k3s-fips-1.32

Direct Vulnerabilities

Known vulnerabilities in the k3s-fips-1.32 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
GHSA-259r-337f-4rfw

*
  • L
GHSA-gcjh-h69q-9w9g

*
  • L
CVE-2026-57497

*
  • L
GHSA-hrxh-6v49-42gf

*
  • L
CVE-2026-56852

*
  • L
CVE-2026-46600

*
  • M
Incorrect Authorization

*
  • H
Untrusted Search Path

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
Uncaught Exception

*
  • L
Improper Certificate Validation

*
  • L
CVE-2025-22872

*
  • L
Deserialization of Untrusted Data

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
CVE-2025-22870

*
  • L
Improper Verification of Cryptographic Signature

*
  • L
Improper Restriction of Rendered UI Layers or Frames

*
  • L
Improper Restriction of Rendered UI Layers or Frames

*
  • L
Improper Validation of Array Index

*
  • L
GO-2026-5932

*
  • L
CVE-2026-46598

*
  • L
Untrusted Search Path

*
  • L
Improper Certificate Validation

*
  • L
CVE-2026-39824

*
  • L
Improper Certificate Validation

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • H
Arbitrary Command Injection

*
  • L
Reachable Assertion

*
  • M
CVE-2026-26014

*
  • L
Cross-site Scripting (XSS)

*
  • C
SQL Injection

*
  • H
Resource Exhaustion

*
  • L
Out-of-Bounds

*
  • L
CVE-2025-22869

*
  • L
Incorrect Type Conversion or Cast

*
  • L
Improper Restriction of Rendered UI Layers or Frames

*
  • L
Directory Traversal

*
  • L
CVE-2026-46595

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
Improper Initialization

*
  • M
Improper Authentication

*
  • H
Symlink Following

*
  • L
CVE-2025-58181

*
  • L
Uncontrolled Memory Allocation

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • M
CVE-2025-47911

*
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

*
  • H
Authentication Bypass

*
  • L
Improper Input Validation

*
  • L
Uncontrolled Search Path Element

*
  • L
Incorrect Authorization

*
  • L
CVE-2024-45338

*
  • L
Improper Authorization

*
  • M
Improper Authentication

*
  • L
Improper Enforcement of Message Integrity During Transmission in a Communication Channel

*
  • H
Off-by-one Error

*
  • M
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • L
CVE-2025-47914

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
Integer Overflow or Wraparound

*
  • L
Memory Leak

*
  • L
Cross-site Scripting (XSS)

*
  • H
Plaintext Storage of a Password

*
  • L
NULL Pointer Dereference

*
  • L
CVE-2026-39821

*
  • M
Information Exposure

*
  • H
CVE-2025-15558

*
  • L
Symlink Following

*
  • L
Improper Authentication

*
  • M
Authentication Bypass

*
  • L
Information Exposure

*
  • L
CVE-2024-28180

*
  • L
Resource Exhaustion

*
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Missing Initialization of Resource

*
  • L
Uncontrolled Recursion

*
  • L
CVE-2026-39822

<1.32.13.1-r1
  • L
CVE-2026-42505

<1.32.13.1-r1
  • L
CVE-2026-33816

*
  • L
Improper Authorization

*
  • L
Integer Overflow or Wraparound

*
  • L
Missing Authorization

*
  • L
Missing Authorization

*
  • L
CVE-2026-33815

*
  • L
CVE-2024-45337

*