registry.rancher.com/rancher/hardened-flannel:v0.28.9-build20260909
image scan · 2 findings
AFFECTED
0
present and loadable
ALREADY VEXED
0
somebody has answered
UNDETERMINED
0
needs a human
RULED OUT
2
not present or unreachable
RULED OUT(2) — the vulnerable code is not present or cannot run
| Severity | Advisory | Package | Version | Location | Fixed in | EPSS | Method | |
|---|---|---|---|---|---|---|---|---|
| UNKNOWN | CVE-2026-73500 | go.etcd.io/etcd/client/pkg/v3 | v3.6.13 | /opt/bin/flanneld | 3.6.14 | 33.2% | pclntab | |
Rancher Security team says not_affected (vulnerable_code_not_present) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/go.etcd.io/etcd/client/pkg/v3@v3.6.13; component is pkg:golang/go.etcd.io%2Fetcd%2Fclient%2Fpkg%2Fv3@v3.6.13 | ||||||||
| UNKNOWN | GO-2026-5932 | golang.org/x/crypto | v0.56.0 | /opt/bin/flanneld | no fix | — | pclntab | |
| ||||||||
Scan coverage#
| Ecosystem | Components | Affected | Vexed | Undetermined | Ruled out | Status |
|---|---|---|---|---|---|---|
golang | 76 | 0 | 0 | 0 | 2 | ok |
os | 68 | 0 | 0 | 0 | 0 | ok |
VEX hubs#
| Hub | Author | Indexes | Matched | Status |
|---|---|---|---|---|
| https://github.com/rancher/vexhub | Rancher Security team | 1168 | 1 | ok |
Triage: scored 1, 0 known exploited, 1 with no CVE id to look up. Feeds as of EPSS 2026-09-14; KEV 2026.09.14.