VYPR

apk package

chainguard/harvester-fips

pkg:apk/chainguard/harvester-fips

Vulnerabilities (53)

  • CVE-2026-7374CriMay 26, 2026
    affected < 1.8.1-r1fixed 1.8.1-r1

    A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine console sockets. By replacing the console socket

  • CVE-2026-39821CriMay 22, 2026
    affected < 1.8.2-r2fixed 1.8.2-r2

    The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in program

  • CVE-2026-25705HigMay 13, 2026
    affected < 1.8.1-r0fixed 1.8.1-r0

    A vulnerability has been identified in [Rancher's Extensions](https://ranchermanager.docs.rancher.com/integrations-in-rancher/rancher-extensions) where malicious code can be injected in Rancher through a path traversal in the `compressedEndpoint` field inside a `UIPlugin` deploym

  • CVE-2026-34040HigMar 31, 2026
    affected < 1.8.1-r11fixed 1.8.1-r11

    Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows attackers to bypass authorization plugins (AuthZ). This issue has been patched in version 29.3.1.

  • CVE-2026-33997MedMar 31, 2026
    affected < 1.8.1-r11fixed 1.8.1-r11

    Moby is an open source container framework. Prior to version 29.3.1, a security vulnerability has been detected that allows plugins privilege validation to be bypassed during docker plugin install. Due to an error in the daemon's privilege comparison logic, the daemon may incorre

  • CVE-2025-15558HigMar 4, 2026
    affected < 0fixed 0

    Docker CLI for Windows searches for plugin binaries in C:\ProgramData\Docker\cli-plugins, a directory that does not exist by default. A low-privileged attacker can create this directory and place malicious CLI plugin binaries (docker-compose.exe, docker-buildx.exe, etc.) that are

  • CVE-2024-58267HigOct 2, 2025
    affected < 1.8.1-r0fixed 1.8.1-r0

    A vulnerability has been identified within Rancher Manager whereby the SAML authentication from the Rancher CLI tool is vulnerable to phishing attacks. The custom authentication protocol for SAML-based providers can be abused to steal Rancher’s authentication tokens.

  • CVE-2024-58260HigOct 2, 2025
    affected < 1.8.1-r0fixed 1.8.1-r0

    A vulnerability has been identified within Rancher Manager where a missing server-side validation on the `.username` field in Rancher can allow users with update permissions on other User resources to cause denial of access for targeted accounts.

  • CVE-2025-54468MedOct 2, 2025
    affected < 1.8.1-r0fixed 1.8.1-r0

    A vulnerability has been identified within Rancher Manager whereby `Impersonate-Extra-*` headers are being sent to an external entity, for example `amazonaws.com`, via the `/meta/proxy` Rancher endpoint. These headers may contain identifiable and/or sensitive information e.g. ema

  • CVE-2025-54410LowJul 30, 2025
    affected < 1.8.1-r11fixed 1.8.1-r11

    Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. A firewalld vulnerability affects Moby releases before 28.0.0. When firewalld reloads, Docker fail

  • CVE-2023-32198higApr 25, 2025
    affected < 1.8.1-r0fixed 1.8.1-r0

    ### Impact A vulnerability has been identified in Steve where by default it was using an insecure option that did not validate the certificate presented by the remote server while performing a TLS connection. This could allow the execution of a man-in-the-middle (MitM) attack aga

  • CVE-2024-22031higApr 25, 2025
    affected < 1.8.1-r0fixed 1.8.1-r0

    ### Impact A vulnerability has been identified within Rancher where a user with the ability to create a project, on a certain cluster, can create a project with the same name as an existing project in a different cluster. This results in the user gaining access to the other proje

  • CVE-2025-23389HigApr 11, 2025
    affected < 1.8.1-r0fixed 1.8.1-r0

    A Improper Access Control vulnerability in SUSE rancher allows a local user to impersonate other identities through SAML Authentication on first login. This issue affects rancher: from 2.8.0 before 2.8.13, from 2.9.0 before 2.9.7, from 2.10.0 before 2.10.3.

  • CVE-2025-23387MedApr 11, 2025
    affected < 1.8.1-r0fixed 1.8.1-r0

    A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowed unauthenticated users to list all CLI authentication tokens and delete them before the CLI is able to get the token value.This issue affects rancher: from 2.8.0 before 2.8.13, from

  • CVE-2024-52282MedApr 11, 2025
    affected < 1.8.1-r0fixed 1.8.1-r0

    A Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SUSE rancher allowing any users with GET access to the Rancher Manager Apps Catalog to read any sensitive information that are contained within the Apps’ values. Additionally, the same information le

  • CVE-2024-7598LowMar 20, 2025
    affected < 1.8.1-r0fixed 1.8.1-r0

    A security issue was discovered in Kubernetes where a malicious or compromised pod could bypass network restrictions enforced by network policies during namespace deletion. The order in which objects are deleted during namespace termination is not defined, and it is possible for

  • CVE-2025-1767MedMar 13, 2025
    affected < 1.8.1-r0fixed 1.8.1-r0

    This CVE only affects Kubernetes clusters that utilize the in-tree gitRepo volume to clone git repositories from other pods within the same node. Since the in-tree gitRepo volume feature has been deprecated and will not receive security updates upstream, any cluster still using t

  • CVE-2024-36623HigNov 29, 2024
    affected < 1.8.1-r11fixed 1.8.1-r11

    moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes.

  • CVE-2022-45157CriNov 13, 2024
    affected < 1.8.1-r0fixed 1.8.1-r0

    A vulnerability has been identified in the way that Rancher stores vSphere's CPI (Cloud Provider Interface) and CSI (Container Storage Interface) credentials used to deploy clusters through the vSphere cloud provider. This issue leads to the vSphere CPI and CSI passwords being st

  • CVE-2023-32194HigOct 16, 2024
    affected < 1.8.1-r0fixed 1.8.1-r0

    A vulnerability has been identified when granting a create or * global role for a resource type of "namespaces"; no matter the API group, the subject will receive * permissions for core namespaces. This can lead to someone being capable of accessing, creating, updating, or dele