registry.rancher.com/rancher/harvester-csi-driver:v0.2.9
image scan · 118 findings
AFFECTED(48) — vulnerable code is present and can be loaded
| Severity | Advisory | Package | Version | Location | Fixed in | EPSS | Method | |
|---|---|---|---|---|---|---|---|---|
| HIGH | SUSE-SU-2026:22315-1 | libopenssl-3-fips-provider | 0:3.5.0-160000.7.1 | no fix | 88.7% | elf-needed-closure | ||
| ||||||||
| HIGH | SUSE-SU-2026:22315-1 | openssl-3 | 0:3.5.0-160000.7.1 | 3.5.0-160000.8.1 | 88.7% | elf-needed-closure | ||
| ||||||||
| HIGH | SUSE-SU-2026:22582-1 | curl | 0:8.14.1-160000.5.1 | 8.14.1-160000.8.1 | 62.8% | elf-needed-closure | ||
| ||||||||
| HIGH | CVE-2026-33814 | golang.org/x/net | v0.49.0 | /usr/bin/harvester-csi-driver | 0.53.0 | 54.0% | ||
| ||||||||
| HIGH | SUSE-SU-2026:23303-1 | libpython3_13-1_0 | 0:3.13.13-160000.1.1 | no fix | 53.0% | elf-needed-closure | ||
| ||||||||
| MEDIUM | SUSE-SU-2026:22156-1 | curl | 0:8.14.1-160000.5.1 | 8.14.1-160000.6.1 | 51.9% | elf-needed-closure | ||
| ||||||||
| HIGH | CVE-2026-39821 | golang.org/x/net | v0.49.0 | /usr/bin/harvester-csi-driver | 0.55.0 | 50.9% | ||
| ||||||||
| HIGH | CVE-2026-39821 | stdlib | 1.25.10 | /usr/bin/container-suseconnect | 1.25.13 | 50.9% | ||
| ||||||||
| HIGH | CVE-2026-39821 | stdlib | 1.26.3 | /usr/bin/harvester-csi-driver | 1.26.6 | 50.9% | ||
| ||||||||
| UNKNOWN | CVE-2024-31420 | kubevirt.io/kubevirt | v1.7.0 | /usr/bin/harvester-csi-driver | no fix | 49.0% | ||
| ||||||||
| LOW | CVE-2026-27145 | stdlib | 1.25.10 | /usr/bin/container-suseconnect | 1.25.11 | 46.4% | ||
| ||||||||
| HIGH | CVE-2026-33818 | stdlib | 1.25.10 | /usr/bin/container-suseconnect | 1.25.13 | 45.3% | ||
| ||||||||
| HIGH | CVE-2026-33818 | stdlib | 1.26.3 | /usr/bin/harvester-csi-driver | 1.26.6 | 45.3% | ||
| ||||||||
| HIGH | CVE-2026-56853 | stdlib | 1.25.10 | /usr/bin/container-suseconnect | 1.25.13 | 45.3% | ||
| ||||||||
| HIGH | CVE-2026-56859 | stdlib | 1.25.10 | /usr/bin/container-suseconnect | 1.25.13 | 45.3% | ||
| ||||||||
| HIGH | CVE-2026-56862 | stdlib | 1.25.10 | /usr/bin/container-suseconnect | 1.25.13 | 45.3% | ||
| ||||||||
| HIGH | CVE-2026-56862 | stdlib | 1.26.3 | /usr/bin/harvester-csi-driver | 1.26.6 | 45.3% | ||
| ||||||||
| MEDIUM | CVE-2026-42504 | stdlib | 1.25.10 | /usr/bin/container-suseconnect | 1.25.11 | 44.9% | ||
| ||||||||
| MEDIUM | CVE-2025-1767 | k8s.io/kubernetes | v1.34.1 | /usr/bin/harvester-csi-driver | no fix | 44.5% | ||
| ||||||||
| MEDIUM | CVE-2026-56860 | stdlib | 1.25.10 | /usr/bin/container-suseconnect | 1.25.13 | 42.5% | ||
| ||||||||
| MEDIUM | CVE-2026-56860 | stdlib | 1.26.3 | /usr/bin/harvester-csi-driver | 1.26.6 | 42.5% | ||
| ||||||||
| MEDIUM | CVE-2026-56852 | golang.org/x/text | v0.33.0 | /usr/bin/harvester-csi-driver | 0.39.0 | 39.7% | ||
| ||||||||
| HIGH | CVE-2026-84304 | google.golang.org/grpc | v1.79.3 | /usr/bin/harvester-csi-driver | 1.83.1 | 35.0% | ||
| ||||||||
| MEDIUM | CVE-2026-42505 | stdlib | 1.25.10 | /usr/bin/container-suseconnect | 1.25.12 | 31.7% | ||
| ||||||||
| MEDIUM | CVE-2026-42507 | stdlib | 1.25.10 | /usr/bin/container-suseconnect | 1.25.11 | 30.5% | ||
| ||||||||
| MEDIUM | CVE-2024-33394 | kubevirt.io/kubevirt | v1.7.0 | /usr/bin/harvester-csi-driver | no fix | 25.6% | ||
| ||||||||
| LOW | CVE-2024-7598 | k8s.io/kubernetes | v1.34.1 | /usr/bin/harvester-csi-driver | no fix | 24.2% | ||
| ||||||||
| CRITICAL | CVE-2026-84303 | google.golang.org/grpc | v1.79.3 | /usr/bin/harvester-csi-driver | 1.83.1 | 23.7% | ||
| ||||||||
| HIGH | CVE-2026-39822 | stdlib | 1.25.10 | /usr/bin/container-suseconnect | 1.25.12 | 14.2% | ||
| ||||||||
| MEDIUM | CVE-2026-41989 | libgcrypt20 | 0:1.12.1-160000.1.1 | no fix | 8.0% | elf-needed-closure | ||
| ||||||||
| LOW | CVE-2026-41990 | libgcrypt20 | 0:1.12.1-160000.1.1 | no fix | 7.3% | elf-needed-closure | ||
| ||||||||
| HIGH | SUSE-SU-2026:22166-1 | libsqlite3-0 | 0:3.51.3-160000.1.1 | no fix | 7.2% | elf-needed-closure | ||
| ||||||||
| LOW | CVE-2026-57062 | gpg2 | 0:2.5.5-160000.5.1 | 2.5.5-160000.6.1 | 3.9% | elf-needed-closure | ||
| ||||||||
| MEDIUM | CVE-2026-5958 | sed | 0:4.9-160000.2.2 | 4.9-160000.3.1 | 3.8% | elf-needed-closure | ||
| ||||||||
| MEDIUM | CVE-2026-27456 | libblkid1 | 0:2.41.1-160000.3.1 | no fix | 1.9% | elf-needed-closure | ||
| ||||||||
| MEDIUM | CVE-2026-27456 | libfdisk1 | 0:2.41.1-160000.3.1 | no fix | 1.9% | elf-needed-closure | ||
| ||||||||
| MEDIUM | CVE-2026-27456 | libmount1 | 0:2.41.1-160000.3.1 | no fix | 1.9% | elf-needed-closure | ||
| ||||||||
| MEDIUM | CVE-2026-27456 | libsmartcols1 | 0:2.41.1-160000.3.1 | no fix | 1.9% | elf-needed-closure | ||
| ||||||||
| MEDIUM | CVE-2026-27456 | util-linux | 0:2.41.1-160000.3.1 | 2.41.1-160000.4.1 | 1.9% | elf-needed-closure | ||
| ||||||||
| HIGH | CVE-2026-84445 | google.golang.org/grpc | v1.79.3 | /usr/bin/harvester-csi-driver | 1.82.2 | — | ||
| ||||||||
| HIGH | GO-2026-6061 | google.golang.org/grpc | v1.79.3 | /usr/bin/harvester-csi-driver | 1.82.1 | — | ||
| ||||||||
| UNKNOWN | SUSE-SU-2026:22947-1 | libopenssl-3-fips-provider | 0:3.5.0-160000.7.1 | no fix | — | elf-needed-closure | ||
| ||||||||
| UNKNOWN | SUSE-SU-2026:22955-1 | libopenssl-3-fips-provider | 0:3.5.0-160000.7.1 | no fix | — | elf-needed-closure | ||
| ||||||||
| UNKNOWN | SUSE-SU-2026:22947-1 | libopenssl3 | 0:3.5.0-160000.7.1 | no fix | — | elf-needed-closure | ||
| ||||||||
| UNKNOWN | SUSE-SU-2026:22955-1 | libopenssl3 | 0:3.5.0-160000.7.1 | no fix | — | elf-needed-closure | ||
| ||||||||
| UNKNOWN | SUSE-SU-2026:22947-1 | openssl-3 | 0:3.5.0-160000.7.1 | 3.5.0-160000.9.1 | — | elf-needed-closure | ||
| ||||||||
| UNKNOWN | SUSE-SU-2026:22955-1 | openssl-3 | 0:3.5.0-160000.7.1 | 3.5.0-160000.9.1 | — | elf-needed-closure | ||
| ||||||||
| UNKNOWN | SUSE-SU-2026:22331-1 | rpcbind | 0:1.2.7-160000.2.2 | 1.2.9-160000.1.1 | — | elf-needed-closure | ||
| ||||||||
ALREADY VEXED(56) — a published statement answers these; vexscan's own verdict is unchanged
| Severity | Advisory | Package | Version | Location | Fixed in | EPSS | Vendor | Reason | |
|---|---|---|---|---|---|---|---|---|---|
| HIGH | SUSE-SU-2026:22315-1 | libopenssl3 | 0:3.5.0-160000.7.1 | no fix | 88.7% | not_affected | vulnerable_code_not_in_execute_path | ||
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Go CSI driver uses crypto/tls; libopenssl3 is not loaded at runtime product matched loosely: statement names pkg:rpm/suse/libopenssl3; component is pkg:rpm/sles/libopenssl3@0:3.5.0-160000.7.1?arch=x86_64 | |||||||||
| HIGH | SUSE-SU-2026:22582-1 | libcurl4 | 0:8.14.1-160000.5.1 | no fix | 62.8% | not_affected | vulnerable_code_not_in_execute_path | ||
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Go CSI driver uses Go net/http; system libcurl4 not linked or loaded product matched loosely: statement names pkg:rpm/suse/libcurl4; component is pkg:rpm/sles/libcurl4@0:8.14.1-160000.5.1?arch=x86_64 | |||||||||
| HIGH | SUSE-SU-2026:22172-1 | libsolv-tools-base | 0:0.7.36-160000.1.1 | no fix | 55.2% | not_affected | vulnerable_code_not_in_execute_path | ||
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) zypper/libsolv package manager not invoked at container runtime; incidental SLES dep product matched loosely: statement names pkg:rpm/suse/libsolv-tools-base; component is pkg:rpm/sles/libsolv-tools-base@0:0.7.36-160000.1.1?arch=x86_64 | |||||||||
| HIGH | SUSE-SU-2026:22172-1 | libzypp | 0:17.38.5-160000.1.1 | 17.38.13-160000.1.1 | 55.2% | not_affected | vulnerable_code_not_in_execute_path | ||
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Harvester CSI driver is a Go binary; libzypp package management library never invoked product matched loosely: statement names pkg:rpm/suse/libzypp; component is pkg:rpm/sles/libzypp@0:17.38.5-160000.1.1?arch=x86_64 | |||||||||
| HIGH | SUSE-SU-2026:22172-1 | zypper | 0:1.14.95-160000.1.1 | 1.14.98-160000.1.1 | 55.2% | not_affected | vulnerable_code_not_in_execute_path | ||
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) CSI driver is a Go binary; zypper package manager is never invoked at container runtime product matched loosely: statement names pkg:rpm/suse/zypper; component is pkg:rpm/sles/zypper@0:1.14.95-160000.1.1?arch=x86_64 | |||||||||
| HIGH | SUSE-SU-2026:23303-1 | python313-base | 0:3.13.13-160000.1.1 | no fix | 53.0% | not_affected | vulnerable_code_not_in_execute_path | ||
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Python is not used at runtime in this container; it is an incidental SLES base-image dependency product matched loosely: statement names pkg:rpm/suse/python313-base; component is pkg:rpm/sles/python313-base@0:3.13.13-160000.1.1?arch=x86_64 | |||||||||
| CRITICAL | CVE-2026-7374 | kubevirt.io/kubevirt | v1.7.0 | /usr/bin/harvester-csi-driver | 1.7.4 | 52.7% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) This vulnerability is found in the virt-handler component which Harvester components do not spin up nor interact directly with during runtime. The kubevirt.io/kubevirt package is a transitive dependency from the github.com/harvester/harvester package. Harvester components only depends on this package for a handful of Go util functions. product matched loosely: statement names pkg:golang/kubevirt.io/kubevirt@v1.4.0; component is pkg:golang/kubevirt.io%2Fkubevirt@v1.7.0 | |||||||||
| MEDIUM | SUSE-SU-2026:22156-1 | libcurl4 | 0:8.14.1-160000.5.1 | no fix | 51.9% | not_affected | vulnerable_code_not_in_execute_path | ||
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Go CSI driver uses net/http stdlib for HTTP; C libcurl not linked at runtime product matched loosely: statement names pkg:rpm/suse/libcurl4; component is pkg:rpm/sles/libcurl4@0:8.14.1-160000.5.1?arch=x86_64 | |||||||||
| HIGH | SUSE-SU-2026:22636-1 | libxml2-2 | 0:2.13.8-160000.4.1 | no fix | 48.4% | not_affected | vulnerable_code_not_in_execute_path | ||
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Go CSI driver binary does not parse XML via libxml2 at runtime product matched loosely: statement names pkg:rpm/suse/libxml2-2; component is pkg:rpm/sles/libxml2-2@0:2.13.8-160000.4.1?arch=x86_64 | |||||||||
| MEDIUM | CVE-2026-39830 | golang.org/x/crypto | v0.47.0 | /usr/bin/harvester-csi-driver | 0.52.0 | 47.9% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/golang.org/x/crypto@v0.36.0; component is pkg:golang/golang.org%2Fx%2Fcrypto@v0.47.0 | |||||||||
| MEDIUM | SUSE-SU-2026:22322-1 | krb5 | 0:1.21.3-160000.2.2 | 1.21.3-160000.3.1 | 47.3% | not_affected | vulnerable_code_not_in_execute_path | ||
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) CSI driver authenticates via K8s service accounts and TLS; Kerberos is not used product matched loosely: statement names pkg:rpm/suse/krb5; component is pkg:rpm/sles/krb5@0:1.21.3-160000.2.2?arch=x86_64 | |||||||||
| LOW | CVE-2026-27145 | stdlib | 1.26.3 | /usr/bin/harvester-csi-driver | 1.26.4 | 46.4% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Harvester CSI driver connects to K8s/storage APIs; cluster-managed cert SANs not adversary-controlled product matched loosely: statement names pkg:golang/stdlib@v1.26.3; component is pkg:golang/stdlib@1.26.3 | |||||||||
| HIGH | CVE-2026-56853 | stdlib | 1.26.3 | /usr/bin/harvester-csi-driver | 1.26.6 | 45.3% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/stdlib@v1.26.3; component is pkg:golang/stdlib@1.26.3 | |||||||||
| HIGH | CVE-2026-56859 | stdlib | 1.26.3 | /usr/bin/harvester-csi-driver | 1.26.6 | 45.3% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/stdlib@v1.26.3; component is pkg:golang/stdlib@1.26.3 | |||||||||
| MEDIUM | SUSE-SU-2026:22948-1 | libssh4 | 0:0.11.4-160000.1.1 | no fix | 45.3% | not_affected | vulnerable_code_not_in_execute_path | ||
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Go uses crypto/ssh; the system libssh C library is not called at runtime product matched loosely: statement names pkg:rpm/suse/libssh4; component is pkg:rpm/sles/libssh4@0:0.11.4-160000.1.1?arch=x86_64 | |||||||||
| MEDIUM | SUSE-SU-2026:22956-1 | libssh4 | 0:0.11.4-160000.1.1 | no fix | 45.3% | not_affected | vulnerable_code_not_in_execute_path | ||
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Go uses crypto/ssh; the system libssh C library is not called at runtime product matched loosely: statement names pkg:rpm/suse/libssh4; component is pkg:rpm/sles/libssh4@0:0.11.4-160000.1.1?arch=x86_64 | |||||||||
| MEDIUM | CVE-2026-42504 | stdlib | 1.26.3 | /usr/bin/harvester-csi-driver | 1.26.4 | 44.9% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Harvester CSI driver uses gRPC for storage; no MIME encoded-word processing in execute path product matched loosely: statement names pkg:golang/stdlib@v1.26.3; component is pkg:golang/stdlib@1.26.3 | |||||||||
| MEDIUM | CVE-2026-46600 | golang.org/x/net | v0.49.0 | /usr/bin/harvester-csi-driver | 0.56.0 | 44.3% | not_affected | vulnerable_code_not_present | |
Rancher Security team says not_affected (vulnerable_code_not_present) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/golang.org/x/net@v0.38.0; component is pkg:golang/golang.org%2Fx%2Fnet@v0.49.0 | |||||||||
| MEDIUM | CVE-2026-46600 | stdlib | 1.26.3 | /usr/bin/harvester-csi-driver | 1.26.6 | 44.3% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/stdlib@v1.26.3; component is pkg:golang/stdlib@1.26.3 | |||||||||
| HIGH | SUSE-SU-2026:22846-1 | libglib-2_0-0 | 0:2.84.4-160000.2.1 | no fix | 44.1% | not_affected | vulnerable_code_not_in_execute_path | ||
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Go CSI driver binary does not link/use GLib at runtime product matched loosely: statement names pkg:rpm/suse/libglib-2_0-0; component is pkg:rpm/sles/libglib-2_0-0@0:2.84.4-160000.2.1?arch=x86_64 | |||||||||
| HIGH | CVE-2026-39834 | golang.org/x/crypto | v0.47.0 | /usr/bin/harvester-csi-driver | 0.52.0 | 42.9% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/golang.org/x/crypto@v0.36.0; component is pkg:golang/golang.org%2Fx%2Fcrypto@v0.47.0 | |||||||||
| CRITICAL | CVE-2026-54680 | github.com/kube-logging/logging-operator | v0.0.0-20250424202944-7e1f9aad6e21 | /usr/bin/harvester-csi-driver | 0.0.0-20260608145523-cf437d7f1e05 | 42.9% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Harvester does not use use fluentd directly. This Go package is only used to import the SDK CRD type. product matched loosely: statement names pkg:golang/github.com/kube-logging/logging-operator@v0.0.0-20250424202944-7e1f9aad6e21; component is pkg:golang/github.com%2Fkube-logging%2Flogging-operator@v0.0.0-20250424202944-7e1f9aad6e21 | |||||||||
| HIGH | CVE-2026-9804 | kubevirt.io/kubevirt | v1.7.0 | /usr/bin/harvester-csi-driver | no fix | 42.4% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) This vulnerability is found in the virt-exportserver component which Harvester components do not spin up nor interact directly with during runtime. The kubevirt.io/kubevirt package is a transitive dependency from the github.com/harvester/harvester package. Harvester components only depends on this package for a handful of Go util functions. product matched loosely: statement names pkg:golang/kubevirt.io/kubevirt@v1.4.0; component is pkg:golang/kubevirt.io%2Fkubevirt@v1.7.0 | |||||||||
| HIGH | CVE-2026-39835 | golang.org/x/crypto | v0.47.0 | /usr/bin/harvester-csi-driver | 0.52.0 | 41.6% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/golang.org/x/crypto@v0.36.0; component is pkg:golang/golang.org%2Fx%2Fcrypto@v0.47.0 | |||||||||
| HIGH | CVE-2026-46595 | golang.org/x/crypto | v0.47.0 | /usr/bin/harvester-csi-driver | 0.52.0 | 41.5% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/golang.org/x/crypto@v0.36.0; component is pkg:golang/golang.org%2Fx%2Fcrypto@v0.47.0 | |||||||||
| HIGH | CVE-2026-46597 | golang.org/x/crypto | v0.47.0 | /usr/bin/harvester-csi-driver | 0.52.0 | 39.5% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/golang.org/x/crypto@v0.36.0; component is pkg:golang/golang.org%2Fx%2Fcrypto@v0.47.0 | |||||||||
| HIGH | CVE-2026-39829 | golang.org/x/crypto | v0.47.0 | /usr/bin/harvester-csi-driver | 0.52.0 | 39.1% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/golang.org/x/crypto@v0.36.0; component is pkg:golang/golang.org%2Fx%2Fcrypto@v0.47.0 | |||||||||
| HIGH | SUSE-SU-2026:22377-1 | tar | 0:1.35-160000.3.1 | 1.35-160000.4.1 | 38.0% | not_affected | vulnerable_code_not_in_execute_path | ||
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) tar is not executed at runtime; it is an incidental SLES base-image dependency product matched loosely: statement names pkg:rpm/suse/tar; component is pkg:rpm/sles/tar@0:1.35-160000.3.1?arch=x86_64 | |||||||||
| MEDIUM | CVE-2025-69720 | libncurses6 | 0:6.5.20250531-160000.2.2 | no fix | 37.8% | not_affected | vulnerable_code_not_in_execute_path | ||
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Container runs as a daemon without interactive terminal; ncurses is not in the execute path product matched loosely: statement names pkg:rpm/suse/libncurses6; component is pkg:rpm/sles/libncurses6@0:6.5.20250531-160000.2.2?arch=x86_64 | |||||||||
| MEDIUM | CVE-2025-69720 | ncurses-utils | 0:6.5.20250531-160000.2.2 | no fix | 37.8% | not_affected | vulnerable_code_not_in_execute_path | ||
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Container runs as a daemon without interactive terminal; ncurses is not in the execute path product matched loosely: statement names pkg:rpm/suse/ncurses-utils; component is pkg:rpm/sles/ncurses-utils@0:6.5.20250531-160000.2.2?arch=x86_64 | |||||||||
| HIGH | SUSE-SU-2026:22847-1 | perl | 0:5.42.0-160000.2.2 | 5.42.0-160000.3.1 | 37.4% | not_affected | vulnerable_code_not_in_execute_path | ||
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Go CSI driver is the entrypoint; perl interpreter not invoked at runtime product matched loosely: statement names pkg:rpm/suse/perl; component is pkg:rpm/sles/perl@0:5.42.0-160000.2.2?arch=x86_64 | |||||||||
| HIGH | SUSE-SU-2026:22847-1 | perl-base | 0:5.42.0-160000.2.2 | no fix | 37.4% | not_affected | vulnerable_code_not_in_execute_path | ||
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Perl is not used at runtime in this container; it is an incidental SLES base-image dependency product matched loosely: statement names pkg:rpm/suse/perl-base; component is pkg:rpm/sles/perl-base@0:5.42.0-160000.2.2?arch=x86_64 | |||||||||
| HIGH | CVE-2026-39831 | golang.org/x/crypto | v0.47.0 | /usr/bin/harvester-csi-driver | 0.52.0 | 35.5% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/golang.org/x/crypto@v0.36.0; component is pkg:golang/golang.org%2Fx%2Fcrypto@v0.47.0 | |||||||||
| MEDIUM | CVE-2025-13281 | k8s.io/kubernetes | v1.34.1 | /usr/bin/harvester-csi-driver | 1.34.2 | 32.4% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Harvester has not direct dependency on the kube-controller-manager. The k8s.io/kubernetes Go package is a transitive dependency from the github.com/rancher/rancher package. product matched loosely: statement names pkg:golang/k8s.io/kubernetes@v1.31.6; component is pkg:golang/k8s.io%2Fkubernetes@v1.34.1 | |||||||||
| MEDIUM | CVE-2026-42505 | stdlib | 1.26.3 | /usr/bin/harvester-csi-driver | 1.26.5 | 31.7% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Harvester CSI driver uses K8s client-go standard TLS; EncryptedClientHelloConfigList not configured product matched loosely: statement names pkg:golang/stdlib@v1.26.3; component is pkg:golang/stdlib@1.26.3 | |||||||||
| HIGH | CVE-2026-56855 | golang.org/x/crypto | v0.47.0 | /usr/bin/harvester-csi-driver | 0.56.0 | 31.3% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/golang.org/x/crypto@v0.47.0; component is pkg:golang/golang.org%2Fx%2Fcrypto@v0.47.0 | |||||||||
| MEDIUM | CVE-2026-42507 | stdlib | 1.26.3 | /usr/bin/harvester-csi-driver | 1.26.4 | 30.5% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Harvester CSI driver uses gRPC; net/textproto error path not reachable from adversary input product matched loosely: statement names pkg:golang/stdlib@v1.26.3; component is pkg:golang/stdlib@1.26.3 | |||||||||
| HIGH | CVE-2026-39828 | golang.org/x/crypto | v0.47.0 | /usr/bin/harvester-csi-driver | 0.52.0 | 30.3% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/golang.org/x/crypto@v0.36.0; component is pkg:golang/golang.org%2Fx%2Fcrypto@v0.47.0 | |||||||||
| HIGH | CVE-2026-25680 | golang.org/x/net | v0.49.0 | /usr/bin/harvester-csi-driver | 0.55.0 | 25.6% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/golang.org/x/net@v0.38.0; component is pkg:golang/golang.org%2Fx%2Fnet@v0.49.0 | |||||||||
| HIGH | CVE-2026-56854 | golang.org/x/crypto | v0.47.0 | /usr/bin/harvester-csi-driver | 0.55.0 | 25.4% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/golang.org/x/crypto@v0.47.0; component is pkg:golang/golang.org%2Fx%2Fcrypto@v0.47.0 | |||||||||
| MEDIUM | CVE-2026-54411 | pam | 0:1.7.1-160000.3.1 | 1.7.1-160000.5.1 | 24.9% | not_affected | vulnerable_code_not_in_execute_path | ||
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Container authenticates via certificates/tokens/OIDC; the PAM library is not called at runtime product matched loosely: statement names pkg:rpm/suse/pam; component is pkg:rpm/sles/pam@0:1.7.1-160000.3.1?arch=x86_64 | |||||||||
| HIGH | CVE-2026-78662 | golang.org/x/crypto | v0.47.0 | /usr/bin/harvester-csi-driver | 0.56.0 | 24.3% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/golang.org/x/crypto@v0.47.0; component is pkg:golang/golang.org%2Fx%2Fcrypto@v0.47.0 | |||||||||
| MEDIUM | CVE-2026-56858 | stdlib | 1.26.3 | /usr/bin/harvester-csi-driver | 1.26.6 | 23.6% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/stdlib@v1.26.3; component is pkg:golang/stdlib@1.26.3 | |||||||||
| MEDIUM | CVE-2026-39827 | golang.org/x/crypto | v0.47.0 | /usr/bin/harvester-csi-driver | 0.52.0 | 20.3% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/golang.org/x/crypto@v0.36.0; component is pkg:golang/golang.org%2Fx%2Fcrypto@v0.47.0 | |||||||||
| MEDIUM | CVE-2025-14525 | kubevirt.io/kubevirt | v1.7.0 | /usr/bin/harvester-csi-driver | no fix | 19.2% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) This vulnerability is a runtime exploit on live virtual machines with active guest agent running. The kubevirt.io/kubevirt package is a transitive dependency from the github.com/harvester/harvester package, which Harvester components uses only for a handful of Go util functions. product matched loosely: statement names pkg:golang/kubevirt.io/kubevirt@v1.4.0; component is pkg:golang/kubevirt.io%2Fkubevirt@v1.7.0 | |||||||||
| MEDIUM | CVE-2026-58055 | libnghttp2-14 | 0:1.64.0-160000.3.1 | no fix | 16.8% | not_affected | vulnerable_code_not_in_execute_path | ||
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Go CSI driver uses net/http (HTTP/2 in stdlib), not system libnghttp2 product matched loosely: statement names pkg:rpm/suse/libnghttp2-14; component is pkg:rpm/sles/libnghttp2-14@0:1.64.0-160000.3.1?arch=x86_64 | |||||||||
| MEDIUM | CVE-2026-42506 | golang.org/x/net | v0.49.0 | /usr/bin/harvester-csi-driver | 0.55.0 | 14.6% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/golang.org/x/net@v0.38.0; component is pkg:golang/golang.org%2Fx%2Fnet@v0.49.0 | |||||||||
| HIGH | CVE-2026-39822 | stdlib | 1.26.3 | /usr/bin/harvester-csi-driver | 1.26.5 | 14.2% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/stdlib@v1.26.3; component is pkg:golang/stdlib@1.26.3 | |||||||||
| MEDIUM | CVE-2026-27136 | golang.org/x/net | v0.49.0 | /usr/bin/harvester-csi-driver | 0.55.0 | 13.0% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/golang.org/x/net@v0.38.0; component is pkg:golang/golang.org%2Fx%2Fnet@v0.49.0 | |||||||||
| MEDIUM | CVE-2026-42502 | golang.org/x/net | v0.49.0 | /usr/bin/harvester-csi-driver | 0.55.0 | 13.0% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/golang.org/x/net@v0.38.0; component is pkg:golang/golang.org%2Fx%2Fnet@v0.49.0 | |||||||||
| MEDIUM | CVE-2026-25681 | golang.org/x/net | v0.49.0 | /usr/bin/harvester-csi-driver | 0.55.0 | 13.0% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/golang.org/x/net@v0.38.0; component is pkg:golang/golang.org%2Fx%2Fnet@v0.49.0 | |||||||||
| HIGH | SUSE-SU-2026:22821-1 | vim | 0:9.2.0530-160000.1.1 | 9.2.0780-160000.1.1 | 12.1% | not_affected | vulnerable_code_not_in_execute_path | ||
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) vim/vi is not executed at runtime; it is an incidental SLES base-image dependency product matched loosely: statement names pkg:rpm/suse/vim; component is pkg:rpm/sles/vim@0:9.2.0530-160000.1.1?arch=x86_64 | |||||||||
| HIGH | SUSE-SU-2026:22821-1 | xxd | 0:9.2.0530-160000.1.1 | no fix | 12.1% | not_affected | vulnerable_code_not_in_execute_path | ||
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) xxd hex utility is not invoked by the Go-based Harvester CSI driver product matched loosely: statement names pkg:rpm/suse/xxd; component is pkg:rpm/sles/xxd@0:9.2.0530-160000.1.1?arch=x86_64 | |||||||||
| HIGH | CVE-2026-41991 | gzip | 0:1.13-160000.2.2 | 1.13-160000.3.1 | 8.4% | not_affected | vulnerable_code_not_in_execute_path | ||
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Go CSI driver; gzip CLI binary not invoked at runtime product matched loosely: statement names pkg:rpm/suse/gzip; component is pkg:rpm/sles/gzip@0:1.13-160000.2.2?arch=x86_64 | |||||||||
| MEDIUM | CVE-2026-6383 | kubevirt.io/kubevirt | v1.7.0 | /usr/bin/harvester-csi-driver | no fix | 4.5% | not_affected | vulnerable_code_not_in_execute_path | |
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Harvester components have no dependency on the virt-api component for RBAC authorization enforcement. The kubevirt.io/kubevirt package is a transitive dependency from the github.com/harvester/harvester package, which Harvester components uses for a handful of Go util functions. product matched loosely: statement names pkg:golang/kubevirt.io/kubevirt@v1.4.0; component is pkg:golang/kubevirt.io%2Fkubevirt@v1.7.0 | |||||||||
| MEDIUM | CVE-2026-27456 | libuuid1 | 0:2.41.1-160000.3.1 | no fix | 1.9% | not_affected | vulnerable_code_not_in_execute_path | ||
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Go CSI driver uses pure-Go uuid generation, libuuid C library never invoked product matched loosely: statement names pkg:rpm/suse/libuuid1; component is pkg:rpm/sles/libuuid1@0:2.41.1-160000.3.1?arch=x86_64 | |||||||||
RULED OUT(14) — the vulnerable code is not present or cannot run
| Severity | Advisory | Package | Version | Location | Fixed in | EPSS | Method | |
|---|---|---|---|---|---|---|---|---|
| HIGH | CVE-2026-42508 | golang.org/x/crypto | v0.47.0 | /usr/bin/harvester-csi-driver | 0.52.0 | 94.0% | pclntab | |
Rancher Security team says not_affected (vulnerable_code_not_present) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/golang.org/x/crypto@v0.47.0; component is pkg:golang/golang.org%2Fx%2Fcrypto@v0.47.0 | ||||||||
| HIGH | CVE-2026-39832 | golang.org/x/crypto | v0.47.0 | /usr/bin/harvester-csi-driver | 0.52.0 | 46.9% | pclntab | |
Rancher Security team says not_affected (vulnerable_code_not_present) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/golang.org/x/crypto@v0.36.0; component is pkg:golang/golang.org%2Fx%2Fcrypto@v0.47.0 | ||||||||
| MEDIUM | SUSE-SU-2026:22948-1 | libssh-config | 0:0.11.4-160000.1.1 | no fix | 45.3% | pkgdb-no-code | ||
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Go uses crypto/ssh; the system libssh C library is not called at runtime product matched loosely: statement names pkg:rpm/suse/libssh-config; component is pkg:rpm/sles/libssh-config@0:0.11.4-160000.1.1?arch=noarch | ||||||||
| MEDIUM | SUSE-SU-2026:22956-1 | libssh-config | 0:0.11.4-160000.1.1 | no fix | 45.3% | pkgdb-no-code | ||
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Go uses crypto/ssh; the system libssh C library is not called at runtime product matched loosely: statement names pkg:rpm/suse/libssh-config; component is pkg:rpm/sles/libssh-config@0:0.11.4-160000.1.1?arch=noarch | ||||||||
| MEDIUM | CVE-2025-69720 | terminfo-base | 0:6.5.20250531-160000.2.2 | no fix | 37.8% | pkgdb-no-code | ||
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) Container runs as a daemon without interactive terminal; ncurses is not in the execute path product matched loosely: statement names pkg:rpm/suse/terminfo-base; component is pkg:rpm/sles/terminfo-base@0:6.5.20250531-160000.2.2?arch=x86_64 | ||||||||
| HIGH | CVE-2026-46598 | golang.org/x/crypto | v0.47.0 | /usr/bin/harvester-csi-driver | 0.52.0 | 34.7% | pclntab | |
Rancher Security team says not_affected (vulnerable_code_not_present) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/golang.org/x/crypto@v0.36.0; component is pkg:golang/golang.org%2Fx%2Fcrypto@v0.47.0 | ||||||||
| HIGH | CVE-2026-39833 | golang.org/x/crypto | v0.47.0 | /usr/bin/harvester-csi-driver | 0.52.0 | 34.7% | pclntab | |
Rancher Security team says not_affected (vulnerable_code_not_present) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/golang.org/x/crypto@v0.36.0; component is pkg:golang/golang.org%2Fx%2Fcrypto@v0.47.0 | ||||||||
| MEDIUM | CVE-2026-41178 | go.opentelemetry.io/otel | v1.41.0 | /usr/bin/harvester-csi-driver | 1.42.0 | 26.6% | pclntab | |
Rancher Security team says not_affected (vulnerable_code_not_present) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/go.opentelemetry.io/otel@v1.41.0; component is pkg:golang/go.opentelemetry.io%2Fotel@v1.41.0 | ||||||||
| MEDIUM | CVE-2026-56858 | stdlib | 1.25.10 | /usr/bin/container-suseconnect | 1.25.13 | 23.6% | pclntab | |
| ||||||||
| MEDIUM | CVE-2026-56864 | golang.org/x/mod | v0.32.0 | /usr/bin/harvester-csi-driver | 0.40.0 | 22.3% | pclntab | |
Rancher Security team says not_affected (vulnerable_code_not_present) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/golang.org/x/mod@v0.32.0; component is pkg:golang/golang.org%2Fx%2Fmod@v0.32.0 | ||||||||
| HIGH | SUSE-SU-2026:22821-1 | vim-data-common | 0:9.2.0530-160000.1.1 | no fix | 12.1% | pkgdb-no-code | ||
Rancher Security team says not_affected (vulnerable_code_not_in_execute_path) vim/vi is not executed at runtime; it is an incidental SLES base-image dependency product matched loosely: statement names pkg:rpm/suse/vim-data-common; component is pkg:rpm/sles/vim-data-common@0:9.2.0530-160000.1.1?arch=noarch | ||||||||
| UNKNOWN | CVE-2026-39824 | golang.org/x/sys | v0.40.0 | /usr/bin/harvester-csi-driver | 0.44.0 | 1.7% | pclntab | |
Rancher Security team says not_affected (vulnerable_code_not_present) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/golang.org/x/sys@v0.31.0; component is pkg:golang/golang.org%2Fx%2Fsys@v0.40.0 | ||||||||
| HIGH | CVE-2026-56865 | golang.org/x/mod | v0.32.0 | /usr/bin/harvester-csi-driver | 0.40.0 | 1.3% | pclntab | |
Rancher Security team says not_affected (vulnerable_code_not_present) Govulncheck determined that the vulnerable code isn't called product matched loosely: statement names pkg:golang/golang.org/x/mod@v0.32.0; component is pkg:golang/golang.org%2Fx%2Fmod@v0.32.0 | ||||||||
| UNKNOWN | GO-2026-5932 | golang.org/x/crypto | v0.47.0 | /usr/bin/harvester-csi-driver | no fix | — | pclntab | |
| ||||||||
Scan coverage#
| Ecosystem | Components | Affected | Vexed | Undetermined | Ruled out | Status |
|---|---|---|---|---|---|---|
golang | 145 | 26 | 33 | 0 | 10 | ok |
os | 162 | 22 | 23 | 0 | 4 | ok |
pypi | 0 | 0 | 0 | 0 | 0 | ok |
VEX hubs#
| Hub | Author | Indexes | Matched | Status |
|---|---|---|---|---|
| https://github.com/rancher/vexhub | Rancher Security team | 1168 | 68 | ok |
Triage: scored 108, 0 known exploited, 1 not in the EPSS feed, 9 with no CVE id to look up. Feeds as of EPSS 2026-09-14; KEV 2026.09.14.