Search:
| Image | Mirrored | Release | Binary/Package | Dependency | Vulnerability ID (CVE) | Severity | Status | Justification (for status not affected) | Type (language or OS) |
|---|---|---|---|---|---|---|---|---|---|
| rancher/hardened-etcd:v3.6.12-k3s1-build20260603 | false | RKE2 v1.36.2-rc2 | usr/local/bin/etcd | go.opentelemetry.io/otel@v1.40.0 | CVE-2026-29181 | HIGH | affected | gobinary | |
| rancher/hardened-etcd:v3.6.12-k3s1-build20260603 | false | RKE2 v1.36.2-rc2 | usr/local/bin/etcd | go.opentelemetry.io/otel/sdk@v1.40.0 | CVE-2026-39883 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.36.2-rc2-rke2r1 | false | RKE2 v1.36.2-rc2 | bin/containerd | github.com/containerd/containerd/v2@v2.3.1-k3s1 | CVE-2026-46680 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.36.2-rc2-rke2r1 | false | RKE2 v1.36.2-rc2 | bin/containerd | github.com/docker/docker@v27.3.1+incompatible | CVE-2026-33997 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/rke2-runtime:v1.36.2-rc2-rke2r1 | false | RKE2 v1.36.2-rc2 | bin/containerd-shim-runc-v2 | github.com/containerd/containerd/v2@v2.3.1-k3s1 | CVE-2026-46680 | HIGH | affected | gobinary | |
| rancher/rke2-runtime:v1.36.2-rc2-rke2r1 | false | RKE2 v1.36.2-rc2 | bin/ctr | github.com/containerd/containerd/v2@v2.3.1-k3s1 | CVE-2026-46680 | HIGH | affected | gobinary | |
| rancher/hardened-addon-resizer:1.8.23-build20260604 | false | RKE2 v1.36.2-rc2 | pod_nanny | golang.org/x/oauth2@v0.24.0 | CVE-2025-22868 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-cluster-autoscaler:v1.10.3-build20260604 | false | RKE2 v1.36.2-rc2 | cluster-proportional-autoscaler | golang.org/x/oauth2@v0.23.0 | CVE-2025-22868 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.36.2-rke2r1-build20260612 | false | RKE2 v1.36.2-rc2 | usr/local/bin/kube-apiserver | go.opentelemetry.io/otel/sdk@v1.40.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.36.2-rke2r1-build20260612 | false | RKE2 v1.36.2-rc2 | usr/local/bin/kube-controller-manager | go.opentelemetry.io/otel/sdk@v1.40.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.36.2-rke2r1-build20260612 | false | RKE2 v1.36.2-rc2 | usr/local/bin/kube-proxy | go.opentelemetry.io/otel/sdk@v1.40.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.36.2-rke2r1-build20260612 | false | RKE2 v1.36.2-rc2 | usr/local/bin/kube-scheduler | go.opentelemetry.io/otel/sdk@v1.40.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/hardened-kubernetes:v1.36.2-rke2r1-build20260612 | false | RKE2 v1.36.2-rc2 | usr/local/bin/kubelet | go.opentelemetry.io/otel/sdk@v1.40.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-cloud-provider:v1.36.1-0.20260508014929-7bbbf7c9b258-build20260515 | false | RKE2 v1.36.2-rc2 | usr/local/bin/rke2-cloud-provider | stdlib@v1.26.3 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.36.2-rc2-rke2r1 | false | RKE2 v1.36.2-rc2 | bin/containerd | github.com/docker/docker@v27.3.1+incompatible | CVE-2026-34040 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.36.2-rc2-rke2r1 | false | RKE2 v1.36.2-rc2 | bin/containerd | github.com/docker/docker@v27.3.1+incompatible | CVE-2026-41567 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.36.2-rc2-rke2r1 | false | RKE2 v1.36.2-rc2 | bin/containerd | github.com/docker/docker@v27.3.1+incompatible | CVE-2026-42306 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.36.2-rc2-rke2r1 | false | RKE2 v1.36.2-rc2 | bin/crictl | github.com/docker/docker@v27.1.1+incompatible | CVE-2026-34040 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.36.2-rc2-rke2r1 | false | RKE2 v1.36.2-rc2 | bin/crictl | github.com/docker/docker@v27.1.1+incompatible | CVE-2026-41567 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.36.2-rc2-rke2r1 | false | RKE2 v1.36.2-rc2 | bin/crictl | github.com/docker/docker@v27.1.1+incompatible | CVE-2026-42306 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.36.2-rc2-rke2r1 | false | RKE2 v1.36.2-rc2 | bin/crictl | go.opentelemetry.io/otel/sdk@v1.42.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.36.2-rc2-rke2r1 | false | RKE2 v1.36.2-rc2 | bin/crictl | stdlib@v1.26.3 | CVE-2026-42504 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/rke2-runtime:v1.36.2-rc2-rke2r1 | false | RKE2 v1.36.2-rc2 | bin/kubelet | go.opentelemetry.io/otel/sdk@v1.40.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/rke2-runtime:v1.36.2-rc2-rke2r1 | false | RKE2 v1.36.2-rc2 | bin/runc | stdlib@v1.25.10 | CVE-2026-42504 | none | not affected | vulnerable code not present | gobinary |