Search:
| Image | Release | Binary/Package | Dependency | Vulnerability ID (CVE) | Severity | Status | Justification (for status not affected) | Type (language or OS) |
|---|---|---|---|---|---|---|---|---|
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/cni | stdlib@v1.25.7 | CVE-2026-25679 | LOW*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/cni | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/cni | stdlib@v1.25.7 | CVE-2026-32282 | MEDIUM*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/containerd-shim-runc-v2 | stdlib@v1.25.7 | CVE-2026-25679 | LOW*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/containerd-shim-runc-v2 | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/k3s | github.com/go-jose/go-jose/v4@v4.1.3 | CVE-2026-34986 | HIGH | affected | gobinary | |
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/k3s | github.com/nats-io/nats-server/v2@v2.12.2 | CVE-2026-27889 | HIGH | affected | gobinary | |
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/k3s | github.com/nats-io/nats-server/v2@v2.12.2 | CVE-2026-29785 | HIGH | affected | gobinary | |
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/k3s | github.com/nats-io/nats-server/v2@v2.12.2 | CVE-2026-33216 | HIGH | affected | gobinary | |
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/k3s | github.com/nats-io/nats-server/v2@v2.12.2 | CVE-2026-33217 | HIGH | affected | gobinary | |
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/k3s | github.com/nats-io/nats-server/v2@v2.12.2 | CVE-2026-33218 | HIGH | affected | gobinary | |
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/k3s | github.com/nats-io/nats-server/v2@v2.12.2 | CVE-2026-33247 | HIGH | affected | gobinary | |
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/k3s | google.golang.org/grpc@v1.72.2 | CVE-2026-33186 | HIGH*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/k3s | stdlib@v1.25.7 | CVE-2026-25679 | LOW*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/k3s | stdlib@v1.25.7 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260309 | K3s v1.35.3 | libcrypto3 | libcrypto3@3.5.5-r0 | CVE-2026-28390 | HIGH | affected | alpine | |
| rancher/klipper-helm:v0.9.14-build20260309 | K3s v1.35.3 | libssl3 | libssl3@3.5.5-r0 | CVE-2026-28390 | HIGH | affected | alpine | |
| rancher/klipper-helm:v0.9.14-build20260309 | K3s v1.35.3 | musl | musl@1.2.5-r21 | CVE-2026-40200 | HIGH | affected | alpine | |
| rancher/klipper-helm:v0.9.14-build20260309 | K3s v1.35.3 | musl-utils | musl-utils@1.2.5-r21 | CVE-2026-40200 | HIGH | affected | alpine | |
| rancher/klipper-helm:v0.9.14-build20260309 | K3s v1.35.3 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | stdlib@v1.25.8 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260309 | K3s v1.35.3 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | stdlib@v1.25.8 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260309 | K3s v1.35.3 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | stdlib@v1.25.8 | CVE-2026-32282 | MEDIUM*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260309 | K3s v1.35.3 | usr/bin/helm | stdlib@v1.24.11 | CVE-2025-61726 | MEDIUM*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260309 | K3s v1.35.3 | usr/bin/helm | stdlib@v1.24.11 | CVE-2026-25679 | LOW*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260309 | K3s v1.35.3 | usr/bin/helm | stdlib@v1.24.11 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/klipper-helm:v0.9.14-build20260309 | K3s v1.35.3 | usr/bin/helm | stdlib@v1.24.11 | CVE-2025-61730 | LOW*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/klipper-lb:v0.4.15 | K3s v1.35.3 | libcrypto3 | libcrypto3@3.5.5-r0 | CVE-2026-28390 | HIGH | affected | alpine | |
| rancher/klipper-lb:v0.4.15 | K3s v1.35.3 | libssl3 | libssl3@3.5.5-r0 | CVE-2026-28390 | HIGH | affected | alpine | |
| rancher/klipper-lb:v0.4.15 | K3s v1.35.3 | musl | musl@1.2.5-r21 | CVE-2026-40200 | HIGH | affected | alpine | |
| rancher/klipper-lb:v0.4.15 | K3s v1.35.3 | musl-utils | musl-utils@1.2.5-r21 | CVE-2026-40200 | HIGH | affected | alpine | |
| rancher/local-path-provisioner:v0.0.35 | K3s v1.35.3 | libcrypto3 | libcrypto3@3.5.5-r0 | CVE-2026-28390 | HIGH | affected | alpine | |
| rancher/local-path-provisioner:v0.0.35 | K3s v1.35.3 | libssl3 | libssl3@3.5.5-r0 | CVE-2026-28390 | HIGH | affected | alpine | |
| rancher/local-path-provisioner:v0.0.35 | K3s v1.35.3 | musl | musl@1.2.5-r21 | CVE-2026-40200 | HIGH | affected | alpine | |
| rancher/local-path-provisioner:v0.0.35 | K3s v1.35.3 | musl-utils | musl-utils@1.2.5-r21 | CVE-2026-40200 | HIGH | affected | alpine | |
| rancher/local-path-provisioner:v0.0.35 | K3s v1.35.3 | usr/bin/local-path-provisioner | stdlib@v1.26.1 | CVE-2026-32280 | HIGH | affected | gobinary | |
| rancher/local-path-provisioner:v0.0.35 | K3s v1.35.3 | usr/bin/local-path-provisioner | stdlib@v1.26.1 | CVE-2026-33810 | MEDIUM*Severity modified based on SUSE's CVE database and CVSS rating |
affected | gobinary | |
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/containerd-shim-runc-v2 | google.golang.org/grpc@v1.78.0 | CVE-2026-33186 | none | not affected | vulnerable code not present | gobinary |
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/containerd-shim-runc-v2 | stdlib@v1.25.7 | CVE-2026-32282 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/k3s | github.com/buger/jsonparser@v1.1.1 | CVE-2026-32285 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/k3s | github.com/docker/docker@v25.0.8+incompatible | CVE-2026-34040 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/k3s | go.opentelemetry.io/otel/sdk@v1.40.0 | CVE-2026-39883 | none | not affected | vulnerable code not present | gobinary |
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/k3s | stdlib@v1.25.7 | CVE-2026-32282 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/runc | stdlib@v1.25.7 | CVE-2026-25679 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/runc | stdlib@v1.25.7 | CVE-2026-32280 | none | not affected | vulnerable code not present | gobinary |
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/runc | stdlib@v1.25.7 | CVE-2026-32282 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/runc | stdlib@v1.25.7 | CVE-2026-27142 | none | not affected | vulnerable code not present | gobinary |
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/runc | stdlib@v1.25.7 | CVE-2026-32281 | none | not affected | vulnerable code not present | gobinary |
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/runc | stdlib@v1.25.7 | CVE-2026-32288 | none | not affected | vulnerable code not present | gobinary |
| rancher/k3s:v1.35.3-k3s1 | K3s v1.35.3 | bin/runc | stdlib@v1.25.7 | CVE-2026-32289 | none | not affected | vulnerable code not present | gobinary |
| rancher/klipper-helm:v0.9.14-build20260309 | K3s v1.35.3 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | google.golang.org/grpc@v1.72.1 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260309 | K3s v1.35.3 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | stdlib@v1.25.8 | CVE-2026-32282 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260309 | K3s v1.35.3 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | stdlib@v1.25.8 | CVE-2026-32288 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260309 | K3s v1.35.3 | home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis | stdlib@v1.25.8 | CVE-2026-32289 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260309 | K3s v1.35.3 | home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status | google.golang.org/grpc@v1.72.1 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260309 | K3s v1.35.3 | usr/bin/helm | google.golang.org/grpc@v1.72.1 | CVE-2026-33186 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260309 | K3s v1.35.3 | usr/bin/helm | stdlib@v1.24.11 | CVE-2025-68121 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260309 | K3s v1.35.3 | usr/bin/helm | stdlib@v1.24.11 | CVE-2025-61728 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/klipper-helm:v0.9.14-build20260309 | K3s v1.35.3 | usr/bin/helm | stdlib@v1.24.11 | CVE-2026-32282 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/local-path-provisioner:v0.0.35 | K3s v1.35.3 | usr/bin/local-path-provisioner | stdlib@v1.26.1 | CVE-2026-32282 | none | not affected | vulnerable code not in execute path | gobinary |
| rancher/local-path-provisioner:v0.0.35 | K3s v1.35.3 | usr/bin/local-path-provisioner | stdlib@v1.26.1 | CVE-2026-32288 | none | not affected | vulnerable code not present | gobinary |
| rancher/local-path-provisioner:v0.0.35 | K3s v1.35.3 | usr/bin/local-path-provisioner | stdlib@v1.26.1 | CVE-2026-32289 | none | not affected | vulnerable code not present | gobinary |