Container image of etcd, the key-value store backing the Kubernetes control plane.
Version: 3.6.8-0
Type: Container
License:
| Expand | CVE | Title | Status | |
|---|---|---|---|---|
| GHSA-5cgq-3rg8-m6cv Open GHSA-5cgq-3rg8-m6cv in a new tab | golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status | Not affected | Critical | |
| GHSA-89gr-r52h-f8rx Open GHSA-89gr-r52h-f8rx in a new tab | golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed | Not affected | Critical | |
| GHSA-f5wc-c3c7-36mc Open GHSA-f5wc-c3c7-36mc in a new tab | golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys | Not affected | Critical | |
| GHSA-jppx-rxg9-jmrx Open GHSA-jppx-rxg9-jmrx in a new tab | golang.org/x/crypto doesn't enforce invoking key constraints | Not affected | Critical | |
| GHSA-p77j-4mvh-x3m3 Open GHSA-p77j-4mvh-x3m3 in a new tab | gRPC-Go has an authorization bypass via missing leading slash in :path | Not affected | Critical | |
| GHSA-rm3j-f69w-wqmq Open GHSA-rm3j-f69w-wqmq in a new tab | golang.org/x/crypto vulnerable to infinite loop on large channel writes | Not affected | Critical | |
| GHSA-vgwf-h737-ff37 Open GHSA-vgwf-h737-ff37 in a new tab | golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses | Not affected | Critical | |
| GHSA-x527-x647-q7gg Open GHSA-x527-x647-q7gg in a new tab | golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement | Not affected | Critical | |
| GHSA-2v4p-qf9q-27wj Open GHSA-2v4p-qf9q-27wj in a new tab | gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers | Not affected | High | |
| GHSA-9h8m-3fm2-qjrq Open GHSA-9h8m-3fm2-qjrq in a new tab | OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking | Not affected | High | |
| GHSA-hfvc-g4fc-pqhx Open GHSA-hfvc-g4fc-pqhx in a new tab | opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking | Not affected | High | |
| GHSA-hrxh-6v49-42gf Open GHSA-hrxh-6v49-42gf in a new tab | gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities | Not affected | High | |
| GHSA-q4h4-gmj2-qvw2 Open GHSA-q4h4-gmj2-qvw2 in a new tab | golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic | Not affected | High | |
| GHSA-vp52-pcj8-j9qc Open GHSA-vp52-pcj8-j9qc in a new tab | gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation | Not affected | High | |
| GHSA-w879-237q-wc7r Open GHSA-w879-237q-wc7r in a new tab | golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS | Not affected | High | |
| GHSA-45gg-vh54-h5m9 Open GHSA-45gg-vh54-h5m9 in a new tab | golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions | Not affected | Medium | |
| GHSA-5cv4-jp36-h3mw Open GHSA-5cv4-jp36-h3mw in a new tab | Go Net HTML parser is vulnerable to denial of service | Not affected | Medium | |
| GHSA-78mq-xcr3-xm33 Open GHSA-78mq-xcr3-xm33 in a new tab | golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow | Not affected | Medium | |
| GHSA-9m57-25v3-79x9 Open GHSA-9m57-25v3-79x9 in a new tab | golang.org/x/crypto: Invoking pathological inputs can lead to client panic | Not affected | Medium | |
| GHSA-qc2q-p7wx-3px3 Open GHSA-qc2q-p7wx-3px3 in a new tab | gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion | Not affected | Medium | |
| GHSA-qpw4-5x99-6vjp Open GHSA-qpw4-5x99-6vjp in a new tab | golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS | Not affected | Medium | |
| GHSA-w67g-5rqw-f597 Open GHSA-w67g-5rqw-f597 in a new tab | Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key | Not affected | Medium | |
| GHSA-8wmf-6v46-5gfg Open GHSA-8wmf-6v46-5gfg in a new tab | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs | Not affected | Low | |
| GHSA-8wmf-6v46-5gfg Open GHSA-8wmf-6v46-5gfg in a new tab | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs | Not affected | Low | |
| GHSA-8wmf-6v46-5gfg Open GHSA-8wmf-6v46-5gfg in a new tab | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs | Not affected | Low | |
| GO-2026-4394 Open GO-2026-4394 in a new tab | OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking in go.opentelemetry.io/otel/sdk | Not affected | Unknown | |
| GO-2026-4762 Open GO-2026-4762 in a new tab | Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc | Not affected | Unknown | |
| GO-2026-4918 Open GO-2026-4918 in a new tab | Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | Not affected | Unknown | |
| GO-2026-5005 Open GO-2026-5005 in a new tab | Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent | Not affected | Unknown | |
| GO-2026-5006 Open GO-2026-5006 in a new tab | Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent | Not affected | Unknown | |
| GO-2026-5013 Open GO-2026-5013 in a new tab | Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh | Not affected | Unknown | |
| GO-2026-5014 Open GO-2026-5014 in a new tab | Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh | Not affected | Unknown | |
| GO-2026-5015 Open GO-2026-5015 in a new tab | Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh | Not affected | Unknown | |
| GO-2026-5016 Open GO-2026-5016 in a new tab | Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh | Not affected | Unknown | |
| GO-2026-5017 Open GO-2026-5017 in a new tab | Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh | Not affected | Unknown | |
| GO-2026-5018 Open GO-2026-5018 in a new tab | Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh | Not affected | Unknown | |
| GO-2026-5019 Open GO-2026-5019 in a new tab | Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh | Not affected | Unknown | |
| GO-2026-5020 Open GO-2026-5020 in a new tab | Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh | Not affected | Unknown | |
| GO-2026-5021 Open GO-2026-5021 in a new tab | Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts | Not affected | Unknown | |
| GO-2026-5023 Open GO-2026-5023 in a new tab | Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh | Not affected | Unknown | |
| GO-2026-5024 Open GO-2026-5024 in a new tab | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows | Not affected | Unknown | |
| GO-2026-5025 Open GO-2026-5025 in a new tab | Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html | Not affected | Unknown | |
| GO-2026-5026 Open GO-2026-5026 in a new tab | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | Not affected | Unknown | |
| GO-2026-5027 Open GO-2026-5027 in a new tab | Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html | Not affected | Unknown | |
| GO-2026-5028 Open GO-2026-5028 in a new tab | Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html | Not affected | Unknown | |
| GO-2026-5029 Open GO-2026-5029 in a new tab | Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html | Not affected | Unknown | |
| GO-2026-5030 Open GO-2026-5030 in a new tab | Invoking duplicate attributes can cause XSS in golang.org/x/net/html | Not affected | Unknown | |
| GO-2026-5033 Open GO-2026-5033 in a new tab | Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent | Not affected | Unknown | |
| GO-2026-5426 Open GO-2026-5426 in a new tab | Opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking in go.opentelemetry.io/otel/sdk | Not affected | Unknown | |
| GO-2026-5841 Open GO-2026-5841 in a new tab | OOB read in github.com/klauspost/compress/s2 | Not affected | Unknown |
golang.org/x/crypto vulnerable to auth bypass via unenforced @revoked status
golang.org/x/crypto: FIDO/U2F security key physical presence check can be bypassed
golang.org/x/crypto doesn't drop invoking agent constraints when forwarding keys
golang.org/x/crypto doesn't enforce invoking key constraints
gRPC-Go has an authorization bypass via missing leading slash in :path
golang.org/x/crypto vulnerable to infinite loop on large channel writes
golang.org/x/crypto: Invoking client can cause server deadlock on unexpected responses
golang.org/x/crypto: Invoking VerifiedPublicKeyCallback permissions skip enforcement
gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers
OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking
opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
golang.org/x/crypto: Invoking byte arithmetic causes underflow and panic
gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation
golang.org/x/crypto: Invoking pathological RSA/DSA parameters may cause DoS
golang.org/x/crypto vulnerable to invoking bypass of certificate restrictions
Go Net HTML parser is vulnerable to denial of service
golang.org/x/crypto is vulnerable to invoking server panic during CheckHostKey/Authenticate flow
golang.org/x/crypto: Invoking pathological inputs can lead to client panic
gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion
golang.org/x/crypto: Invoking memory leak when rejecting channels can lead to DoS
Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key
OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking in go.opentelemetry.io/otel/sdk
Authorization bypass in gRPC-Go via missing leading slash in :path in google.golang.org/grpc
Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net
Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent
Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent
Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh
Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh
Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh
Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh
Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh
Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh
Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh
Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh
Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts
Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh
Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows
Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html
Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna
Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html
Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html
Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html
Invoking duplicate attributes can cause XSS in golang.org/x/net/html
Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent
Opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking in go.opentelemetry.io/otel/sdk
OOB read in github.com/klauspost/compress/s2
Showing 1–50 of 61