k3s-1.32

Direct Vulnerabilities

Known vulnerabilities in the k3s-1.32 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
CVE-2026-56852

*
  • L
GHSA-hrxh-6v49-42gf

*
  • L
CVE-2026-46600

*
  • L
Improper Certificate Validation

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
Improper Certificate Validation

*
  • L
Improper Restriction of Rendered UI Layers or Frames

*
  • H
Untrusted Search Path

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
Improper Input Validation

*
  • L
Uncontrolled Recursion

*
  • L
CVE-2025-22870

*
  • L
CVE-2025-22869

*
  • L
Improper Restriction of Rendered UI Layers or Frames

*
  • L
Improper Validation of Array Index

*
  • L
Reachable Assertion

*
  • L
CVE-2025-47914

*
  • L
CVE-2026-46598

*
  • L
Memory Leak

*
  • L
CVE-2026-39821

*
  • L
CVE-2025-22872

*
  • L
Symlink Following

*
  • L
Incorrect Type Conversion or Cast

*
  • M
Improper Authentication

*
  • M
Incorrect Authorization

*
  • L
Out-of-Bounds

*
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

*
  • L
Untrusted Search Path

*
  • M
CVE-2026-26014

*
  • H
Authentication Bypass

*
  • L
Cross-site Scripting (XSS)

*
  • L
Uncaught Exception

*
  • L
GO-2026-5932

*
  • L
Improper Initialization

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
Information Exposure

*
  • L
Integer Overflow or Wraparound

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
Resource Exhaustion

*
  • M
Information Exposure

*
  • L
Incorrect Authorization

*
  • M
Improper Authentication

*
  • H
Off-by-one Error

*
  • L
Improper Restriction of Rendered UI Layers or Frames

*
  • L
NULL Pointer Dereference

*
  • L
Uncontrolled Memory Allocation

*
  • H
Symlink Following

*
  • L
CVE-2025-58181

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • H
CVE-2025-15558

*
  • L
Improper Authorization

*
  • H
Resource Exhaustion

*
  • L
CVE-2026-39824

*
  • M
Authentication Bypass

*
  • L
Improper Certificate Validation

*
  • M
CVE-2025-47911

*
  • L
CVE-2024-45338

*
  • L
Directory Traversal

*
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
CVE-2026-46595

*
  • L
Improper Authentication

*
  • H
Arbitrary Command Injection

*
  • L
Improper Verification of Cryptographic Signature

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • M
Missing Initialization of Resource

*
  • L
Cross-site Scripting (XSS)

*
  • L
Deserialization of Untrusted Data

*
  • L
Improper Enforcement of Message Integrity During Transmission in a Communication Channel

*
  • L
Uncontrolled Search Path Element

*
  • C
SQL Injection

*
  • L
CVE-2024-28180

*
  • H
Plaintext Storage of a Password

*
  • L
CVE-2026-39822

<1.32.13.1-r1
  • L
CVE-2026-42505

<1.32.13.1-r1
  • L
Missing Authorization

*
  • L
CVE-2024-45337

*
  • L
Missing Authorization

*
  • L
Improper Authorization

*
  • L
Integer Overflow or Wraparound

*
  • L
CVE-2026-33816

*
  • L
CVE-2026-33815

*