Search:
Image | Mirrored | Release | Binary/Package | Dependency | Vulnerability ID (CVE) | Severity | Status | Justification (for status not affected) | Type (language or OS) |
---|---|---|---|---|---|---|---|---|---|
rancher/hardened-coredns:v1.12.3-build20250909 | false | RKE2 v1.32.9 | coredns | github.com/coredns/coredns@v1.12.3 | CVE-2025-58063 | MEDIUM*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
rancher/hardened-coredns:v1.12.3-build20250909 | false | RKE2 v1.32.9 | coredns | github.com/quic-go/quic-go@v0.54.0 | CVE-2025-59530 | HIGH | affected | gobinary | |
rancher/hardened-dns-node-cache:1.26.0-build20250909 | false | RKE2 v1.32.9 | node-cache | github.com/coredns/coredns@v1.12.2 | CVE-2025-58063 | MEDIUM*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
rancher/hardened-dns-node-cache:1.26.0-build20250909 | false | RKE2 v1.32.9 | node-cache | github.com/quic-go/quic-go@v0.52.0 | CVE-2025-59530 | HIGH | affected | gobinary | |
rancher/klipper-helm:v0.9.8-build20250709 | false | RKE2 v1.32.9 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | stdlib@v1.24.5 | CVE-2025-47907 | MEDIUM*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
rancher/klipper-helm:v0.9.8-build20250709 | false | RKE2 v1.32.9 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | stdlib@v1.24.5 | CVE-2025-47907 | MEDIUM*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
rancher/klipper-helm:v0.9.8-build20250709 | false | RKE2 v1.32.9 | usr/bin/helm | stdlib@v1.24.4 | CVE-2025-47907 | MEDIUM*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
rancher/mirrored-sig-storage-snapshot-controller:v8.2.0 | true | RKE2 v1.32.9 | snapshot-controller | stdlib@v1.23.1 | CVE-2025-47907 | MEDIUM*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
rancher/nginx-ingress-controller:v1.12.6-hardened1 | false | RKE2 v1.32.9 | libopenssl1_1 | libopenssl1_1@1.1.1w-150600.5.15.1 | SUSE-SU-2025:03443-1 | HIGH | affected | sles | |
rancher/nginx-ingress-controller:v1.12.6-hardened1 | false | RKE2 v1.32.9 | libopenssl3 | libopenssl3@3.1.4-150600.5.36.4 | SUSE-SU-2025:03442-1 | HIGH | affected | sles | |
rancher/hardened-addon-resizer:1.8.23-build20250909 | false | RKE2 v1.32.9 | pod_nanny | golang.org/x/net@v0.33.0 | CVE-2025-22870 | none | not affected | vulnerable code not present | gobinary |
rancher/hardened-addon-resizer:1.8.23-build20250909 | false | RKE2 v1.32.9 | pod_nanny | golang.org/x/net@v0.33.0 | CVE-2025-22872 | none | not affected | vulnerable code not present | gobinary |
rancher/hardened-addon-resizer:1.8.23-build20250909 | false | RKE2 v1.32.9 | pod_nanny | golang.org/x/oauth2@v0.24.0 | CVE-2025-22868 | none | not affected | vulnerable code not present | gobinary |
rancher/hardened-calico:v3.30.3-build20250909 | false | RKE2 v1.32.9 | libbrotlicommon1 | libbrotlicommon1@1.0.7-3.3.1 | SUSE-SU-2025:03268-1 | none | not affected | vulnerable code cannot be controlled by adversary | sles |
rancher/hardened-calico:v3.30.3-build20250909 | false | RKE2 v1.32.9 | libbrotlidec1 | libbrotlidec1@1.0.7-3.3.1 | SUSE-SU-2025:03268-1 | none | not affected | vulnerable code cannot be controlled by adversary | sles |
rancher/hardened-cluster-autoscaler:v1.10.2-build20250909 | false | RKE2 v1.32.9 | cluster-proportional-autoscaler | golang.org/x/net@v0.36.0 | CVE-2025-22872 | none | not affected | vulnerable code not present | gobinary |
rancher/hardened-cluster-autoscaler:v1.10.2-build20250909 | false | RKE2 v1.32.9 | cluster-proportional-autoscaler | golang.org/x/oauth2@v0.23.0 | CVE-2025-22868 | none | not affected | vulnerable code not present | gobinary |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | libbrotlicommon1 | libbrotlicommon1@1.0.7-3.3.1 | SUSE-SU-2025:03268-1 | none | not affected | vulnerable code cannot be controlled by adversary | sles |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | libbrotlidec1 | libbrotlidec1@1.0.7-3.3.1 | SUSE-SU-2025:03268-1 | none | not affected | vulnerable code cannot be controlled by adversary | sles |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | libcurl4 | libcurl4@8.6.0-150600.4.21.1 | SUSE-SU-2025:03198-1 | none | not affected | vulnerable code cannot be controlled by adversary | sles |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | curl | curl@8.6.0-150600.4.21.1 | SUSE-SU-2025:03198-1 | none | not affected | vulnerable code cannot be controlled by adversary | sles |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | usr/local/bin/kube-apiserver | golang.org/x/crypto@v0.28.0 | CVE-2024-45337 | none | not affected | vulnerable code not in execute path | gobinary |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | usr/local/bin/kube-apiserver | golang.org/x/crypto@v0.28.0 | CVE-2025-22869 | none | not affected | vulnerable code not present | gobinary |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | usr/local/bin/kube-apiserver | golang.org/x/net@v0.30.0 | CVE-2025-22870 | none | not affected | vulnerable code not in execute path | gobinary |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | usr/local/bin/kube-apiserver | golang.org/x/oauth2@v0.23.0 | CVE-2025-22868 | none | not affected | vulnerable code not present | gobinary |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | usr/local/bin/kube-apiserver | gopkg.in/square/go-jose.v2@v2.6.0 | CVE-2024-28180 | none | not affected | vulnerable code not in execute path | gobinary |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | usr/local/bin/kube-controller-manager | golang.org/x/crypto@v0.28.0 | CVE-2024-45337 | none | not affected | vulnerable code not in execute path | gobinary |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | usr/local/bin/kube-controller-manager | golang.org/x/crypto@v0.28.0 | CVE-2025-22869 | none | not affected | vulnerable code not present | gobinary |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | usr/local/bin/kube-controller-manager | golang.org/x/net@v0.30.0 | CVE-2025-22870 | none | not affected | vulnerable code not in execute path | gobinary |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | usr/local/bin/kube-controller-manager | golang.org/x/oauth2@v0.23.0 | CVE-2025-22868 | none | not affected | vulnerable code not present | gobinary |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | usr/local/bin/kube-controller-manager | gopkg.in/square/go-jose.v2@v2.6.0 | CVE-2024-28180 | none | not affected | vulnerable code not in execute path | gobinary |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | usr/local/bin/kube-proxy | golang.org/x/crypto@v0.28.0 | CVE-2024-45337 | none | not affected | vulnerable code not in execute path | gobinary |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | usr/local/bin/kube-proxy | golang.org/x/crypto@v0.28.0 | CVE-2025-22869 | none | not affected | vulnerable code not present | gobinary |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | usr/local/bin/kube-proxy | golang.org/x/net@v0.30.0 | CVE-2025-22870 | none | not affected | vulnerable code not in execute path | gobinary |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | usr/local/bin/kube-proxy | golang.org/x/oauth2@v0.23.0 | CVE-2025-22868 | none | not affected | vulnerable code not present | gobinary |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | usr/local/bin/kube-scheduler | golang.org/x/crypto@v0.28.0 | CVE-2024-45337 | none | not affected | vulnerable code not in execute path | gobinary |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | usr/local/bin/kube-scheduler | golang.org/x/crypto@v0.28.0 | CVE-2025-22869 | none | not affected | vulnerable code not present | gobinary |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | usr/local/bin/kube-scheduler | golang.org/x/net@v0.30.0 | CVE-2025-22870 | none | not affected | vulnerable code not in execute path | gobinary |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | usr/local/bin/kube-scheduler | golang.org/x/oauth2@v0.23.0 | CVE-2025-22868 | none | not affected | vulnerable code not present | gobinary |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | usr/local/bin/kubectl | golang.org/x/net@v0.30.0 | CVE-2025-22870 | none | not affected | vulnerable code not in execute path | gobinary |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | usr/local/bin/kubectl | golang.org/x/oauth2@v0.23.0 | CVE-2025-22868 | none | not affected | vulnerable code not present | gobinary |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | usr/local/bin/kubelet | go.opentelemetry.io/contrib/instrumentation/github.com/emicklei/go-restful/otelrestful@v0.42.0 | CVE-2023-45142 | none | not affected | vulnerable code not present | gobinary |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | usr/local/bin/kubelet | golang.org/x/crypto@v0.28.0 | CVE-2024-45337 | none | not affected | vulnerable code not in execute path | gobinary |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | usr/local/bin/kubelet | golang.org/x/crypto@v0.28.0 | CVE-2025-22869 | none | not affected | vulnerable code not present | gobinary |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | usr/local/bin/kubelet | golang.org/x/net@v0.30.0 | CVE-2025-22870 | none | not affected | vulnerable code not in execute path | gobinary |
rancher/hardened-kubernetes:v1.32.9-rke2r1-build20250910 | false | RKE2 v1.32.9 | usr/local/bin/kubelet | golang.org/x/oauth2@v0.23.0 | CVE-2025-22868 | none | not affected | vulnerable code not present | gobinary |
rancher/klipper-helm:v0.9.8-build20250709 | false | RKE2 v1.32.9 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | helm.sh/helm/v3@v3.18.4 | CVE-2025-55198 | none | not affected | vulnerable code not in execute path | gobinary |
rancher/klipper-helm:v0.9.8-build20250709 | false | RKE2 v1.32.9 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | helm.sh/helm/v3@v3.18.4 | CVE-2025-55199 | none | not affected | vulnerable code not in execute path | gobinary |
rancher/mirrored-sig-storage-snapshot-controller:v8.2.0 | true | RKE2 v1.32.9 | snapshot-controller | golang.org/x/net@v0.31.0 | CVE-2025-22870 | none | not affected | vulnerable code not present | gobinary |
rancher/mirrored-sig-storage-snapshot-controller:v8.2.0 | true | RKE2 v1.32.9 | snapshot-controller | golang.org/x/net@v0.31.0 | CVE-2025-22872 | none | not affected | vulnerable code not present | gobinary |
rancher/mirrored-sig-storage-snapshot-controller:v8.2.0 | true | RKE2 v1.32.9 | snapshot-controller | golang.org/x/oauth2@v0.24.0 | CVE-2025-22868 | none | not affected | vulnerable code not present | gobinary |
rancher/nginx-ingress-controller:v1.12.6-hardened1 | false | RKE2 v1.32.9 | libbrotlicommon1 | libbrotlicommon1@1.0.7-3.3.1 | SUSE-SU-2025:03268-1 | none | not affected | vulnerable code cannot be controlled by adversary | sles |
rancher/nginx-ingress-controller:v1.12.6-hardened1 | false | RKE2 v1.32.9 | libbrotlidec1 | libbrotlidec1@1.0.7-3.3.1 | SUSE-SU-2025:03268-1 | none | not affected | vulnerable code cannot be controlled by adversary | sles |
rancher/nginx-ingress-controller:v1.12.6-hardened1 | false | RKE2 v1.32.9 | libcurl4 | libcurl4@8.6.0-150600.4.21.1 | SUSE-SU-2025:03198-1 | none | not affected | vulnerable code cannot be controlled by adversary | sles |
rancher/nginx-ingress-controller:v1.12.6-hardened1 | false | RKE2 v1.32.9 | curl | curl@8.6.0-150600.4.21.1 | SUSE-SU-2025:03198-1 | none | not affected | vulnerable code cannot be controlled by adversary | sles |
rancher/nginx-ingress-controller:v1.12.6-hardened1 | false | RKE2 v1.32.9 | libopenssl-3-devel | libopenssl-3-devel@3.1.4-150600.5.36.4 | SUSE-SU-2025:03442-1 | none | not affected | vulnerable code not present | sles |
rancher/nginx-ingress-controller:v1.12.6-hardened1 | false | RKE2 v1.32.9 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.1.4-150600.5.36.4 | SUSE-SU-2025:03442-1 | none | not affected | vulnerable code not present | sles |
rancher/nginx-ingress-controller:v1.12.6-hardened1 | false | RKE2 v1.32.9 | openssl-3 | openssl-3@3.1.4-150600.5.36.4 | SUSE-SU-2025:03442-1 | none | not affected | vulnerable code not present | sles |
rancher/rke2-runtime:v1.32.9-rke2r1 | false | RKE2 v1.32.9 | bin/crictl | golang.org/x/net@v0.30.0 | CVE-2025-22870 | none | not affected | vulnerable code not in execute path | gobinary |
rancher/rke2-runtime:v1.32.9-rke2r1 | false | RKE2 v1.32.9 | bin/crictl | golang.org/x/net@v0.30.0 | CVE-2025-22872 | none | not affected | vulnerable code not in execute path | gobinary |
rancher/rke2-runtime:v1.32.9-rke2r1 | false | RKE2 v1.32.9 | bin/crictl | golang.org/x/oauth2@v0.23.0 | CVE-2025-22868 | none | not affected | vulnerable code not present | gobinary |
rancher/rke2-runtime:v1.32.9-rke2r1 | false | RKE2 v1.32.9 | bin/kubectl | golang.org/x/net@v0.30.0 | CVE-2025-22870 | none | not affected | vulnerable code not in execute path | gobinary |
rancher/rke2-runtime:v1.32.9-rke2r1 | false | RKE2 v1.32.9 | bin/kubectl | golang.org/x/oauth2@v0.23.0 | CVE-2025-22868 | none | not affected | vulnerable code not present | gobinary |
rancher/rke2-runtime:v1.32.9-rke2r1 | false | RKE2 v1.32.9 | bin/kubelet | go.opentelemetry.io/contrib/instrumentation/github.com/emicklei/go-restful/otelrestful@v0.42.0 | CVE-2023-45142 | none | not affected | vulnerable code not present | gobinary |
rancher/rke2-runtime:v1.32.9-rke2r1 | false | RKE2 v1.32.9 | bin/kubelet | golang.org/x/crypto@v0.28.0 | CVE-2024-45337 | none | not affected | vulnerable code not in execute path | gobinary |
rancher/rke2-runtime:v1.32.9-rke2r1 | false | RKE2 v1.32.9 | bin/kubelet | golang.org/x/crypto@v0.28.0 | CVE-2025-22869 | none | not affected | vulnerable code not present | gobinary |
rancher/rke2-runtime:v1.32.9-rke2r1 | false | RKE2 v1.32.9 | bin/kubelet | golang.org/x/net@v0.30.0 | CVE-2025-22870 | none | not affected | vulnerable code not in execute path | gobinary |
rancher/rke2-runtime:v1.32.9-rke2r1 | false | RKE2 v1.32.9 | bin/kubelet | golang.org/x/oauth2@v0.23.0 | CVE-2025-22868 | none | not affected | vulnerable code not present | gobinary |