Runs the core Kubernetes controllers that reconcile cluster state to the desired spec.
Version: 1.36.5
Type: Container
License:
| Expand | CVE | Title | Status | |
|---|---|---|---|---|
| GHSA-2v4p-qf9q-27wj Open GHSA-2v4p-qf9q-27wj in a new tab | gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers | Not affected | High | |
| GHSA-hfvc-g4fc-pqhx Open GHSA-hfvc-g4fc-pqhx in a new tab | opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking | Not affected | High | |
| GHSA-hrxh-6v49-42gf Open GHSA-hrxh-6v49-42gf in a new tab | gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities | Not affected | High | |
| GHSA-vp52-pcj8-j9qc Open GHSA-vp52-pcj8-j9qc in a new tab | gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation | Not affected | High | |
| GHSA-gcjh-h69q-9w9g Open GHSA-gcjh-h69q-9w9g in a new tab | cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag | Not affected | Medium | |
| GHSA-qc2q-p7wx-3px3 Open GHSA-qc2q-p7wx-3px3 in a new tab | gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion | Not affected | Medium | |
| GHSA-8wmf-6v46-5gfg Open GHSA-8wmf-6v46-5gfg in a new tab | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs | Not affected | Low | |
| GHSA-8wmf-6v46-5gfg Open GHSA-8wmf-6v46-5gfg in a new tab | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs | Not affected | Low | |
| GHSA-8wmf-6v46-5gfg Open GHSA-8wmf-6v46-5gfg in a new tab | OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs | Not affected | Low | |
| GO-2026-5158 Open GO-2026-5158 in a new tab | Opentelemetry-go's baggage parsing no longer caps raw header length in go.opentelemetry.io/otel | Not affected | Unknown | |
| GO-2026-5426 Open GO-2026-5426 in a new tab | Opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking in go.opentelemetry.io/otel/sdk | Not affected | Unknown | |
| GO-2026-5932 Open GO-2026-5932 in a new tab | The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues | Not affected | Unknown | |
| GO-2026-6061 Open GO-2026-6061 in a new tab | Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc | Not affected | Unknown | |
| GO-2026-6094 Open GO-2026-6094 in a new tab | JSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go | Not affected | Unknown | |
| GO-2026-6107 Open GO-2026-6107 in a new tab | Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3 | Not affected | Unknown | |
| GO-2026-6303 Open GO-2026-6303 in a new tab | Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh | Not affected | Unknown | |
| GO-2026-6348 Open GO-2026-6348 in a new tab | Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation in google.golang.org/grpc | Not affected | Unknown | |
| GO-2026-6354 Open GO-2026-6354 in a new tab | Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh | Not affected | Unknown | |
| GO-2026-6355 Open GO-2026-6355 in a new tab | Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh | Not affected | Unknown | |
| GO-2026-6441 Open GO-2026-6441 in a new tab | Bypass of xDS RBAC HTTP filter header matching in google.golang.org/grpc | Not affected | Unknown | |
| GO-2026-6443 Open GO-2026-6443 in a new tab | Server panic via missing authority or Host headers in google.golang.org/grpc | Not affected | Unknown |
gRPC-Go xDS servers: Denial of Service (DoS) via crash due to missing `:authority` and `Host` headers
opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking
gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
gRPC-Go: Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation
cel-go: JSON Private Fields Exposed via NativeTypes and ParseStructTag
gRPC-Go: xDS RBAC HTTP Filter bypass via mixed-case Header Matching and gRFC A41 validation evasion
OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
Opentelemetry-go's baggage parsing no longer caps raw header length in go.opentelemetry.io/otel
Opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking in go.opentelemetry.io/otel/sdk
The golang.org/x/crypto/openpgp package is unmaintained, unsafe by design, and has known security issues
Vulnerabilities in the xDS RBAC authorization engine and the HTTP/2 transport server implementation in google.golang.org/grpc
JSON private fields exposed via NativeTypes and ParseStructTag in github.com/google/cel-go
Unbounded TLS handshake goroutines in go.etcd.io/etcd/client/pkg/v3
Source-address critical option not enforced for non-public-key auth callbacks in golang.org/x/crypto/ssh
Heap Memory Exhaustion (OOM) via HTTP/2 DATA Frame Fragmentation in google.golang.org/grpc
Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh
Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh
Bypass of xDS RBAC HTTP filter header matching in google.golang.org/grpc
Server panic via missing authority or Host headers in google.golang.org/grpc
Showing 1–21 of 21