Search:
| Image | Mirrored | Release | Binary/Package | Dependency | Vulnerability ID (CVE) | Severity | Status | Justification (for status not affected) | Type (language or OS) |
|---|---|---|---|---|---|---|---|---|---|
| rancher/hardened-calico:v3.32.0-build20260511 | false | RKE2 v1.35.5-rc3 | liblzma5 | liblzma5@5.4.1-150600.3.3.1 | SUSE-SU-2026:2051-1 | HIGH | affected | sles | |
| rancher/hardened-coredns:v1.14.3-build20260511 | false | RKE2 v1.35.5-rc3 | busybox | busybox@1.37.0-150700.18.15.1 | SUSE-SU-2026:2054-1 | HIGH | affected | sles | |
| rancher/hardened-dns-node-cache:1.26.8-build20260511 | false | RKE2 v1.35.5-rc3 | busybox | busybox@1.37.0-150700.18.15.1 | SUSE-SU-2026:2054-1 | HIGH | affected | sles | |
| rancher/hardened-flannel:v0.28.4-build20260511 | false | RKE2 v1.35.5-rc3 | busybox | busybox@1.37.0-150700.18.15.1 | SUSE-SU-2026:2054-1 | HIGH | affected | sles | |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | glibc | glibc@2.40-160000.4.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | glibc-locale-base | glibc-locale-base@2.40-160000.4.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/klipper-helm:v0.10.0-build20260513 | false | RKE2 v1.35.5-rc3 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | github.com/containerd/containerd@v1.7.30 | CVE-2026-46680 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.10.0-build20260513 | false | RKE2 v1.35.5-rc3 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | github.com/containerd/containerd@v1.7.30 | CVE-2026-46680 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.10.0-build20260513 | false | RKE2 v1.35.5-rc3 | usr/bin/helm | github.com/containerd/containerd@v1.7.30 | CVE-2026-46680 | HIGH | affected | gobinary | |
| rancher/kube-webhook-certgen:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | kube-webhook-certgen | stdlib@v1.26.2 | CVE-2026-33811 | HIGH | affected | gobinary | |
| rancher/kube-webhook-certgen:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | kube-webhook-certgen | stdlib@v1.26.2 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/kube-webhook-certgen:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | kube-webhook-certgen | stdlib@v1.26.2 | CVE-2026-39820 | HIGH | affected | gobinary | |
| rancher/kube-webhook-certgen:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | kube-webhook-certgen | stdlib@v1.26.2 | CVE-2026-39836 | HIGH | affected | gobinary | |
| rancher/kube-webhook-certgen:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | kube-webhook-certgen | stdlib@v1.26.2 | CVE-2026-42499 | HIGH | affected | gobinary | |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | glibc | glibc@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | glibc-devel | glibc-devel@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | glibc-locale-base | glibc-locale-base@2.40-160000.3.1 | SUSE-SU-2026:21807-1 | HIGH | affected | sles | |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | libcap-progs | libcap-progs@2.73-160000.2.2 | SUSE-SU-2026:21373-1 | HIGH | affected | sles | |
| rancher/rke2-cloud-provider:v1.35.4-0.20260415195656-e51c0636351d-build20260415 | false | RKE2 v1.35.5-rc3 | usr/local/bin/rke2-cloud-provider | stdlib@v1.25.9 | CVE-2026-33814 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/containerd | github.com/containerd/containerd/v2@v2.2.3-k3s1 | CVE-2026-46680 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/containerd | github.com/docker/docker@v27.3.1+incompatible | CVE-2026-41567 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/containerd | github.com/docker/docker@v27.3.1+incompatible | CVE-2026-42306 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/containerd | github.com/docker/docker@v27.3.1+incompatible | CVE-2026-33997 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/containerd-shim-runc-v2 | github.com/containerd/containerd/v2@v2.2.3-k3s1 | CVE-2026-46680 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/crictl | github.com/docker/docker@v27.1.1+incompatible | CVE-2026-41567 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/crictl | github.com/docker/docker@v27.1.1+incompatible | CVE-2026-42306 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/crictl | github.com/docker/docker@v27.1.1+incompatible | CVE-2026-33997 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/ctr | github.com/containerd/containerd/v2@v2.2.3-k3s1 | CVE-2026-46680 | HIGH | affected | gobinary | |
| rancher/hardened-addon-resizer:1.8.23-build20260511 | false | RKE2 v1.35.5-rc3 | pod_nanny | golang.org/x/oauth2@v0.24.0 | CVE-2025-22868 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cluster-autoscaler:v1.10.3-build20260511 | false | RKE2 v1.35.5-rc3 | cluster-proportional-autoscaler | golang.org/x/oauth2@v0.23.0 | CVE-2025-22868 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260512 | false | RKE2 v1.35.5-rc3 | usr/local/bin/etcd | go.opentelemetry.io/otel/sdk@v1.34.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260512 | false | RKE2 v1.35.5-rc3 | usr/local/bin/etcd | go.opentelemetry.io/otel/sdk@v1.34.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260512 | false | RKE2 v1.35.5-rc3 | usr/local/bin/etcd | google.golang.org/grpc@v1.71.1 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-etcd:v3.6.7-k3s1-build20260512 | false | RKE2 v1.35.5-rc3 | usr/local/bin/etcdctl | google.golang.org/grpc@v1.71.1 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-apiserver | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-apiserver | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-apiserver | google.golang.org/grpc@v1.72.2 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-apiserver | stdlib@v1.25.9 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-apiserver | stdlib@v1.25.9 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-apiserver | stdlib@v1.25.9 | CVE-2026-39820 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-apiserver | stdlib@v1.25.9 | CVE-2026-39823 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-apiserver | stdlib@v1.25.9 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-apiserver | stdlib@v1.25.9 | CVE-2026-39826 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-apiserver | stdlib@v1.25.9 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-apiserver | stdlib@v1.25.9 | CVE-2026-42499 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-controller-manager | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-controller-manager | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-controller-manager | google.golang.org/grpc@v1.72.2 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-controller-manager | stdlib@v1.25.9 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-controller-manager | stdlib@v1.25.9 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-controller-manager | stdlib@v1.25.9 | CVE-2026-39820 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-controller-manager | stdlib@v1.25.9 | CVE-2026-39823 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-controller-manager | stdlib@v1.25.9 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-controller-manager | stdlib@v1.25.9 | CVE-2026-39826 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-controller-manager | stdlib@v1.25.9 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-controller-manager | stdlib@v1.25.9 | CVE-2026-42499 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-proxy | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-proxy | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-proxy | google.golang.org/grpc@v1.72.2 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-proxy | stdlib@v1.25.9 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-proxy | stdlib@v1.25.9 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-proxy | stdlib@v1.25.9 | CVE-2026-39820 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-proxy | stdlib@v1.25.9 | CVE-2026-39823 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-proxy | stdlib@v1.25.9 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-proxy | stdlib@v1.25.9 | CVE-2026-39826 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-proxy | stdlib@v1.25.9 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-proxy | stdlib@v1.25.9 | CVE-2026-42499 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-scheduler | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-scheduler | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-scheduler | google.golang.org/grpc@v1.72.2 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-scheduler | stdlib@v1.25.9 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-scheduler | stdlib@v1.25.9 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-scheduler | stdlib@v1.25.9 | CVE-2026-39820 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-scheduler | stdlib@v1.25.9 | CVE-2026-39823 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-scheduler | stdlib@v1.25.9 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-scheduler | stdlib@v1.25.9 | CVE-2026-39826 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-scheduler | stdlib@v1.25.9 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kube-scheduler | stdlib@v1.25.9 | CVE-2026-42499 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kubectl | stdlib@v1.25.9 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kubectl | stdlib@v1.25.9 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kubectl | stdlib@v1.25.9 | CVE-2026-39820 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kubectl | stdlib@v1.25.9 | CVE-2026-39823 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kubectl | stdlib@v1.25.9 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kubectl | stdlib@v1.25.9 | CVE-2026-39826 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kubectl | stdlib@v1.25.9 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kubectl | stdlib@v1.25.9 | CVE-2026-42499 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kubelet | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kubelet | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kubelet | google.golang.org/grpc@v1.72.2 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kubelet | stdlib@v1.25.9 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kubelet | stdlib@v1.25.9 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kubelet | stdlib@v1.25.9 | CVE-2026-39820 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kubelet | stdlib@v1.25.9 | CVE-2026-39823 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kubelet | stdlib@v1.25.9 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kubelet | stdlib@v1.25.9 | CVE-2026-39826 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kubelet | stdlib@v1.25.9 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/hardened-kubernetes:v1.35.5-rke2r2-build20260521 | false | RKE2 v1.35.5-rc3 | usr/local/bin/kubelet | stdlib@v1.25.9 | CVE-2026-42499 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.10.0-build20260513 | false | RKE2 v1.35.5-rc3 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | google.golang.org/grpc@v1.72.2 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.10.0-build20260513 | false | RKE2 v1.35.5-rc3 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | google.golang.org/grpc@v1.72.2 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.10.0-build20260513 | false | RKE2 v1.35.5-rc3 | usr/bin/helm | google.golang.org/grpc@v1.72.2 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | libcap2 | libcap2@2.73-160000.2.2 | SUSE-SU-2026:21373-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | libopenssl-3-devel | libopenssl-3-devel@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | libopenssl-3-fips-provider | libopenssl-3-fips-provider@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | libopenssl3 | libopenssl3@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | libpython3_13-1_0 | libpython3_13-1_0@3.13.12-160000.1.1 | SUSE-SU-2026:21178-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | libsystemd0 | libsystemd0@257.10-160000.1.1 | SUSE-SU-2026:21144-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | libudev1 | libudev1@257.10-160000.1.1 | SUSE-SU-2026:21144-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | openssl-3 | openssl-3@3.5.0-160000.6.1 | SUSE-SU-2026:21186-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | python313-base | python313-base@3.13.12-160000.1.1 | SUSE-SU-2026:21178-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | tar | tar@1.35-160000.2.2 | SUSE-SU-2026:21143-1 | none | not affected | vulnerable code not in execute path | sles |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | dbg | stdlib@v1.26.2 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | dbg | stdlib@v1.26.2 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | dbg | stdlib@v1.26.2 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | dbg | stdlib@v1.26.2 | CVE-2026-39823 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | dbg | stdlib@v1.26.2 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | dbg | stdlib@v1.26.2 | CVE-2026-39826 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | dbg | stdlib@v1.26.2 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | dbg | stdlib@v1.26.2 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | nginx-ingress-controller | stdlib@v1.26.2 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | nginx-ingress-controller | stdlib@v1.26.2 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | nginx-ingress-controller | stdlib@v1.26.2 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | nginx-ingress-controller | stdlib@v1.26.2 | CVE-2026-39823 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | nginx-ingress-controller | stdlib@v1.26.2 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | nginx-ingress-controller | stdlib@v1.26.2 | CVE-2026-39826 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | nginx-ingress-controller | stdlib@v1.26.2 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | nginx-ingress-controller | stdlib@v1.26.2 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | wait-shutdown | stdlib@v1.26.2 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | wait-shutdown | stdlib@v1.26.2 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | wait-shutdown | stdlib@v1.26.2 | CVE-2026-39820 | none | not affected | vulnerable code not present | gobinary |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | wait-shutdown | stdlib@v1.26.2 | CVE-2026-39823 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | wait-shutdown | stdlib@v1.26.2 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | wait-shutdown | stdlib@v1.26.2 | CVE-2026-39826 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | wait-shutdown | stdlib@v1.26.2 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/nginx-ingress-controller:v1.14.5-hardened2 | false | RKE2 v1.35.5-rc3 | wait-shutdown | stdlib@v1.26.2 | CVE-2026-42499 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-cloud-provider:v1.35.4-0.20260415195656-e51c0636351d-build20260415 | false | RKE2 v1.35.5-rc3 | usr/local/bin/rke2-cloud-provider | google.golang.org/grpc@v1.72.2 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-cloud-provider:v1.35.4-0.20260415195656-e51c0636351d-build20260415 | false | RKE2 v1.35.5-rc3 | usr/local/bin/rke2-cloud-provider | stdlib@v1.25.9 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-cloud-provider:v1.35.4-0.20260415195656-e51c0636351d-build20260415 | false | RKE2 v1.35.5-rc3 | usr/local/bin/rke2-cloud-provider | stdlib@v1.25.9 | CVE-2026-39820 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-cloud-provider:v1.35.4-0.20260415195656-e51c0636351d-build20260415 | false | RKE2 v1.35.5-rc3 | usr/local/bin/rke2-cloud-provider | stdlib@v1.25.9 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-cloud-provider:v1.35.4-0.20260415195656-e51c0636351d-build20260415 | false | RKE2 v1.35.5-rc3 | usr/local/bin/rke2-cloud-provider | stdlib@v1.25.9 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-cloud-provider:v1.35.4-0.20260415195656-e51c0636351d-build20260415 | false | RKE2 v1.35.5-rc3 | usr/local/bin/rke2-cloud-provider | stdlib@v1.25.9 | CVE-2026-42499 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/containerd | github.com/docker/cli@v29.1.5+incompatible | CVE-2025-15558 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/containerd | github.com/docker/docker@v27.3.1+incompatible | CVE-2026-34040 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/containerd | github.com/go-jose/go-jose/v4@v4.1.3 | CVE-2026-34986 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/containerd | go.opentelemetry.io/otel@v1.38.0 | CVE-2026-29181 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/containerd | go.opentelemetry.io/otel/sdk@v1.38.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/containerd | go.opentelemetry.io/otel/sdk@v1.38.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/containerd | google.golang.org/grpc@v1.78.0 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/containerd-shim-runc-v2 | google.golang.org/grpc@v1.78.0 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/crictl | github.com/buger/jsonparser@v1.1.1 | CVE-2026-32285 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/crictl | github.com/docker/docker@v27.1.1+incompatible | CVE-2026-34040 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/crictl | go.opentelemetry.io/otel/sdk@v1.37.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/crictl | go.opentelemetry.io/otel/sdk@v1.37.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/crictl | google.golang.org/grpc@v1.75.0 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/ctr | go.opentelemetry.io/otel@v1.38.0 | CVE-2026-29181 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/ctr | google.golang.org/grpc@v1.78.0 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/kubectl | stdlib@v1.25.9 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/kubectl | stdlib@v1.25.9 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/kubectl | stdlib@v1.25.9 | CVE-2026-39820 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/kubectl | stdlib@v1.25.9 | CVE-2026-39823 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/kubectl | stdlib@v1.25.9 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/kubectl | stdlib@v1.25.9 | CVE-2026-39826 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/kubectl | stdlib@v1.25.9 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/kubectl | stdlib@v1.25.9 | CVE-2026-42499 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/kubelet | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-24051 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/kubelet | go.opentelemetry.io/otel/sdk@v1.36.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/kubelet | google.golang.org/grpc@v1.72.2 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/kubelet | stdlib@v1.25.9 | CVE-2026-33811 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/kubelet | stdlib@v1.25.9 | CVE-2026-33814 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/kubelet | stdlib@v1.25.9 | CVE-2026-39820 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/kubelet | stdlib@v1.25.9 | CVE-2026-39823 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/kubelet | stdlib@v1.25.9 | CVE-2026-39825 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/kubelet | stdlib@v1.25.9 | CVE-2026-39826 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/kubelet | stdlib@v1.25.9 | CVE-2026-39836 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.35.5-rc3-rke2r2 | false | RKE2 v1.35.5-rc3 | bin/kubelet | stdlib@v1.25.9 | CVE-2026-42499 | none | not affected | vulnerable code not in execute path | gobinary |