SUSE Rancher - RKE2 v1.36.2-rc2 version - CVE Scans - 2026-06-16

How to use this page

Search:

Image Mirrored Release Binary/Package Dependency Vulnerability ID (CVE) Severity Status Justification (for status not affected) Type (language or OS)
rancher/hardened-etcd:v3.6.12-k3s1-build20260603 false RKE2 v1.36.2-rc2 usr/local/bin/etcd go.opentelemetry.io/otel@v1.40.0 CVE-2026-29181 HIGH affected gobinary
rancher/hardened-etcd:v3.6.12-k3s1-build20260603 false RKE2 v1.36.2-rc2 usr/local/bin/etcd go.opentelemetry.io/otel/sdk@v1.40.0 CVE-2026-39883 HIGH affected gobinary
rancher/rke2-runtime:v1.36.2-rc2-rke2r1 false RKE2 v1.36.2-rc2 bin/containerd github.com/containerd/containerd/v2@v2.3.1-k3s1 CVE-2026-46680 HIGH affected gobinary
rancher/rke2-runtime:v1.36.2-rc2-rke2r1 false RKE2 v1.36.2-rc2 bin/containerd github.com/docker/docker@v27.3.1+incompatible CVE-2026-33997
HIGH*Severity modified based on SUSE's CVE database and CVSS rating
affected gobinary
rancher/rke2-runtime:v1.36.2-rc2-rke2r1 false RKE2 v1.36.2-rc2 bin/containerd-shim-runc-v2 github.com/containerd/containerd/v2@v2.3.1-k3s1 CVE-2026-46680 HIGH affected gobinary
rancher/rke2-runtime:v1.36.2-rc2-rke2r1 false RKE2 v1.36.2-rc2 bin/ctr github.com/containerd/containerd/v2@v2.3.1-k3s1 CVE-2026-46680 HIGH affected gobinary
rancher/hardened-addon-resizer:1.8.23-build20260604 false RKE2 v1.36.2-rc2 pod_nanny golang.org/x/oauth2@v0.24.0 CVE-2025-22868 none not affected vulnerable code not present gobinary
rancher/hardened-cluster-autoscaler:v1.10.3-build20260604 false RKE2 v1.36.2-rc2 cluster-proportional-autoscaler golang.org/x/oauth2@v0.23.0 CVE-2025-22868 none not affected vulnerable code not present gobinary
rancher/hardened-kubernetes:v1.36.2-rke2r1-build20260612 false RKE2 v1.36.2-rc2 usr/local/bin/kube-apiserver go.opentelemetry.io/otel/sdk@v1.40.0 CVE-2026-39883 none not affected vulnerable code not present gobinary
rancher/hardened-kubernetes:v1.36.2-rke2r1-build20260612 false RKE2 v1.36.2-rc2 usr/local/bin/kube-controller-manager go.opentelemetry.io/otel/sdk@v1.40.0 CVE-2026-39883 none not affected vulnerable code not present gobinary
rancher/hardened-kubernetes:v1.36.2-rke2r1-build20260612 false RKE2 v1.36.2-rc2 usr/local/bin/kube-proxy go.opentelemetry.io/otel/sdk@v1.40.0 CVE-2026-39883 none not affected vulnerable code not present gobinary
rancher/hardened-kubernetes:v1.36.2-rke2r1-build20260612 false RKE2 v1.36.2-rc2 usr/local/bin/kube-scheduler go.opentelemetry.io/otel/sdk@v1.40.0 CVE-2026-39883 none not affected vulnerable code not present gobinary
rancher/hardened-kubernetes:v1.36.2-rke2r1-build20260612 false RKE2 v1.36.2-rc2 usr/local/bin/kubelet go.opentelemetry.io/otel/sdk@v1.40.0 CVE-2026-39883 none not affected vulnerable code not present gobinary
rancher/rke2-cloud-provider:v1.36.1-0.20260508014929-7bbbf7c9b258-build20260515 false RKE2 v1.36.2-rc2 usr/local/bin/rke2-cloud-provider stdlib@v1.26.3 CVE-2026-42504 none not affected vulnerable code not in execute path gobinary
rancher/rke2-runtime:v1.36.2-rc2-rke2r1 false RKE2 v1.36.2-rc2 bin/containerd github.com/docker/docker@v27.3.1+incompatible CVE-2026-34040 none not affected vulnerable code not in execute path gobinary
rancher/rke2-runtime:v1.36.2-rc2-rke2r1 false RKE2 v1.36.2-rc2 bin/containerd github.com/docker/docker@v27.3.1+incompatible CVE-2026-41567 none not affected vulnerable code not in execute path gobinary
rancher/rke2-runtime:v1.36.2-rc2-rke2r1 false RKE2 v1.36.2-rc2 bin/containerd github.com/docker/docker@v27.3.1+incompatible CVE-2026-42306 none not affected vulnerable code not in execute path gobinary
rancher/rke2-runtime:v1.36.2-rc2-rke2r1 false RKE2 v1.36.2-rc2 bin/crictl github.com/docker/docker@v27.1.1+incompatible CVE-2026-34040 none not affected vulnerable code not in execute path gobinary
rancher/rke2-runtime:v1.36.2-rc2-rke2r1 false RKE2 v1.36.2-rc2 bin/crictl github.com/docker/docker@v27.1.1+incompatible CVE-2026-41567 none not affected vulnerable code not in execute path gobinary
rancher/rke2-runtime:v1.36.2-rc2-rke2r1 false RKE2 v1.36.2-rc2 bin/crictl github.com/docker/docker@v27.1.1+incompatible CVE-2026-42306 none not affected vulnerable code not in execute path gobinary
rancher/rke2-runtime:v1.36.2-rc2-rke2r1 false RKE2 v1.36.2-rc2 bin/crictl go.opentelemetry.io/otel/sdk@v1.42.0 CVE-2026-39883 none not affected vulnerable code not present gobinary
rancher/rke2-runtime:v1.36.2-rc2-rke2r1 false RKE2 v1.36.2-rc2 bin/crictl stdlib@v1.26.3 CVE-2026-42504 none not affected vulnerable code not in execute path gobinary
rancher/rke2-runtime:v1.36.2-rc2-rke2r1 false RKE2 v1.36.2-rc2 bin/kubelet go.opentelemetry.io/otel/sdk@v1.40.0 CVE-2026-39883 none not affected vulnerable code not present gobinary
rancher/rke2-runtime:v1.36.2-rc2-rke2r1 false RKE2 v1.36.2-rc2 bin/runc stdlib@v1.25.10 CVE-2026-42504 none not affected vulnerable code not present gobinary