K3s v1.33.2 - CVE Scans - 2025-07-31

How to use this page

Search:

Image Release Binary/Package Dependency Vulnerability ID (CVE) Severity Status Justification (for status not affected) Type (language or OS)
rancher/klipper-helm:v0.9.7-build20250616 K3s v1.33.2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status helm.sh/helm/v3@v3.18.3 CVE-2025-53547 HIGH affected gobinary
rancher/k3s:v1.33.2-k3s1 K3s v1.33.2 bin/k3s github.com/pion/interceptor@v0.1.37 CVE-2025-49140 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.9.7-build20250616 K3s v1.33.2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis helm.sh/helm/v3@v3.18.3 CVE-2025-53547 none not affected vulnerable code not in execute path gobinary
rancher/local-path-provisioner:v0.0.31 K3s v1.33.2 libcrypto3 libcrypto3@3.3.2-r4 CVE-2024-12797 none not affected vulnerable code cannot be controlled by adversary alpine
rancher/local-path-provisioner:v0.0.31 K3s v1.33.2 libssl3 libssl3@3.3.2-r4 CVE-2024-12797 none not affected vulnerable code cannot be controlled by adversary alpine
rancher/local-path-provisioner:v0.0.31 K3s v1.33.2 usr/bin/local-path-provisioner golang.org/x/net@v0.34.0 CVE-2025-22870 none not affected vulnerable code not present gobinary
rancher/local-path-provisioner:v0.0.31 K3s v1.33.2 usr/bin/local-path-provisioner golang.org/x/net@v0.34.0 CVE-2025-22872 none not affected vulnerable code not present gobinary
rancher/local-path-provisioner:v0.0.31 K3s v1.33.2 usr/bin/local-path-provisioner golang.org/x/oauth2@v0.25.0 CVE-2025-22868 none not affected vulnerable code not present gobinary