SUSE Rancher - RKE2 v1.36.3 version - CVE Scans - 2026-08-08

How to use this page

  • You can click a column header to sort by column.
  • Use the search bar below to filter the results by image (and version/tag), if the image is mirrored or made by SUSE (true/false),
    release, affected binary, vulnerable dependency (and its version), vulnerability ID (CVE, GHSA, SUSE-SU etc.), severity,
    status (if affected or not affected/false-positive), justification (for false-positives),
    vulnerability type (related to the programming language or container OS).
  • The search functionality might execute a bit slow depending on the number of vulnerabilities displayed in the page.
  • False-positive CVEs that are removed with VEX have the status as "not affected" with the severity set to "none",
    because they do not affect the binary/package/image. The justification explains why they are false-positives,
    according to the VEX statuses as explained in KB 000021573.
  • For further instructions about scanned versions, scanning frequency, tooling and false-positives, please consult the main instructions.
  • The severity (CVSS rating) of some CVEs in the portal might differ from the original severity reported by some vendors and security scanners.
    This happens, because SUSE recalculates the CVSS rating of CVEs based on criteria, like: applicability and difficulty of the issue being
    exploited in the wild; how it can actually affect the confidentiality, integrity and availability of SUSE's products etc. CVEs that had their CVSS
    severity rating changed, either decreased or increased, will have the distinctive tag '*' close to its severity.
Image Mirrored Release Binary/Package Dependency Vulnerability ID (CVE) Severity Status Justification (for status not affected) Type (language or OS)
rancher/hardened-traefik:v3.7.8-build20260717 false RKE2 v1.36.3 traefik github.com/traefik/traefik/v3@v3.7.8 CVE-2026-71324 HIGH affected gobinary
rancher/hardened-traefik:v3.7.8-build20260717 false RKE2 v1.36.3 traefik github.com/traefik/traefik/v3@v3.7.8 CVE-2026-71327 HIGH affected gobinary
rancher/hardened-calico:v3.32.1-build20260722 false RKE2 v1.36.3 gzip gzip@1.10-150200.10.1 SUSE-SU-2026:3269-1 none not affected vulnerable code not in execute path sles
rancher/hardened-calico:v3.32.1-build20260722 false RKE2 v1.36.3 libglib-2_0-0 libglib-2_0-0@2.78.6-150600.4.35.1 SUSE-SU-2026:3341-1 none not affected vulnerable code not in execute path sles
rancher/hardened-etcd:v3.6.14-k3s1-build20260723 false RKE2 v1.36.3 usr/local/bin/etcd golang.org/x/text@v0.37.0 CVE-2026-56852 none not affected vulnerable code not in execute path gobinary
rancher/hardened-etcd:v3.6.14-k3s1-build20260723 false RKE2 v1.36.3 usr/local/bin/etcdctl golang.org/x/text@v0.37.0 CVE-2026-56852 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.36.3-rke2r1-build20260723 false RKE2 v1.36.3 usr/local/bin/kube-apiserver golang.org/x/text@v0.38.0 CVE-2026-56852 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.36.3-rke2r1-build20260723 false RKE2 v1.36.3 usr/local/bin/kube-controller-manager golang.org/x/text@v0.38.0 CVE-2026-56852 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.36.3-rke2r1-build20260723 false RKE2 v1.36.3 usr/local/bin/kube-proxy golang.org/x/text@v0.38.0 CVE-2026-56852 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.36.3-rke2r1-build20260723 false RKE2 v1.36.3 usr/local/bin/kube-scheduler golang.org/x/text@v0.38.0 CVE-2026-56852 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.36.3-rke2r1-build20260723 false RKE2 v1.36.3 usr/local/bin/kubectl golang.org/x/text@v0.38.0 CVE-2026-56852 none not affected vulnerable code not in execute path gobinary
rancher/hardened-kubernetes:v1.36.3-rke2r1-build20260723 false RKE2 v1.36.3 usr/local/bin/kubelet golang.org/x/text@v0.38.0 CVE-2026-56852 none not affected vulnerable code not in execute path gobinary
rancher/hardened-traefik:v3.7.8-build20260717 false RKE2 v1.36.3 traefik google.golang.org/grpc@v1.81.1 GHSA-hrxh-6v49-42gf none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.51.0 CVE-2026-39828 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.51.0 CVE-2026-39828 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 usr/bin/helm golang.org/x/crypto@v0.51.0 CVE-2026-39828 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.51.0 CVE-2026-39829 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.51.0 CVE-2026-39829 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 usr/bin/helm golang.org/x/crypto@v0.51.0 CVE-2026-39829 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.51.0 CVE-2026-39830 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.51.0 CVE-2026-39830 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 usr/bin/helm golang.org/x/crypto@v0.51.0 CVE-2026-39830 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.51.0 CVE-2026-39831 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.51.0 CVE-2026-39831 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 usr/bin/helm golang.org/x/crypto@v0.51.0 CVE-2026-39831 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.51.0 CVE-2026-39832 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.51.0 CVE-2026-39832 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 usr/bin/helm golang.org/x/crypto@v0.51.0 CVE-2026-39832 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.51.0 CVE-2026-39835 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.51.0 CVE-2026-39835 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 usr/bin/helm golang.org/x/crypto@v0.51.0 CVE-2026-39835 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.51.0 CVE-2026-42508 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.51.0 CVE-2026-42508 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 usr/bin/helm golang.org/x/crypto@v0.51.0 CVE-2026-42508 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.51.0 CVE-2026-46595 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.51.0 CVE-2026-46595 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 usr/bin/helm golang.org/x/crypto@v0.51.0 CVE-2026-46595 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.51.0 CVE-2026-46597 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.51.0 CVE-2026-46597 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 usr/bin/helm golang.org/x/crypto@v0.51.0 CVE-2026-46597 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis oras.land/oras-go/v2@v2.6.0 CVE-2026-50151 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status oras.land/oras-go/v2@v2.6.0 CVE-2026-50151 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 usr/bin/helm oras.land/oras-go/v2@v2.6.0 CVE-2026-50151 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis oras.land/oras-go/v2@v2.6.0 CVE-2026-50163 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status oras.land/oras-go/v2@v2.6.0 CVE-2026-50163 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 usr/bin/helm oras.land/oras-go/v2@v2.6.0 CVE-2026-50163 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.13.3-build20260727 false RKE2 v1.36.3 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/text@v0.37.0 CVE-2026-56852 none not affected vulnerable code not in execute path gobinary
rancher/rke2-cloud-provider:v1.36.2-0.20260610225606-10b320a3ba51-build20260709 false RKE2 v1.36.3 usr/local/bin/rke2-cloud-provider golang.org/x/crypto@v0.51.0 CVE-2026-39828 none not affected vulnerable code not present gobinary
rancher/rke2-cloud-provider:v1.36.2-0.20260610225606-10b320a3ba51-build20260709 false RKE2 v1.36.3 usr/local/bin/rke2-cloud-provider golang.org/x/crypto@v0.51.0 CVE-2026-39829 none not affected vulnerable code not present gobinary
rancher/rke2-cloud-provider:v1.36.2-0.20260610225606-10b320a3ba51-build20260709 false RKE2 v1.36.3 usr/local/bin/rke2-cloud-provider golang.org/x/crypto@v0.51.0 CVE-2026-39830 none not affected vulnerable code not present gobinary
rancher/rke2-cloud-provider:v1.36.2-0.20260610225606-10b320a3ba51-build20260709 false RKE2 v1.36.3 usr/local/bin/rke2-cloud-provider golang.org/x/crypto@v0.51.0 CVE-2026-39831 none not affected vulnerable code not present gobinary
rancher/rke2-cloud-provider:v1.36.2-0.20260610225606-10b320a3ba51-build20260709 false RKE2 v1.36.3 usr/local/bin/rke2-cloud-provider golang.org/x/crypto@v0.51.0 CVE-2026-39832 none not affected vulnerable code not present gobinary
rancher/rke2-cloud-provider:v1.36.2-0.20260610225606-10b320a3ba51-build20260709 false RKE2 v1.36.3 usr/local/bin/rke2-cloud-provider golang.org/x/crypto@v0.51.0 CVE-2026-39835 none not affected vulnerable code not present gobinary
rancher/rke2-cloud-provider:v1.36.2-0.20260610225606-10b320a3ba51-build20260709 false RKE2 v1.36.3 usr/local/bin/rke2-cloud-provider golang.org/x/crypto@v0.51.0 CVE-2026-42508 none not affected vulnerable code not present gobinary
rancher/rke2-cloud-provider:v1.36.2-0.20260610225606-10b320a3ba51-build20260709 false RKE2 v1.36.3 usr/local/bin/rke2-cloud-provider golang.org/x/crypto@v0.51.0 CVE-2026-46595 none not affected vulnerable code not present gobinary
rancher/rke2-cloud-provider:v1.36.2-0.20260610225606-10b320a3ba51-build20260709 false RKE2 v1.36.3 usr/local/bin/rke2-cloud-provider golang.org/x/crypto@v0.51.0 CVE-2026-46597 none not affected vulnerable code not present gobinary
rancher/rke2-cloud-provider:v1.36.2-0.20260610225606-10b320a3ba51-build20260709 false RKE2 v1.36.3 usr/local/bin/rke2-cloud-provider google.golang.org/grpc@v1.79.3 GHSA-hrxh-6v49-42gf none not affected vulnerable code not in execute path gobinary
rancher/rke2-runtime:v1.36.3-rke2r1 false RKE2 v1.36.3 bin/crictl github.com/docker/docker@v27.1.1+incompatible CVE-2026-34040 none not affected vulnerable code not in execute path gobinary
rancher/rke2-runtime:v1.36.3-rke2r1 false RKE2 v1.36.3 bin/containerd github.com/docker/docker@v27.3.1+incompatible CVE-2026-34040 none not affected vulnerable code not in execute path gobinary
rancher/rke2-runtime:v1.36.3-rke2r1 false RKE2 v1.36.3 bin/crictl github.com/docker/docker@v27.1.1+incompatible CVE-2026-41567 none not affected vulnerable code not present gobinary
rancher/rke2-runtime:v1.36.3-rke2r1 false RKE2 v1.36.3 bin/containerd github.com/docker/docker@v27.3.1+incompatible CVE-2026-41567 none not affected vulnerable code not present gobinary
rancher/rke2-runtime:v1.36.3-rke2r1 false RKE2 v1.36.3 bin/crictl github.com/docker/docker@v27.1.1+incompatible CVE-2026-42306 none not affected vulnerable code not present gobinary
rancher/rke2-runtime:v1.36.3-rke2r1 false RKE2 v1.36.3 bin/containerd github.com/docker/docker@v27.3.1+incompatible CVE-2026-42306 none not affected vulnerable code not present gobinary
rancher/rke2-runtime:v1.36.3-rke2r1 false RKE2 v1.36.3 bin/containerd golang.org/x/text@v0.38.0 CVE-2026-56852 none not affected vulnerable code not in execute path gobinary
rancher/rke2-runtime:v1.36.3-rke2r1 false RKE2 v1.36.3 bin/containerd-shim-runc-v2 golang.org/x/text@v0.38.0 CVE-2026-56852 none not affected vulnerable code not in execute path gobinary
rancher/rke2-runtime:v1.36.3-rke2r1 false RKE2 v1.36.3 bin/ctr golang.org/x/text@v0.38.0 CVE-2026-56852 none not affected vulnerable code not in execute path gobinary
rancher/rke2-runtime:v1.36.3-rke2r1 false RKE2 v1.36.3 bin/kubectl golang.org/x/text@v0.38.0 CVE-2026-56852 none not affected vulnerable code not in execute path gobinary
rancher/rke2-runtime:v1.36.3-rke2r1 false RKE2 v1.36.3 bin/kubelet golang.org/x/text@v0.38.0 CVE-2026-56852 none not affected vulnerable code not in execute path gobinary