Vulnerability Reportrancher/k3s:v1.35.6-rc1-k3s1

rancher/k3s:v1.35.6-rc1-k3s1
digestsha256:749878eb77d22e2d2a38edd4f3519b462ebef1ee1b371fb74cc23ec2013dff02

Executive Summary

Last scanned:

Threat Score
74/100CAUTION
Reputation
TRUSTED

This image carries significant risk; production deployment is highly discouraged without strict compensating controls. An attacker with pod creation permissions could achieve arbitrary code execution on the host and in containers via CVE-2026-50195 and CVE-2026-53488. Disabling Container Device Interface (CDI) and avoiding checkpoint restore can mitigate some risks, but containerd must be updated. Note that CVE-2026-53492 only applies when CDI is enabled, which is not default in k3s.

Vulnerabilities

Vulnerability Log

58 total
CVE IDAdjusted SeverityPackageExploit ProbabilityRisk Context
CVE-2026-50195HIGH8.42
github.com/containerd/containerd/v2
v2.2.4-k3s2
fixed in 2.1.9, 2.2.5, 2.3.2
0.3%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-53488HIGH7.48
github.com/containerd/containerd/v2
v2.2.4-k3s2
fixed in 2.0.10, 2.1.9, 2.2.5, 2.3.2
0.2%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-46680MEDIUM6.63
github.com/containerd/containerd/v2
v2.2.4-k3s2
fixed in 2.0.9, 2.2.4, 2.3.1
0.2%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-53492MEDIUM6.53
github.com/containerd/containerd/v2
v2.2.4-k3s2
fixed in 2.1.9, 2.2.5, 2.3.2
0.3%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-33814MEDIUM6.38
golang.org/x/net
v0.47.0
fixed in 0.53.0
0.8%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-46597MEDIUM6.38
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-33814MEDIUM6.38
golang.org/x/net
v0.43.0
fixed in 0.53.0
0.8%
Theoretical Threat
Directly ExposedContext importance: HIGH
CVE-2026-42508MEDIUM6.29
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.6%
Theoretical Threat
Directly Exposed
CVE-2026-42306MEDIUM6.12
github.com/docker/docker
v25.0.15-0.20260325154711-d2dbc0547253+incompatible
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-46595MEDIUM6.03
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-39821MEDIUM5.58
golang.org/x/net
v0.47.0
fixed in 0.55.0
0.7%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-39821MEDIUM5.58
golang.org/x/net
v0.43.0
fixed in 0.55.0
0.7%
Theoretical Threat
Directly ExposedContext importance: MEDIUM
CVE-2026-53489MEDIUM5.52
github.com/containerd/containerd/v2
v2.2.4-k3s2
fixed in 2.1.9, 2.2.5, 2.3.2
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-25680MEDIUM5.52
golang.org/x/net
v0.47.0
fixed in 0.55.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39827MEDIUM5.52
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39834MEDIUM5.52
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-25680MEDIUM5.52
golang.org/x/net
v0.43.0
fixed in 0.55.0
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-42502MEDIUM5.18
golang.org/x/net
v0.47.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42502MEDIUM5.18
golang.org/x/net
v0.43.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-47262MEDIUM4.67
github.com/containerd/containerd/v2
v2.2.4-k3s2
fixed in 2.0.10, 2.1.9, 2.2.5, 2.3.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-39833MEDIUM4.67
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2026-42506MEDIUM4.59
golang.org/x/net
v0.47.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42506MEDIUM4.59
golang.org/x/net
v0.43.0
fixed in 0.55.0
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-42505MEDIUM4.5
stdlib
v1.25.11
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.3%
Theoretical Threat
Directly Exposed
CVE-2026-46598MEDIUM4.5
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Directly Exposed
CVE-2025-47911MEDIUM4.5
golang.org/x/net
v0.43.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2025-58190MEDIUM4.5
golang.org/x/net
v0.43.0
fixed in 0.45.0
0.5%
Theoretical Threat
Directly Exposed
CVE-2026-33186MEDIUM4.37
google.golang.org/grpc
v1.78.0
fixed in 1.79.3
1.6%
Low-Moderate Risk
Post-ExploitContext importance: MEDIUM
CVE-2026-33186MEDIUM4.37
google.golang.org/grpc
v1.72.2
fixed in 1.79.3
1.6%
Low-Moderate Risk
Post-ExploitContext importance: MEDIUM
CVE-2026-41568LOW3.31
github.com/docker/docker
v25.0.15-0.20260325154711-d2dbc0547253+incompatible
No fix yet
0.1%
Theoretical Threat
Directly Exposed
CVE-2026-34040LOW3.23
github.com/docker/docker
v25.0.15-0.20260325154711-d2dbc0547253+incompatible
fixed in 29.3.1
10.1%
High Exploitation Risk
Post-Exploit
CVE-2026-39822LOW3.18
stdlib
v1.25.11
fixed in 1.25.12, 1.26.5, 1.27.0-rc.2
0.2%
Theoretical Threat
Post-ExploitContext importance: MEDIUM
CVE-2026-41579LOW3.06
github.com/opencontainers/runc
v1.4.2
fixed in 1.3.6, 1.4.3, 1.5.0-rc.3
0.2%
Theoretical Threat
Directly Exposed
CVE-2026-39828LOW2.69
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-39832LOW2.66
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-25681LOW2.48
golang.org/x/net
v0.47.0
fixed in 0.55.0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-27136LOW2.48
golang.org/x/net
v0.47.0
fixed in 0.55.0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-33997LOW2.48
github.com/docker/docker
v25.0.15-0.20260325154711-d2dbc0547253+incompatible
fixed in 29.3.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-39831LOW2.48
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-25681LOW2.48
golang.org/x/net
v0.43.0
fixed in 0.55.0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-27136LOW2.48
golang.org/x/net
v0.43.0
fixed in 0.55.0
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-41567LOW2.29
github.com/docker/docker
v25.0.15-0.20260325154711-d2dbc0547253+incompatible
No fix yet
0.2%
Theoretical Threat
Post-Exploit
CVE-2026-40898LOW2.29
github.com/quic-go/quic-go
v0.59.0
fixed in 0.59.1
0.4%
Theoretical Threat
Post-Exploit
CVE-2026-39829LOW2.29
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-39830LOW2.29
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.6%
Theoretical Threat
Post-Exploit
CVE-2026-39835LOW2.29
golang.org/x/crypto
v0.47.0
fixed in 0.52.0
0.5%
Theoretical Threat
Post-Exploit
CVE-2026-46600NONE0
golang.org/x/net
v0.47.0
fixed in 0.56.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39824NONE0
golang.org/x/sys
v0.40.0
fixed in 0.44.0
0.1%
Theoretical Threat
Not Applicable
CVE-2026-56852NONE0
golang.org/x/text
v0.31.0
fixed in 0.39.0
0.4%
Theoretical Threat
Not Applicable
GHSA-hrxh-6v49-42gfNONE0
google.golang.org/grpc
v1.78.0
fixed in 1.82.1
Not Applicable
GHSA-gcjh-h69q-9w9gNONE0
github.com/google/cel-go
v0.26.1
fixed in 0.29.0
Not Applicable
CVE-2026-57497NONE0
github.com/quic-go/webtransport-go
v0.10.0
fixed in 0.11.1
Not Applicable
GO-2026-5932NONE0
golang.org/x/crypto
v0.47.0
No fix yet
Not Applicable
CVE-2026-46600NONE0
golang.org/x/net
v0.55.0
fixed in 0.56.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-56852NONE0
golang.org/x/text
v0.37.0
fixed in 0.39.0
0.4%
Theoretical Threat
Not Applicable
GHSA-hrxh-6v49-42gfNONE0
google.golang.org/grpc
v1.72.2
fixed in 1.82.1
Not Applicable
CVE-2026-46600NONE0
golang.org/x/net
v0.43.0
fixed in 0.56.0
0.3%
Theoretical Threat
Not Applicable
CVE-2026-39824NONE0
golang.org/x/sys
v0.38.0
fixed in 0.44.0
0.1%
Theoretical Threat
Not Applicable

Reachability analysis

Which CVEs are actually reachable — is the vulnerable code even linked and callable.

Locked

Runtime verification

Live-container probes: default user, writable paths, capabilities, exposed ports.

Locked

Hardening recommendations

A step-by-step hardened build plan, with parity tests proving nothing breaks.

Locked

Want to check another image? Run a full scan with the Docker Security Scanner.