Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CLEANSTART-2026-KD34055
  • CleanStart/docker-cli-buildx
SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass 4 days ago
  • Fix available
  • Severity - 8.8 (High)
CLEANSTART-2026-OK73778
  • CleanStart/kube-state-metrics-fips
SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass 4 days ago
  • Fix available
  • Severity - 8.8 (High)
CLEANSTART-2026-PG05502
  • CleanStart/containerd
SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass 4 days ago
  • Fix available
  • Severity - 8.8 (High)
CLEANSTART-2026-GQ35594
  • CleanStart/argo-cd-fips
  • CleanStart/aws-eks-pod-identity-agent-fips
  • CleanStart/aws-privateca-issuer
  • CleanStart/aws-privateca-issuer-fips
  • CleanStart/cadvisor-fips
  • ... 95 more
Security fix for CVE-2026-27140 applied in: argo-cd-fips 3.0.23-r1, aws-eks-pod-identity-agent-fips 0.1.36-r0, aws-privateca-issuer 1.7.0-r0, aws-privateca-issuer-fips 1.7.0-r1, cadvisor-fips 0.55.1-r0, cass-operator-fips 1.30.0-r1, cert-manager 1.20.0-r0, cert-manager-cmctl-fips 2.4.0-r3, cert-manager-webhook-pdns-fips 3.2.3-r2, certificate-transparency-trillian-ctserver 1.3.2-r2, certificate-transparency-trillian-ctserver-fips 1.3.2-r0, cilium 1.17.15-r0, cilium 1.18.9-r0, cilium 1.19.3-r0, cloudnative-pg-fips 1.24.4-r4, cloudnative-pg-fips 1.25.4-r3, cloudnative-pg-fips 1.26.3-r2, cloudnative-pg-fips 1.27.3-r2, cloudnative-pg-fips 1.28.1-r2, confluent-cp-docker-utils 1.0.8-r0, coredns 1.14.2-r1, crossplane-provider-sql-fips 0.13.0-r1, dex 2.45.1-r2, docker 29.3.0-r1, eks-distro-kube-apiserver 1.34.2-r0, eks-distro-kube-apiserver-fips 1.34.2-r0, eks-distro-kube-scheduler-fips 1.34.3-r0, external-secrets 2.2.0-r0, external-secrets-fips 0.17.0-r2, external-secrets-fips 2.2.0-r0, fluent-operator-fips 3.2.0-r7, fluent-operator-fips 3.3.0-r8, fluent-operator-fips 3.4.0-r8, fluent-operator-fips 3.5.0-r2, fluent-operator-fips 3.6.0-r4, fluent-operator-fips 3.7.0-r2, flux-notification-controller-fips 1.5.0-r0, gostatsd 28.3.0-r2, grafana-mimir-fips 3.0.5-r1, helm 4.1.3-r0, helm-fips 4.1.3-r0, helm-operator 1.42.1-r0, helm-operator 1.42.2-r0, helm-operator-fips 1.41.1-r2, istio 1.28.5-r3, istio 1.29.1-r1, istio-fips 1.25.5-r5, istio-fips 1.26.8-r2, istio-fips 1.27.8-r3, istio-fips 1.28.5-r3, istio-fips 1.29.1-r2, istio-pilot-discovery-fips 1.28.3-r1, jitsucom-bulker 2.10.0-r2, jitsucom-bulker 2.11.0-r0, jitsucom-bulker 2.8.6-r0, jitsucom-bulker 2.9.0-r0, k8ssandra-client-fips 0.5.0-r8, k8ssandra-client-fips 0.6.4-r7, k8ssandra-client-fips 0.7.0-r5, k8ssandra-client-fips 0.8.10-r1, k8ssandra-client-fips 0.8.9-r0, k8ssandra-operator-fips 1.29.0-r1, kafka_exporter-fips 1.6.0-r1, kafka_exporter-fips 1.7.0-r2, karpenter-fips 1.9.0-r0, keda 2.19.0-r3, keda-fips 2.18.3-r3, kserve 0.16.0-r2, kserve-modelmesh-serving 0.12.0-r2, kube-rbac-proxy 0.20.2-r1, kube-rbac-proxy-fips 0.20.2-r1, kube-state-metrics 2.10.1-r1, kube-state-metrics-fips 2.18.0-r1, kube-vip 1.1.0-r0, kubernetes 1.34.1-r3, kubernetes-csi-driver-nfs-fips 4.12.1-r2, kubernetes-csi-external-attacher 4.10.0-r0, kubernetes-csi-external-attacher-fips 4.10.0-r0, kubernetes-csi-external-resizer 2.0.0-r0, kubernetes-csi-external-resizer-fips 2.0.0-r1, kubernetes-csi-external-resizer-fips 2.1.0-r1, kubernetes-csi-external-snapshotter-fips 8.4.0-r3, kubernetes-csi-external-snapshotter-fips 8.5.0-r2, kubernetes-csi-livenessprobe-fips 2.18.0-r2, kubernetes-csi-node-driver-registrar 2.13.0-r0, kubernetes-dashboard 7.14.0-r1, kubernetes-dashboard-api 1.14.0-r1, kubernetes-dashboard-api-fips 1.14.0-r1, kubernetes-dashboard-auth 1.4.0-r1, kubernetes-dashboard-auth-fips 1.4.0-r2, kubernetes-dashboard-fips 7.14.0-r0, kubernetes-dashboard-web 1.7.0-r0, kubernetes-event-exporter 1.7-r1, kubernetes-event-exporter-fips 1.7-r0, kured 1.20.0-r0, kustomize-fips 5.8.1-r0, kyverno-fips 1.13.6-r10, kyverno-fips 1.16.3-r6, kyverno-fips 1.17.1-r5, kyverno-policy-reporter-fips 3.7.3-r2, local-static-provisioner 2.8.0-r2, minio-operator-fips 5.0.19-r1, mountpoint-s3-csi-driver 2.3.0-r1, newrelic-nri-kube-events 2.16.4-r2, nginx-prometheus-exporter 1.5.1-r2, nginx-prometheus-exporter-fips 1.5.1-r1, nvidia-container-toolkit 1.19.0-r0, openbao-fips 2.5.1-r2, opensearch-k8s-operator-fips 2.5.1-r3, opensearch-k8s-operator-fips 2.6.1-r8, opensearch-k8s-operator-fips 2.8.0-r3, prom-mysqld-exporter-fips 0.18.0-r3, prometheus-mysqld-exporter 0.15.0-r1, prometheus-mysqld-exporter-fips 0.19.0-r1, prometheus-operator 0.69.1-r1, prometheus-redis-exporter-fips 1.77.0-r4, prometheus-redis-exporter-fips 1.78.0-r4, prometheus-redis-exporter-fips 1.79.0-r4, prometheus-redis-exporter-fips 1.80.2-r2, prometheus-redis-exporter-fips 1.81.0-r1, prometheus-redis-exporter-fips 1.82.0-r0, rabbitmq-cluster-operator 2.18.0-r0, rabbitmq-messaging-topology-operator 1.16.0-r0, renovate 43.123.8-r1, sealed-secrets 0.33.1-r0, sealed-secrets 0.34.0-r0, stakater-reloader-fips 1.2.1-r3, stakater-reloader-fips 1.3.0-r2, step-issuer 0.10.2-r1, tempo 2.10.3-r0, tempo-fips 2.10.3-r0, tigera-operator 1.41.1-r0, timoni 0.25.2-r0, trust-manager-fips 0.20.3-r1, trust-manager-fips 0.21.1-r1, velero-plugin-for-gcp-fips 1.13.1-r2, velero-plugin-for-gcp-fips 1.13.2-r1, velero-plugin-for-microsoft-azure-fips 1.13.1-r1, velero-plugin-for-microsoft-azure-fips 1.13.2-r1, velero-plugin-for-microsoft-azure-fips 1.14.0-r1, wave 0.11.0-r1, yunikorn-web-fips 1.7.0-r0, zot 2.1.13-r2 18 Sep
  • Fix available
CGA-7c7j-hp6x-4chx
  • Chainguard/kyverno-1.17
  • Wolfi/kyverno-1.17
See record for full details 15 Sep
  • No fix available
  • Severity - 8.8 (High)
CGA-ppj3-g8pf-5c42
  • Chainguard/redpanda-25.3-compat
  • Wolfi/redpanda-25.3-compat
See record for full details 15 Sep
  • No fix available
  • Severity - 8.8 (High)
CGA-vm44-x83j-3h99
  • Chainguard/ingress-nginx-custom-error-pages-compat-1.14
  • Wolfi/ingress-nginx-custom-error-pages-compat-1.14
See record for full details 15 Sep
  • Fix available
  • Severity - 8.8 (High)
CGA-6mwq-ch6h-5f33
  • Chainguard/helm-3
  • Wolfi/helm-3
See record for full details 15 Sep
  • Fix available
  • Severity - 8.8 (High)
CGA-74wq-g9wv-cp49
  • Chainguard/datadog-agent-7.76
  • Wolfi/datadog-agent-7.76
See record for full details 15 Sep
  • Fix available
  • Severity - 8.8 (High)
CGA-q29r-w593-xp5r
  • Chainguard/kyverno-cli-1.17
  • Wolfi/kyverno-cli-1.17
See record for full details 15 Sep
  • Fix available
  • Severity - 8.8 (High)
CGA-j4r2-64m3-hcwh
  • Chainguard/tekton-pipelines-controller-1.10
  • Wolfi/tekton-pipelines-controller-1.10
See record for full details 15 Sep
  • Fix available
  • Severity - 8.8 (High)
CGA-x9mc-5h95-79cf
  • Chainguard/calico-key-cert-provisioner-3.31
  • Wolfi/calico-key-cert-provisioner-3.31
See record for full details 15 Sep
  • Fix available
  • Severity - 8.8 (High)
CGA-49fg-v7qx-9wvq
  • Chainguard/ingress-nginx-custom-error-pages-1.14
  • Wolfi/ingress-nginx-custom-error-pages-1.14
See record for full details 15 Sep
  • Fix available
  • Severity - 8.8 (High)
CGA-97jf-rgcw-fxg7
  • Chainguard/kyverno-1.17
  • Wolfi/kyverno-1.17
See record for full details 15 Sep
  • Fix available
  • Severity - 8.8 (High)
CGA-rrxr-6mwq-93g8
  • Chainguard/tekton-pipelines-webhook-1.10
  • Wolfi/tekton-pipelines-webhook-1.10
See record for full details 15 Sep
  • Fix available
  • Severity - 8.8 (High)
CGA-xcc4-8x34-76pc
  • Chainguard/tekton-pipelines-nop-1.10
  • Wolfi/tekton-pipelines-nop-1.10
See record for full details 15 Sep
  • Fix available
  • Severity - 8.8 (High)