Vulnerability Reportrancher/k3s:v1.33.13-rc1-k3s1

rancher/k3s:v1.33.13-rc1-k3s1
digestsha256:29238ac61fd24f886101b332fad3c78d3da04bd202be3852f81e5f48965c4e2a

Executive Summary

Last scanned:

Threat Score
100/100DANGEROUS
Reputation
TRUSTED

This image poses a critical security risk and must not be used in production, especially as an internet-facing service. An attacker could exploit CVE-2026-33186 to bypass authorization in gRPC, gaining unauthorized access to sensitive endpoints, or use CVE-2026-50195 to poison the local image cache and execute arbitrary code in victim pods. Additionally, CVE-2026-53488 may allow arbitrary command execution on the host through malicious image labels. Note that CVE-2026-53492 (CDI annotation smuggling) only applies if Container Device Interface (CDI) is enabled on the node; ensure CDI is disabled if this image is used in a controlled environment. Upgrading to patched versions of gRPC and containerd is essential to mitigate these risks.

Vulnerabilities

Vulnerability Log

58 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-33186CRITICAL9.1
google.golang.org/grpc
v1.78.0
fixed in 1.79.3
1.6%
Low-Moderate Risk
Directly ExposedContext importance: HIGH
CVE-2026-33186CRITICAL9.1
google.golang.org/grpc
v1.72.1
fixed in 1.79.3
1.6%
Low-Moderate Risk
Directly ExposedContext importance: HIGH
CVE-2026-50195HIGH8.42
github.com/containerd/containerd/v2
v2.2.4-k3s1.33
fixed in 2.1.9, 2.2.5, 2.3.2
0.3%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-53492HIGH8.16
github.com/containerd/containerd/v2
v2.2.4-k3s1.33
fixed in 2.1.9, 2.2.5, 2.3.2
0.3%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-53488HIGH7.48
github.com/containerd/containerd/v2
v2.2.4-k3s1.33
fixed in 2.0.10, 2.1.9, 2.2.5, 2.3.2
0.2%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-39822MEDIUM6.63
stdlib
v1.25.11
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-46680MEDIUM6.63
github.com/containerd/containerd/v2
v2.2.4-k3s1.33
fixed in 2.0.9, 2.2.4, 2.3.1
0.2%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-46597MEDIUM6.38
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-42508MEDIUM6.29
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42306MEDIUM6.12
github.com/docker/docker
v25.0.15-0.20260325154711-d2dbc0547253+incompatible
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-46595MEDIUM6.03
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-39821MEDIUM5.58
golang.org/x/net
v0.47.0
fixed in 0.55.0
0.7%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-39821MEDIUM5.58
golang.org/x/net
v0.43.0
fixed in 0.55.0
0.7%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-53489MEDIUM5.52
github.com/containerd/containerd/v2
v2.2.4-k3s1.33
fixed in 2.1.9, 2.2.5, 2.3.2
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-25680MEDIUM5.52
golang.org/x/net
v0.47.0
fixed in 0.55.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39827MEDIUM5.52
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39834MEDIUM5.52
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-25680MEDIUM5.52
golang.org/x/net
v0.43.0
fixed in 0.55.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42502MEDIUM5.18
golang.org/x/net
v0.47.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42502MEDIUM5.18
golang.org/x/net
v0.43.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-47262MEDIUM4.67
github.com/containerd/containerd/v2
v2.2.4-k3s1.33
fixed in 2.0.10, 2.1.9, 2.2.5, 2.3.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39833MEDIUM4.67
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42506MEDIUM4.59
golang.org/x/net
v0.47.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42506MEDIUM4.59
golang.org/x/net
v0.43.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42505MEDIUM4.5
stdlib
v1.25.11
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-46598MEDIUM4.5
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-47911MEDIUM4.5
golang.org/x/net
v0.43.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58190MEDIUM4.5
golang.org/x/net
v0.43.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-41568LOW3.31
github.com/docker/docker
v25.0.15-0.20260325154711-d2dbc0547253+incompatible
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-34040LOW3.23
github.com/docker/docker
v25.0.15-0.20260325154711-d2dbc0547253+incompatible
fixed in 29.3.1
10.1%
High Exploitation Risk
Post-Exploit
CVE-2026-41579LOW3.06
github.com/opencontainers/runc
v1.4.2
fixed in 1.3.6, 1.4.3, 1.5.0-rc.3
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-39828LOW2.69
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-39832LOW2.66
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-25681LOW2.48
golang.org/x/net
v0.47.0
fixed in 0.55.0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-27136LOW2.48
golang.org/x/net
v0.47.0
fixed in 0.55.0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-33997LOW2.48
github.com/docker/docker
v25.0.15-0.20260325154711-d2dbc0547253+incompatible
fixed in 29.3.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-39831LOW2.48
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-25681LOW2.48
golang.org/x/net
v0.43.0
fixed in 0.55.0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-27136LOW2.48
golang.org/x/net
v0.43.0
fixed in 0.55.0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-33814LOW2.29
golang.org/x/net
v0.47.0
fixed in 0.53.0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-41567LOW2.29
github.com/docker/docker
v25.0.15-0.20260325154711-d2dbc0547253+incompatible
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-40898LOW2.29
github.com/quic-go/quic-go
v0.59.0
fixed in 0.59.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-39829LOW2.29
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-39830LOW2.29
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-39835LOW2.29
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-33814LOW2.29
golang.org/x/net
v0.43.0
fixed in 0.53.0
0.8%
Theoretical Threat
Post-Exploit
CVE-2026-46600NONE0
golang.org/x/net
v0.47.0
fixed in 0.56.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39824NONE0
golang.org/x/sys
v0.40.0
fixed in 0.44.0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56852NONE0
golang.org/x/text
v0.31.0
fixed in 0.39.0
0.4%
Theoretical Threat
Not Applicable
GHSA-hrxh-6v49-42gfNONE0
google.golang.org/grpc
v1.78.0
fixed in 1.82.1
Not Applicable
GHSA-gcjh-h69q-9w9gNONE0
github.com/google/cel-go
v0.26.0
fixed in 0.29.0
Not Applicable
CVE-2026-57497NONE0
github.com/quic-go/webtransport-go
v0.10.0
fixed in 0.11.1
Not Applicable
GO-2026-5932NONE0
golang.org/x/crypto
v0.47.0
No fix yet
Not Applicable
CVE-2026-46600NONE0
golang.org/x/net
v0.55.0
fixed in 0.56.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-56852NONE0
golang.org/x/text
v0.37.0
fixed in 0.39.0
0.4%
Theoretical Threat
Not Applicable
GHSA-hrxh-6v49-42gfNONE0
google.golang.org/grpc
v1.72.1
fixed in 1.82.1
Not Applicable
CVE-2026-46600NONE0
golang.org/x/net
v0.43.0
fixed in 0.56.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39824NONE0
golang.org/x/sys
v0.38.0
fixed in 0.44.0
0.1%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Supply chain analysis

Base-image lineage, package provenance and signatures — nothing slipped in unnoticed.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.