quay.io/stackstate/zookeeper:3.9.5-7c9dc1f5-main-28 false Observability v2.9 dev Java io.netty:netty-codec@4.1.130.Final CVE-2026-42583 HIGH affected jar
quay.io/stackstate/zookeeper:3.9.5-7c9dc1f5-main-28 false Observability v2.9 dev Java io.netty:netty-transport-native-epoll@4.1.130.Final CVE-2026-42577 HIGH affected jar
quay.io/stackstate/zookeeper:3.9.5-7c9dc1f5-main-28 false Observability v2.9 dev Java org.eclipse.jetty:jetty-http@9.4.58.v20250814 CVE-2026-2332 HIGH affected jar