K3s v1.36.2 - CVE Scans - 2026-07-28

How to use this page

  • You can click a column header to sort by column.
  • Use the search bar below to filter the results by image (and version/tag), release, affected binary, vulnerable dependency (and its version), vulnerability ID (CVE, GHSA, SUSE-SU etc.), severity, status (if affected or not affected/false-positive), justification (for false-positives), vulnerability type (related to the programming language or container OS).
  • The search functionality might execute a bit slow depending on the number of vulnerabilities displayed in the page.
  • False-positive CVEs that are removed with VEX have the status as "not affected" with the severity set to "none", because they do not affect the binary/package/image. The justification explains why they are false-positives, according to the VEX statuses as explained the README.
  • For further information about scanned versions, scanning frequency, tooling and false-positives, please consult the main instructions.
  • The severity (CVSS rating) of some CVEs in the portal might differ from the original severity reported by some vendors and security scanners. This happens, because the K3s team recalculates the CVSS rating based on SUSE's CVE database and according to criteria, like: applicability and difficulty of the issue being exploited in the wild; how it can actually affect the confidentiality, integrity and availability of a K3s cluster etc. CVEs that had their CVSS severity rating changed, either decreased or increased, will have the distinctive tag '*' close to its severity.
Image Release Binary/Package Dependency Vulnerability ID (CVE) Severity Status Justification (for status not affected) Type (language or OS)
rancher/k3s:v1.36.2-k3s1 K3s v1.36.2 bin/k3s github.com/docker/docker@v25.0.15-0.20260325154711-d2dbc0547253+incompatible CVE-2026-33997 HIGH*Severity modified based on SUSE's CVE database and CVSS rating affected gobinary
rancher/k3s:v1.36.2-k3s1 K3s v1.36.2 bin/k3s github.com/docker/docker@v25.0.15-0.20260325154711-d2dbc0547253+incompatible CVE-2026-34040 HIGH affected gobinary
rancher/k3s:v1.36.2-k3s1 K3s v1.36.2 bin/cni stdlib@v1.26.4 CVE-2026-39822 HIGH affected gobinary
rancher/k3s:v1.36.2-k3s1 K3s v1.36.2 bin/k3s github.com/docker/docker@v25.0.15-0.20260325154711-d2dbc0547253+incompatible CVE-2026-42306 HIGH affected gobinary
rancher/k3s:v1.36.2-k3s1 K3s v1.36.2 bin/k3s google.golang.org/grpc@v1.79.3 GHSA-hrxh-6v49-42gf HIGH affected gobinary
rancher/k3s:v1.36.2-k3s1 K3s v1.36.2 bin/containerd-shim-runc-v2 google.golang.org/grpc@v1.80.0 GHSA-hrxh-6v49-42gf HIGH affected gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/net@v0.49.0 CVE-2026-33814 HIGH affected gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/net@v0.49.0 CVE-2026-33814 HIGH affected gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 usr/bin/helm golang.org/x/net@v0.49.0 CVE-2026-33814 HIGH affected gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/net@v0.49.0 CVE-2026-39821 HIGH affected gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/net@v0.49.0 CVE-2026-39821 HIGH affected gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 usr/bin/helm golang.org/x/net@v0.49.0 CVE-2026-39821 HIGH affected gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status stdlib@v1.25.11 CVE-2026-39822 HIGH affected gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 usr/bin/helm stdlib@v1.25.11 CVE-2026-39822 HIGH affected gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.47.0 CVE-2026-39834 HIGH*Severity modified based on SUSE's CVE database and CVSS rating affected gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 usr/bin/helm golang.org/x/crypto@v0.47.0 CVE-2026-39834 HIGH*Severity modified based on SUSE's CVE database and CVSS rating affected gobinary
rancher/local-path-provisioner:v0.0.36 K3s v1.36.2 usr/bin/local-path-provisioner golang.org/x/net@v0.38.0 CVE-2026-33814 HIGH affected gobinary
rancher/local-path-provisioner:v0.0.36 K3s v1.36.2 usr/bin/local-path-provisioner golang.org/x/net@v0.38.0 CVE-2026-39821 HIGH affected gobinary
rancher/local-path-provisioner:v0.0.36 K3s v1.36.2 usr/local/go/bin/go stdlib@v1.26.3 CVE-2026-39822 HIGH affected gobinary
rancher/local-path-provisioner:v0.0.36 K3s v1.36.2 usr/local/go/bin/gofmt stdlib@v1.26.3 CVE-2026-39822 HIGH affected gobinary
rancher/local-path-provisioner:v0.0.36 K3s v1.36.2 usr/local/go/pkg/tool/linux_amd64/asm stdlib@v1.26.3 CVE-2026-39822 HIGH affected gobinary
rancher/local-path-provisioner:v0.0.36 K3s v1.36.2 usr/local/go/pkg/tool/linux_amd64/cgo stdlib@v1.26.3 CVE-2026-39822 HIGH affected gobinary
rancher/local-path-provisioner:v0.0.36 K3s v1.36.2 usr/local/go/pkg/tool/linux_amd64/compile stdlib@v1.26.3 CVE-2026-39822 HIGH affected gobinary
rancher/local-path-provisioner:v0.0.36 K3s v1.36.2 usr/local/go/pkg/tool/linux_amd64/cover stdlib@v1.26.3 CVE-2026-39822 HIGH affected gobinary
rancher/local-path-provisioner:v0.0.36 K3s v1.36.2 usr/local/go/pkg/tool/linux_amd64/fix stdlib@v1.26.3 CVE-2026-39822 HIGH affected gobinary
rancher/local-path-provisioner:v0.0.36 K3s v1.36.2 usr/local/go/pkg/tool/linux_amd64/link stdlib@v1.26.3 CVE-2026-39822 HIGH affected gobinary
rancher/local-path-provisioner:v0.0.36 K3s v1.36.2 usr/local/go/pkg/tool/linux_amd64/preprofile stdlib@v1.26.3 CVE-2026-39822 HIGH affected gobinary
rancher/local-path-provisioner:v0.0.36 K3s v1.36.2 usr/local/go/pkg/tool/linux_amd64/vet stdlib@v1.26.3 CVE-2026-39822 HIGH affected gobinary
rancher/local-path-provisioner:v0.0.36 K3s v1.36.2 libcrypto3 libcrypto3@3.5.6-r0 CVE-2026-45447 HIGH affected alpine
rancher/local-path-provisioner:v0.0.36 K3s v1.36.2 libssl3 libssl3@3.5.6-r0 CVE-2026-45447 HIGH affected alpine
rancher/k3s:v1.36.2-k3s1 K3s v1.36.2 bin/runc golang.org/x/net@v0.43.0 CVE-2026-25681 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.2-k3s1 K3s v1.36.2 bin/runc golang.org/x/net@v0.43.0 CVE-2026-27136 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.2-k3s1 K3s v1.36.2 bin/runc golang.org/x/net@v0.43.0 CVE-2026-33814 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.2-k3s1 K3s v1.36.2 bin/runc golang.org/x/net@v0.43.0 CVE-2026-39821 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.2-k3s1 K3s v1.36.2 bin/containerd-shim-runc-v2 stdlib@v1.26.4 CVE-2026-39822 none not affected vulnerable code not in execute path gobinary
rancher/k3s:v1.36.2-k3s1 K3s v1.36.2 bin/k3s stdlib@v1.26.4 CVE-2026-39822 none not affected vulnerable code not in execute path gobinary
rancher/k3s:v1.36.2-k3s1 K3s v1.36.2 bin/runc stdlib@v1.26.4 CVE-2026-39822 none not affected vulnerable code not in execute path gobinary
rancher/k3s:v1.36.2-k3s1 K3s v1.36.2 bin/k3s golang.org/x/crypto@v0.47.0 CVE-2026-39828 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.2-k3s1 K3s v1.36.2 bin/k3s golang.org/x/crypto@v0.47.0 CVE-2026-39829 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.2-k3s1 K3s v1.36.2 bin/k3s golang.org/x/crypto@v0.47.0 CVE-2026-39830 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.2-k3s1 K3s v1.36.2 bin/k3s golang.org/x/crypto@v0.47.0 CVE-2026-39831 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.2-k3s1 K3s v1.36.2 bin/k3s golang.org/x/crypto@v0.47.0 CVE-2026-39832 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.2-k3s1 K3s v1.36.2 bin/k3s golang.org/x/crypto@v0.47.0 CVE-2026-39835 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.2-k3s1 K3s v1.36.2 bin/k3s github.com/docker/docker@v25.0.15-0.20260325154711-d2dbc0547253+incompatible CVE-2026-41567 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.2-k3s1 K3s v1.36.2 bin/k3s golang.org/x/crypto@v0.47.0 CVE-2026-42508 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.2-k3s1 K3s v1.36.2 bin/k3s golang.org/x/crypto@v0.47.0 CVE-2026-46595 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.2-k3s1 K3s v1.36.2 bin/k3s golang.org/x/crypto@v0.47.0 CVE-2026-46597 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.2-k3s1 K3s v1.36.2 bin/containerd-shim-runc-v2 github.com/containerd/containerd/v2@v2.3.2-k3s2 CVE-2026-53488 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.2-k3s1 K3s v1.36.2 bin/containerd-shim-runc-v2 github.com/containerd/containerd/v2@v2.3.2-k3s2 CVE-2026-53489 none not affected vulnerable code not present gobinary
rancher/k3s:v1.36.2-k3s1 K3s v1.36.2 bin/containerd-shim-runc-v2 github.com/containerd/containerd/v2@v2.3.2-k3s2 CVE-2026-53492 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/net@v0.49.0 CVE-2026-25681 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/net@v0.49.0 CVE-2026-25681 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 usr/bin/helm golang.org/x/net@v0.49.0 CVE-2026-25681 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/net@v0.49.0 CVE-2026-27136 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/net@v0.49.0 CVE-2026-27136 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 usr/bin/helm golang.org/x/net@v0.49.0 CVE-2026-27136 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis stdlib@v1.25.11 CVE-2026-39822 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.47.0 CVE-2026-39828 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.47.0 CVE-2026-39828 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 usr/bin/helm golang.org/x/crypto@v0.47.0 CVE-2026-39828 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.47.0 CVE-2026-39829 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.47.0 CVE-2026-39829 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 usr/bin/helm golang.org/x/crypto@v0.47.0 CVE-2026-39829 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.47.0 CVE-2026-39830 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.47.0 CVE-2026-39830 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 usr/bin/helm golang.org/x/crypto@v0.47.0 CVE-2026-39830 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.47.0 CVE-2026-39831 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.47.0 CVE-2026-39831 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 usr/bin/helm golang.org/x/crypto@v0.47.0 CVE-2026-39831 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.47.0 CVE-2026-39832 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.47.0 CVE-2026-39832 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 usr/bin/helm golang.org/x/crypto@v0.47.0 CVE-2026-39832 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.47.0 CVE-2026-39835 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.47.0 CVE-2026-39835 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 usr/bin/helm golang.org/x/crypto@v0.47.0 CVE-2026-39835 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.47.0 CVE-2026-42508 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.47.0 CVE-2026-42508 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 usr/bin/helm golang.org/x/crypto@v0.47.0 CVE-2026-42508 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.47.0 CVE-2026-46595 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.47.0 CVE-2026-46595 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 usr/bin/helm golang.org/x/crypto@v0.47.0 CVE-2026-46595 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis golang.org/x/crypto@v0.47.0 CVE-2026-46597 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status golang.org/x/crypto@v0.47.0 CVE-2026-46597 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 usr/bin/helm golang.org/x/crypto@v0.47.0 CVE-2026-46597 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis oras.land/oras-go/v2@v2.6.0 CVE-2026-50151 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status oras.land/oras-go/v2@v2.6.0 CVE-2026-50151 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 usr/bin/helm oras.land/oras-go/v2@v2.6.0 CVE-2026-50151 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis oras.land/oras-go/v2@v2.6.0 CVE-2026-50163 none not affected vulnerable code not present gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status oras.land/oras-go/v2@v2.6.0 CVE-2026-50163 none not affected vulnerable code not in execute path gobinary
rancher/klipper-helm:v0.11.1-build20260615 K3s v1.36.2 usr/bin/helm oras.land/oras-go/v2@v2.6.0 CVE-2026-50163 none not affected vulnerable code not in execute path gobinary
rancher/local-path-provisioner:v0.0.36 K3s v1.36.2 usr/bin/local-path-provisioner golang.org/x/net@v0.38.0 CVE-2026-25681 none not affected vulnerable code not present gobinary
rancher/local-path-provisioner:v0.0.36 K3s v1.36.2 usr/bin/local-path-provisioner golang.org/x/net@v0.38.0 CVE-2026-27136 none not affected vulnerable code not present gobinary
rancher/local-path-provisioner:v0.0.36 K3s v1.36.2 usr/bin/local-path-provisioner stdlib@v1.26.3 CVE-2026-27145 none not affected vulnerable code not in execute path gobinary
rancher/local-path-provisioner:v0.0.36 K3s v1.36.2 usr/bin/local-path-provisioner stdlib@v1.26.3 CVE-2026-39822 none not affected vulnerable code not in execute path gobinary
rancher/local-path-provisioner:v0.0.36 K3s v1.36.2 usr/bin/local-path-provisioner stdlib@v1.26.3 CVE-2026-42504 none not affected vulnerable code not in execute path gobinary