registry.rancher.com/rancher/klipper-helm:v0.13.3-build20260909 image scan · 4 findings
⚠ 1 finding to act on — 1 medium
AFFECTED(1) — vulnerable code is present and can be loaded Severity Advisory Package Version Location Fixed in EPSS Method ▸ MEDIUM CVE-2026-35206 helm.sh/helm/v4 v0.13.3-build20260909 /usr/bin/helm 4.1.4 9.8% advisory CVE-2026-35206 (also GHSA-hr2v-4r36-88hr ) from golang severity MEDIUM CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L fixed in 4.1.4 epss 9.8% 9.8% percentile (epss 0.00199) purl pkg:golang/helm.sh%2Fhelm%2Fv4@v0.13.3-build20260909 binary /usr/bin/helm (stripped) packages helm.sh/helm/v4 (module) [image-tag-version] version not in build info (reported (devel)); inferred from image tag "v0.13.3-build20260909" -- the image name contains the module name (helm) [prefer-vendor] SUSE Security Team rates this MEDIUM (preferred vendor score)
RULED OUT(3) — the vulnerable code is not present or cannot run Severity Advisory Package Version Location Method ▸ UNKNOWN GO-2026-5932 golang.org/x/crypto v0.56.0 /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis pclntab advisory GO-2026-5932 from golang epss not scored — this advisory has no CVE id, and both feeds are keyed by CVE purl pkg:golang/golang.org%2Fx%2Fcrypto@v0.56.0 binary /home/klipper-helm/.local/share/helm/plugins/helm-mapkubeapis/bin/mapkubeapis packages golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package) vex vulnerable_code_not_present [pclntab] ▸ UNKNOWN GO-2026-5932 golang.org/x/crypto v0.56.0 /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status pclntab advisory GO-2026-5932 from golang epss not scored — this advisory has no CVE id, and both feeds are keyed by CVE purl pkg:golang/golang.org%2Fx%2Fcrypto@v0.56.0 binary /home/klipper-helm/.local/share/helm/plugins/helm-set-status/helm-set-status (stripped) packages golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package) vex vulnerable_code_not_present [pclntab] ▸ UNKNOWN GO-2026-5932 golang.org/x/crypto v0.56.0 /usr/bin/helm pclntab advisory GO-2026-5932 from golang epss not scored — this advisory has no CVE id, and both feeds are keyed by CVE purl pkg:golang/golang.org%2Fx%2Fcrypto@v0.56.0 binary /usr/bin/helm (stripped) packages golang.org/x/crypto/openpgp, golang.org/x/crypto/openpgp/armor, golang.org/x/crypto/openpgp/clearsign, golang.org/x/crypto/openpgp/elgamal, golang.org/x/crypto/openpgp/errors, golang.org/x/crypto/openpgp/packet, golang.org/x/crypto/openpgp/s2k (package) vex vulnerable_code_not_present [pclntab]
Scan coverage# Ecosystem Components Affected Vexed Undetermined Ruled out Status golang115 1 0 0 3 ok os16 0 0 0 0 ok
VEX hubs# Triage: scored 1, 0 known exploited, 3 with no CVE id to look up. Feeds as of EPSS 2026-09-14; KEV 2026.09.14.