registry.rancher.com/rancher/hardened-k8s-metrics-server:v0.9.0-build20260909
image scan · 3 findings
AFFECTED
1
present and loadable
ALREADY VEXED
0
somebody has answered
UNDETERMINED
0
needs a human
RULED OUT
2
not present or unreachable
AFFECTED(1) — vulnerable code is present and can be loaded
| Severity | Advisory | Package | Version | Location | Fixed in | Method | |
|---|---|---|---|---|---|---|---|
| UNKNOWN | GO-2026-6094 | github.com/google/cel-go | v0.29.0 | /metrics-server | 0.30.0 | ||
| |||||||
RULED OUT(2) — the vulnerable code is not present or cannot run
| Severity | Advisory | Package | Version | Location | Fixed in | EPSS | Method | |
|---|---|---|---|---|---|---|---|---|
| UNKNOWN | CVE-2026-73500 | go.etcd.io/etcd/client/pkg/v3 | v3.6.7 | /metrics-server | 3.6.14 | 33.2% | pclntab | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/go.etcd.io/etcd/client/pkg/v3@v3.6.7; component is pkg:golang/go.etcd.io%2Fetcd%2Fclient%2Fpkg%2Fv3@v3.6.7 | ||||||||
| UNKNOWN | GO-2026-5932 | golang.org/x/crypto | v0.56.0 | /metrics-server | no fix | — | pclntab | |
| ||||||||
Scan coverage#
| Ecosystem | Components | Affected | Vexed | Undetermined | Ruled out | Status |
|---|---|---|---|---|---|---|
golang | 98 | 1 | 0 | 0 | 2 | ok |
VEX hubs#
| Hub | Author | Indexes | Matched | Status |
|---|---|---|---|---|
| https://github.com/rancher/vexhub | Rancher Security team | 1168 | 1 | ok |
Triage: scored 1, 0 known exploited, 2 with no CVE id to look up. Feeds as of EPSS 2026-09-14; KEV 2026.09.14.