not scored — this advisory has no CVE id, and both feeds are keyed by CVE
purl
pkg:golang/github.com%2Fgoogle%2Fcel-go@v0.29.0
binary
/snapshot-controller
packages
github.com/google/cel-go/ext (package)
[govulncheck-unavailable]govulncheck is not on PATH, so binary-mode reachability was not tested; install govulncheck to let this finding be ruled not_in_execute_path when its code is unreachable
RULED OUT(4)— the vulnerable code is not present or cannot run
[vendor-vex]Rancher Security team published not_affected for pkg:golang/github.com/kubernetes-csi/external-snapshotter/v8 (vulnerable_code_not_in_execute_path); statement names pkg:golang/go.etcd.io/etcd/client/pkg/v3@v3.6.11; component is pkg:golang/go.etcd.io%2Fetcd%2Fclient%2Fpkg%2Fv3@v3.6.11
Rancher Security team says not_affected(vulnerable_code_not_in_execute_path)
Govulncheck determined that the vulnerable code isn't called
product pkg:golang/github.com/kubernetes-csi/external-snapshotter/v8 · published 2026-09-02T02:30:48Z · from https://github.com/rancher/vexhub
matched loosely: statement names pkg:golang/go.etcd.io/etcd/client/pkg/v3@v3.6.11; component is pkg:golang/go.etcd.io%2Fetcd%2Fclient%2Fpkg%2Fv3@v3.6.11
[prefer-vendor]SUSE Security Team rates this HIGH, used instead of UNKNOWN (preferred vendor score)
[vendor-vex]Rancher Security team published not_affected for pkg:golang/github.com/kubernetes-csi/external-snapshotter/v8 (vulnerable_code_not_present); statement names pkg:golang/golang.org/x/crypto@v0.55.0; component is pkg:golang/golang.org%2Fx%2Fcrypto@v0.55.0
Rancher Security team says not_affected(vulnerable_code_not_present)
Govulncheck determined that the vulnerable code isn't called
product pkg:golang/github.com/kubernetes-csi/external-snapshotter/v8 · published 2026-09-03T02:19:37Z · from https://github.com/rancher/vexhub
matched loosely: statement names pkg:golang/golang.org/x/crypto@v0.55.0; component is pkg:golang/golang.org%2Fx%2Fcrypto@v0.55.0
[prefer-vendor]SUSE Security Team rates this HIGH, used instead of UNKNOWN (preferred vendor score)
[vendor-vex]Rancher Security team published not_affected for pkg:golang/github.com/kubernetes-csi/external-snapshotter/v8 (vulnerable_code_not_present); statement names pkg:golang/golang.org/x/crypto@v0.55.0; component is pkg:golang/golang.org%2Fx%2Fcrypto@v0.55.0
Rancher Security team says not_affected(vulnerable_code_not_present)
Govulncheck determined that the vulnerable code isn't called
product pkg:golang/github.com/kubernetes-csi/external-snapshotter/v8 · published 2026-09-03T02:19:37Z · from https://github.com/rancher/vexhub
matched loosely: statement names pkg:golang/golang.org/x/crypto@v0.55.0; component is pkg:golang/golang.org%2Fx%2Fcrypto@v0.55.0