Search:
| Image | Mirrored | Release | Binary/Package | Dependency | Vulnerability ID (CVE) | Severity | Status | Justification (for status not affected) | Type (language or OS) |
|---|---|---|---|---|---|---|---|---|---|
| rancher/hardened-dns-node-cache:1.26.8-build20260416 | false | RKE2 v1.34.7-rc2 | node-cache | github.com/coredns/coredns@v1.13.2 | CVE-2026-26017 | HIGH | affected | gobinary | |
| rancher/hardened-dns-node-cache:1.26.8-build20260416 | false | RKE2 v1.34.7-rc2 | node-cache | github.com/coredns/coredns@v1.13.2 | CVE-2026-26018 | HIGH | affected | gobinary | |
| rancher/hardened-dns-node-cache:1.26.8-build20260416 | false | RKE2 v1.34.7-rc2 | node-cache | github.com/coredns/coredns@v1.13.2 | CVE-2025-68151 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/klipper-helm:v0.9.16-build20260410 | false | RKE2 v1.34.7-rc2 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | google.golang.org/grpc@v1.72.2 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rke2-cloud-provider:v1.34.7-0.20260415182025-e7567db58dd7-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/rke2-cloud-provider | go.opentelemetry.io/otel/sdk@v1.40.0 | CVE-2026-39883 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.34.7-rc2-rke2r1 | false | RKE2 v1.34.7-rc2 | bin/containerd | github.com/go-jose/go-jose/v4@v4.1.3 | CVE-2026-34986 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.34.7-rc2-rke2r1 | false | RKE2 v1.34.7-rc2 | bin/crictl | github.com/docker/docker@v27.1.1+incompatible | CVE-2026-34040 | HIGH | affected | gobinary | |
| rancher/hardened-addon-resizer:1.8.23-build20260413 | false | RKE2 v1.34.7-rc2 | pod_nanny | golang.org/x/net@v0.33.0 | CVE-2025-22870 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-addon-resizer:1.8.23-build20260413 | false | RKE2 v1.34.7-rc2 | pod_nanny | golang.org/x/net@v0.33.0 | CVE-2025-22872 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-addon-resizer:1.8.23-build20260413 | false | RKE2 v1.34.7-rc2 | pod_nanny | golang.org/x/oauth2@v0.24.0 | CVE-2025-22868 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cluster-autoscaler:v1.10.3-build20260414 | false | RKE2 v1.34.7-rc2 | cluster-proportional-autoscaler | golang.org/x/net@v0.36.0 | CVE-2025-22872 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cluster-autoscaler:v1.10.3-build20260414 | false | RKE2 v1.34.7-rc2 | cluster-proportional-autoscaler | golang.org/x/oauth2@v0.23.0 | CVE-2025-22868 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260415 | false | RKE2 v1.34.7-rc2 | usr/local/bin/etcd | go.opentelemetry.io/otel/sdk@v1.34.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260415 | false | RKE2 v1.34.7-rc2 | usr/local/bin/etcd | go.opentelemetry.io/otel/sdk@v1.34.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260415 | false | RKE2 v1.34.7-rc2 | usr/local/bin/etcd | golang.org/x/crypto@v0.42.0 | CVE-2025-47914 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260415 | false | RKE2 v1.34.7-rc2 | usr/local/bin/etcd | golang.org/x/crypto@v0.42.0 | CVE-2025-58181 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260415 | false | RKE2 v1.34.7-rc2 | usr/local/bin/etcd | google.golang.org/grpc@v1.71.1 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260415 | false | RKE2 v1.34.7-rc2 | usr/local/bin/etcdctl | google.golang.org/grpc@v1.71.1 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260413 | false | RKE2 v1.34.7-rc2 | metrics-server | go.opentelemetry.io/otel/sdk@v1.35.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260413 | false | RKE2 v1.34.7-rc2 | metrics-server | go.opentelemetry.io/otel/sdk@v1.35.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260413 | false | RKE2 v1.34.7-rc2 | metrics-server | golang.org/x/crypto@v0.38.0 | CVE-2025-47914 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260413 | false | RKE2 v1.34.7-rc2 | metrics-server | golang.org/x/crypto@v0.38.0 | CVE-2025-58181 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-k8s-metrics-server:v0.8.1-build20260413 | false | RKE2 v1.34.7-rc2 | metrics-server | google.golang.org/grpc@v1.72.0 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kube-apiserver | github.com/opencontainers/selinux@v1.11.1 | CVE-2025-52881 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kube-apiserver | go.opentelemetry.io/otel/sdk@v1.34.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kube-apiserver | go.opentelemetry.io/otel/sdk@v1.34.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kube-apiserver | golang.org/x/crypto@v0.36.0 | CVE-2025-47914 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kube-apiserver | golang.org/x/crypto@v0.36.0 | CVE-2025-58181 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kube-apiserver | google.golang.org/grpc@v1.72.1 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kube-controller-manager | github.com/opencontainers/selinux@v1.11.1 | CVE-2025-52881 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kube-controller-manager | go.opentelemetry.io/otel/sdk@v1.34.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kube-controller-manager | go.opentelemetry.io/otel/sdk@v1.34.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kube-controller-manager | golang.org/x/crypto@v0.36.0 | CVE-2025-47914 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kube-controller-manager | golang.org/x/crypto@v0.36.0 | CVE-2025-58181 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kube-controller-manager | google.golang.org/grpc@v1.72.1 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kube-proxy | go.opentelemetry.io/otel/sdk@v1.34.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kube-proxy | go.opentelemetry.io/otel/sdk@v1.34.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kube-proxy | golang.org/x/crypto@v0.36.0 | CVE-2025-47914 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kube-proxy | golang.org/x/crypto@v0.36.0 | CVE-2025-58181 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kube-proxy | google.golang.org/grpc@v1.72.1 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kube-scheduler | go.opentelemetry.io/otel/sdk@v1.34.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kube-scheduler | go.opentelemetry.io/otel/sdk@v1.34.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kube-scheduler | golang.org/x/crypto@v0.36.0 | CVE-2025-47914 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kube-scheduler | golang.org/x/crypto@v0.36.0 | CVE-2025-58181 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kube-scheduler | google.golang.org/grpc@v1.72.1 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kubelet | github.com/opencontainers/selinux@v1.11.1 | CVE-2025-52881 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kubelet | go.opentelemetry.io/otel/sdk@v1.34.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kubelet | go.opentelemetry.io/otel/sdk@v1.34.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kubelet | golang.org/x/crypto@v0.36.0 | CVE-2025-47914 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kubelet | golang.org/x/crypto@v0.36.0 | CVE-2025-58181 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.34.7-rke2r1-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/kubelet | google.golang.org/grpc@v1.72.1 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-snapshot-controller:v8.5.0-build20260410 | false | RKE2 v1.34.7-rc2 | snapshot-controller | go.opentelemetry.io/otel/sdk@v1.40.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-snapshot-controller:v8.5.0-build20260410 | false | RKE2 v1.34.7-rc2 | snapshot-controller | google.golang.org/grpc@v1.78.0 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.16-build20260410 | false | RKE2 v1.34.7-rc2 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | google.golang.org/grpc@v1.72.2 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.16-build20260410 | false | RKE2 v1.34.7-rc2 | usr/bin/helm | google.golang.org/grpc@v1.72.2 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-cloud-provider:v1.34.7-0.20260415182025-e7567db58dd7-build20260416 | false | RKE2 v1.34.7-rc2 | usr/local/bin/rke2-cloud-provider | google.golang.org/grpc@v1.72.1 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.34.7-rc2-rke2r1 | false | RKE2 v1.34.7-rc2 | bin/containerd | github.com/docker/cli@v29.1.5+incompatible | CVE-2025-15558 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.34.7-rc2-rke2r1 | false | RKE2 v1.34.7-rc2 | bin/containerd | github.com/docker/docker@v27.3.1+incompatible | CVE-2026-34040 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.34.7-rc2-rke2r1 | false | RKE2 v1.34.7-rc2 | bin/containerd | go.opentelemetry.io/otel/sdk@v1.38.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.34.7-rc2-rke2r1 | false | RKE2 v1.34.7-rc2 | bin/containerd | go.opentelemetry.io/otel/sdk@v1.38.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.34.7-rc2-rke2r1 | false | RKE2 v1.34.7-rc2 | bin/containerd | google.golang.org/grpc@v1.78.0 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.34.7-rc2-rke2r1 | false | RKE2 v1.34.7-rc2 | bin/containerd-shim-runc-v2 | google.golang.org/grpc@v1.78.0 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.34.7-rc2-rke2r1 | false | RKE2 v1.34.7-rc2 | bin/crictl | github.com/buger/jsonparser@v1.1.1 | CVE-2026-32285 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.34.7-rc2-rke2r1 | false | RKE2 v1.34.7-rc2 | bin/crictl | go.opentelemetry.io/otel/sdk@v1.37.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.34.7-rc2-rke2r1 | false | RKE2 v1.34.7-rc2 | bin/crictl | go.opentelemetry.io/otel/sdk@v1.37.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.34.7-rc2-rke2r1 | false | RKE2 v1.34.7-rc2 | bin/crictl | google.golang.org/grpc@v1.75.0 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.34.7-rc2-rke2r1 | false | RKE2 v1.34.7-rc2 | bin/ctr | google.golang.org/grpc@v1.78.0 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.34.7-rc2-rke2r1 | false | RKE2 v1.34.7-rc2 | bin/kubelet | github.com/opencontainers/selinux@v1.11.1 | CVE-2025-52881 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.34.7-rc2-rke2r1 | false | RKE2 v1.34.7-rc2 | bin/kubelet | go.opentelemetry.io/otel/sdk@v1.34.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.34.7-rc2-rke2r1 | false | RKE2 v1.34.7-rc2 | bin/kubelet | go.opentelemetry.io/otel/sdk@v1.34.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.34.7-rc2-rke2r1 | false | RKE2 v1.34.7-rc2 | bin/kubelet | golang.org/x/crypto@v0.36.0 | CVE-2025-47914 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.34.7-rc2-rke2r1 | false | RKE2 v1.34.7-rc2 | bin/kubelet | golang.org/x/crypto@v0.36.0 | CVE-2025-58181 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.34.7-rc2-rke2r1 | false | RKE2 v1.34.7-rc2 | bin/kubelet | google.golang.org/grpc@v1.72.1 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |