[prefer-vendor]SUSE Security Team rates this HIGH, used instead of UNKNOWN (preferred vendor score)
[vendor-vex]Rancher Security team published not_affected for pkg:golang/github.com/harvester/harvester-cloud-provider (vulnerable_code_not_in_execute_path); statement names pkg:golang/stdlib@v1.25.7; component is pkg:golang/stdlib@1.26.5
Rancher Security team says not_affected(vulnerable_code_not_in_execute_path)
Govulncheck determined that the vulnerable code isn't called
product pkg:golang/github.com/harvester/harvester-cloud-provider · published 2026-08-14T02:57:50Z · from https://github.com/rancher/vexhub
matched loosely: statement names pkg:golang/stdlib@v1.25.7; component is pkg:golang/stdlib@1.26.5
[prefer-vendor]SUSE Security Team rates this MEDIUM, used instead of UNKNOWN (preferred vendor score)
[vendor-vex]Rancher Security team published not_affected for pkg:golang/github.com/harvester/harvester-cloud-provider (vulnerable_code_not_in_execute_path); statement names pkg:golang/stdlib@v1.25.7; component is pkg:golang/stdlib@1.26.5
Rancher Security team says not_affected(vulnerable_code_not_in_execute_path)
Govulncheck determined that the vulnerable code isn't called
product pkg:golang/github.com/harvester/harvester-cloud-provider · published 2026-08-14T02:57:50Z · from https://github.com/rancher/vexhub
matched loosely: statement names pkg:golang/stdlib@v1.25.7; component is pkg:golang/stdlib@1.26.5
[prefer-vendor]SUSE Security Team rates this HIGH (preferred vendor score)
[vendor-vex]Rancher Security team published not_affected for pkg:golang/github.com/harvester/harvester-cloud-provider (vulnerable_code_not_in_execute_path); statement names pkg:golang/kubevirt.io/kubevirt@v1.1.0; component is pkg:golang/kubevirt.io%2Fkubevirt@v1.7.4
Rancher Security team says not_affected(vulnerable_code_not_in_execute_path)
This vulnerability is found in the virt-exportserver component which Harvester components do not spin up nor interact directly with during runtime. The kubevirt.io/kubevirt package is a transitive dependency from the github.com/harvester/harvester package. Harvester components only depends on this package for a handful of Go util functions.
product pkg:golang/github.com/harvester/harvester-cloud-provider · published 2026-07-15T23:07:06Z · from https://github.com/rancher/vexhub
matched loosely: statement names pkg:golang/kubevirt.io/kubevirt@v1.1.0; component is pkg:golang/kubevirt.io%2Fkubevirt@v1.7.4
[prefer-vendor]SUSE Security Team rates this HIGH, used instead of UNKNOWN (preferred vendor score)
[vendor-vex]Rancher Security team published not_affected for pkg:golang/github.com/harvester/harvester-cloud-provider (vulnerable_code_not_present); statement names pkg:golang/golang.org/x/crypto@v0.55.0; component is pkg:golang/golang.org%2Fx%2Fcrypto@v0.53.0
Rancher Security team says not_affected(vulnerable_code_not_present)
Govulncheck determined that the vulnerable code isn't called
product pkg:golang/github.com/harvester/harvester-cloud-provider · published 2026-09-11T02:12:52Z · from https://github.com/rancher/vexhub
matched loosely: statement names pkg:golang/golang.org/x/crypto@v0.55.0; component is pkg:golang/golang.org%2Fx%2Fcrypto@v0.53.0
[prefer-vendor]SUSE Security Team rates this HIGH, used instead of UNKNOWN (preferred vendor score)
[vendor-vex]Rancher Security team published not_affected for pkg:golang/github.com/harvester/harvester-cloud-provider (vulnerable_code_not_in_execute_path); statement names pkg:golang/golang.org/x/crypto@v0.38.0; component is pkg:golang/golang.org%2Fx%2Fcrypto@v0.53.0
Rancher Security team says not_affected(vulnerable_code_not_in_execute_path)
Govulncheck determined that the vulnerable code isn't called
product pkg:golang/github.com/harvester/harvester-cloud-provider · published 2026-08-29T02:14:16Z · from https://github.com/rancher/vexhub
matched loosely: statement names pkg:golang/golang.org/x/crypto@v0.38.0; component is pkg:golang/golang.org%2Fx%2Fcrypto@v0.53.0
[prefer-vendor]SUSE Security Team rates this HIGH, used instead of UNKNOWN (preferred vendor score)
[vendor-vex]Rancher Security team published not_affected for pkg:golang/github.com/harvester/harvester-cloud-provider (vulnerable_code_not_present); statement names pkg:golang/golang.org/x/crypto@v0.55.0; component is pkg:golang/golang.org%2Fx%2Fcrypto@v0.53.0
Rancher Security team says not_affected(vulnerable_code_not_present)
Govulncheck determined that the vulnerable code isn't called
product pkg:golang/github.com/harvester/harvester-cloud-provider · published 2026-09-11T02:12:52Z · from https://github.com/rancher/vexhub
matched loosely: statement names pkg:golang/golang.org/x/crypto@v0.55.0; component is pkg:golang/golang.org%2Fx%2Fcrypto@v0.53.0
[prefer-vendor]SUSE Security Team rates this MEDIUM, used instead of UNKNOWN (preferred vendor score)
[vendor-vex]Rancher Security team published not_affected for pkg:golang/github.com/harvester/harvester-cloud-provider (vulnerable_code_not_in_execute_path); statement names pkg:golang/kubevirt.io/kubevirt@v1.1.0; component is pkg:golang/kubevirt.io%2Fkubevirt@v1.7.4
Rancher Security team says not_affected(vulnerable_code_not_in_execute_path)
This vulnerability is a runtime exploit on live virtual machines with active guest agent running. The kubevirt.io/kubevirt package is a transitive dependency from the github.com/harvester/harvester package, which Harvester components uses only for a handful of Go util functions.
product pkg:golang/github.com/harvester/harvester-cloud-provider · published 2026-07-16T16:54:48Z · from https://github.com/rancher/vexhub
matched loosely: statement names pkg:golang/kubevirt.io/kubevirt@v1.1.0; component is pkg:golang/kubevirt.io%2Fkubevirt@v1.7.4
[vendor-vex]Rancher Security team published not_affected for pkg:golang/github.com/harvester/harvester-cloud-provider (vulnerable_code_not_in_execute_path); statement names pkg:golang/kubevirt.io/kubevirt@v1.1.0; component is pkg:golang/kubevirt.io%2Fkubevirt@v1.7.4
Rancher Security team says not_affected(vulnerable_code_not_in_execute_path)
Harvester components have no dependency on the virt-api component for RBAC authorization enforcement. The kubevirt.io/kubevirt package is a transitive dependency from the github.com/harvester/harvester package, which Harvester components uses for a handful of Go util functions.
product pkg:golang/github.com/harvester/harvester-cloud-provider · published 2026-07-16T16:54:48Z · from https://github.com/rancher/vexhub
matched loosely: statement names pkg:golang/kubevirt.io/kubevirt@v1.1.0; component is pkg:golang/kubevirt.io%2Fkubevirt@v1.7.4
RULED OUT(2)— the vulnerable code is not present or cannot run
[vendor-vex]Rancher Security team published not_affected for pkg:golang/github.com/harvester/harvester-cloud-provider (vulnerable_code_not_in_execute_path); statement names pkg:golang/go.etcd.io/etcd/client/pkg/v3@v3.6.4; component is pkg:golang/go.etcd.io%2Fetcd%2Fclient%2Fpkg%2Fv3@v3.5.21
Rancher Security team says not_affected(vulnerable_code_not_in_execute_path)
Govulncheck determined that the vulnerable code isn't called
product pkg:golang/github.com/harvester/harvester-cloud-provider · published 2026-09-11T02:12:52Z · from https://github.com/rancher/vexhub
matched loosely: statement names pkg:golang/go.etcd.io/etcd/client/pkg/v3@v3.6.4; component is pkg:golang/go.etcd.io%2Fetcd%2Fclient%2Fpkg%2Fv3@v3.5.21