Vulnerability Reportrancher/k3s:v1.33.12-k3s1

rancher/k3s:v1.33.12-k3s1
digestsha256:173eb786fa098114e49b4e3f9a2a711602451ef884961b0a821015f068e08209

Executive Summary

Last scanned:

Threat Score
75/100DANGEROUS
Reputation
TRUSTED

This image poses a critical security risk and must not be used in production, especially as an internet-facing service. Exploitation could allow an attacker to bypass gRPC authorization (CVE-2026-33186) and gain unauthorized access to sensitive data or execute arbitrary code via container image cache poisoning (CVE-2026-50195). Note: CVE-2026-33186 only applies if path-based authorization interceptors are configured, and CVE-2026-50195 requires the attacker to have pod creation permissions. Despite originating from a trusted publisher, the presence of these high-severity vulnerabilities warrants immediate remediation or image replacement.

Vulnerabilities

Vulnerability Log

82 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-33186HIGH7.28
google.golang.org/grpc
v1.78.0
fixed in 1.79.3
1.6%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-33186HIGH7.28
google.golang.org/grpc
v1.72.1
fixed in 1.79.3
1.6%
Low-Moderate Risk
Directly ExposedContext importance: MEDIUM
CVE-2026-50195MEDIUM6.74
github.com/containerd/containerd/v2
v2.2.3-k3s1.33
fixed in 2.1.9, 2.2.5, 2.3.2
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-53492MEDIUM6.53
github.com/containerd/containerd/v2
v2.2.3-k3s1.33
fixed in 2.1.9, 2.2.5, 2.3.2
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-39836MEDIUM6.38
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42499MEDIUM6.38
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly Exposed
CVE-2026-42504MEDIUM6.38
stdlib
v1.25.9
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-41567MEDIUM6.38
github.com/docker/docker
v25.0.15-0.20260325154711-d2dbc0547253+incompatible
No fix yet
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-40898MEDIUM6.38
github.com/quic-go/quic-go
v0.59.0
fixed in 0.59.1
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39829MEDIUM6.38
golang.org/x/crypto
v0.36.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-39830MEDIUM6.38
golang.org/x/crypto
v0.36.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-39835MEDIUM6.38
golang.org/x/crypto
v0.36.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-46597MEDIUM6.38
golang.org/x/crypto
v0.36.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42508MEDIUM6.29
golang.org/x/crypto
v0.36.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42306MEDIUM6.12
github.com/docker/docker
v25.0.15-0.20260325154711-d2dbc0547253+incompatible
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-46595MEDIUM6.03
golang.org/x/crypto
v0.36.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-53488MEDIUM5.98
github.com/containerd/containerd/v2
v2.2.3-k3s1.33
fixed in 2.0.10, 2.1.9, 2.2.5, 2.3.2
0.2%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-39821MEDIUM5.58
golang.org/x/net
v0.47.0
fixed in 0.55.0
0.7%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-39821MEDIUM5.58
golang.org/x/net
v0.50.0
fixed in 0.55.0
0.7%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-39821MEDIUM5.58
golang.org/x/net
v0.43.0
fixed in 0.55.0
0.7%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-39825MEDIUM5.52
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-53489MEDIUM5.52
github.com/containerd/containerd/v2
v2.2.3-k3s1.33
fixed in 2.1.9, 2.2.5, 2.3.2
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-25680MEDIUM5.52
golang.org/x/net
v0.47.0
fixed in 0.55.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39827MEDIUM5.52
golang.org/x/crypto
v0.36.0
fixed in 0.52.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39834MEDIUM5.52
golang.org/x/crypto
v0.36.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-25680MEDIUM5.52
golang.org/x/net
v0.50.0
fixed in 0.55.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-25680MEDIUM5.52
golang.org/x/net
v0.43.0
fixed in 0.55.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39822MEDIUM5.3
stdlib
v1.25.9
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-46680MEDIUM5.3
github.com/containerd/containerd/v2
v2.2.3-k3s1.33
fixed in 2.0.9, 2.2.4, 2.3.1
0.2%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-42502MEDIUM5.18
golang.org/x/net
v0.47.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42502MEDIUM5.18
golang.org/x/net
v0.50.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42502MEDIUM5.18
golang.org/x/net
v0.43.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-27145MEDIUM5.1
stdlib
v1.25.9
fixed in 1.25.11, 1.26.4
0.6%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33811MEDIUM5.1
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33814MEDIUM5.1
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33814MEDIUM5.1
golang.org/x/net
v0.47.0
fixed in 0.53.0
0.8%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33814MEDIUM5.1
golang.org/x/net
v0.50.0
fixed in 0.53.0
0.8%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33814MEDIUM5.1
golang.org/x/net
v0.43.0
fixed in 0.53.0
0.8%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-47262MEDIUM4.67
github.com/containerd/containerd/v2
v2.2.3-k3s1.33
fixed in 2.0.10, 2.1.9, 2.2.5, 2.3.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39833MEDIUM4.67
golang.org/x/crypto
v0.36.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-39823MEDIUM4.59
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39826MEDIUM4.59
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42506MEDIUM4.59
golang.org/x/net
v0.47.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42506MEDIUM4.59
golang.org/x/net
v0.50.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42506MEDIUM4.59
golang.org/x/net
v0.43.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42505MEDIUM4.5
stdlib
v1.25.9
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42507MEDIUM4.5
stdlib
v1.25.9
fixed in 1.25.11, 1.26.4
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-47914MEDIUM4.5
golang.org/x/crypto
v0.36.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58181MEDIUM4.5
golang.org/x/crypto
v0.36.0
fixed in 0.45.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-46598MEDIUM4.5
golang.org/x/crypto
v0.36.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-27141MEDIUM4.5
golang.org/x/net
v0.50.0
fixed in 0.51.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-47911MEDIUM4.5
golang.org/x/net
v0.43.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58190MEDIUM4.5
golang.org/x/net
v0.43.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-41568LOW3.31
github.com/docker/docker
v25.0.15-0.20260325154711-d2dbc0547253+incompatible
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-34040LOW3.23
github.com/docker/docker
v25.0.15-0.20260325154711-d2dbc0547253+incompatible
fixed in 29.3.1
10.1%
High Exploitation Risk
Post-Exploit
CVE-2026-41579LOW3.06
github.com/opencontainers/runc
v1.4.2
fixed in 1.3.6, 1.4.3, 1.5.0-rc.3
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-39828LOW2.69
golang.org/x/crypto
v0.36.0
fixed in 0.52.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-39832LOW2.66
golang.org/x/crypto
v0.36.0
fixed in 0.52.0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-25681LOW2.48
golang.org/x/net
v0.47.0
fixed in 0.55.0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-27136LOW2.48
golang.org/x/net
v0.47.0
fixed in 0.55.0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-33997LOW2.48
github.com/docker/docker
v25.0.15-0.20260325154711-d2dbc0547253+incompatible
fixed in 29.3.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-39831LOW2.48
golang.org/x/crypto
v0.36.0
fixed in 0.52.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-25681LOW2.48
golang.org/x/net
v0.50.0
fixed in 0.55.0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-27136LOW2.48
golang.org/x/net
v0.50.0
fixed in 0.55.0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-25681LOW2.48
golang.org/x/net
v0.43.0
fixed in 0.55.0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-27136LOW2.48
golang.org/x/net
v0.43.0
fixed in 0.55.0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-39820LOW2.29
stdlib
v1.25.9
fixed in 1.25.10, 1.26.3
0.8%
Theoretical Threat
Post-Exploit
CVE-2025-47913LOW2.29
golang.org/x/crypto
v0.36.0
fixed in 0.43.0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-46600NONE0
golang.org/x/net
v0.47.0
fixed in 0.56.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39824NONE0
golang.org/x/sys
v0.40.0
fixed in 0.44.0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56852NONE0
golang.org/x/text
v0.31.0
fixed in 0.39.0
0.4%
Theoretical Threat
Not Applicable
GHSA-hrxh-6v49-42gfNONE0
google.golang.org/grpc
v1.78.0
fixed in 1.82.1
Not Applicable
GHSA-gcjh-h69q-9w9gNONE0
github.com/google/cel-go
v0.26.0
fixed in 0.29.0
Not Applicable
CVE-2026-42328NONE0
github.com/ipld/go-ipld-prime
v0.22.0
fixed in 0.23.0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-57497NONE0
github.com/quic-go/webtransport-go
v0.10.0
fixed in 0.11.1
Not Applicable
GO-2026-5932NONE0
golang.org/x/crypto
v0.36.0
No fix yet
Not Applicable
CVE-2026-46600NONE0
golang.org/x/net
v0.50.0
fixed in 0.56.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39824NONE0
golang.org/x/sys
v0.41.0
fixed in 0.44.0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56852NONE0
golang.org/x/text
v0.36.0
fixed in 0.39.0
0.4%
Theoretical Threat
Not Applicable
GHSA-hrxh-6v49-42gfNONE0
google.golang.org/grpc
v1.72.1
fixed in 1.82.1
Not Applicable
CVE-2026-46600NONE0
golang.org/x/net
v0.43.0
fixed in 0.56.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39824NONE0
golang.org/x/sys
v0.38.0
fixed in 0.44.0
0.1%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.