Skip to main content
Testkube 2.11.0 is out! Improved insights and metrics, more responsive AI chat, Gateway API support, and much more! Read More

testkube-kubectl-1.36.2_linux_arm64

digestsha256:82452e1f159fb1a2d9b4a4ed647fb532f2e7550b572fe383f7094d06f8303924
vulnerabilitiescritical: 5 high: 10 medium: 9 low: 2 unspecified: 17
platformlinux/arm64
size24 MB
packages119
critical: 3 high: 3 medium: 0 low: 0 unspecified: 12curl 8.20.0-r1 (apk)

pkg:apk/alpine/curl@8.20.0-r1?os_name=alpine&os_version=3.24

# kubectl-release.dockerfile (5:5)
FROM alpine/kubectl:1.36.2

critical : CVE--2026--11856

Affected range<8.21.0-r0
Fixed version8.21.0-r0
EPSS Score0.604%
EPSS Percentile46th percentile
Description

critical : CVE--2026--10536

Affected range<8.21.0-r0
Fixed version8.21.0-r0
EPSS Score0.507%
EPSS Percentile41st percentile
Description

critical : CVE--2026--11564

Affected range<8.21.0-r0
Fixed version8.21.0-r0
EPSS Score0.363%
EPSS Percentile30th percentile
Description

high : CVE--2026--12064

Affected range<8.21.0-r0
Fixed version8.21.0-r0
EPSS Score0.339%
EPSS Percentile27th percentile
Description

high : CVE--2026--11586

Affected range<8.21.0-r0
Fixed version8.21.0-r0
EPSS Score0.491%
EPSS Percentile40th percentile
Description

high : CVE--2026--11352

Affected range<8.21.0-r0
Fixed version8.21.0-r0
EPSS Score0.577%
EPSS Percentile45th percentile
Description

unspecified : CVE--2026--9547

Affected range<8.21.0-r0
Fixed version8.21.0-r0
EPSS Score0.325%
EPSS Percentile25th percentile
Description

unspecified : CVE--2026--9546

Affected range<8.21.0-r0
Fixed version8.21.0-r0
EPSS Score0.399%
EPSS Percentile33rd percentile
Description

unspecified : CVE--2026--9545

Affected range<8.21.0-r0
Fixed version8.21.0-r0
EPSS Score0.268%
EPSS Percentile19th percentile
Description

unspecified : CVE--2026--9080

Affected range<8.21.0-r0
Fixed version8.21.0-r0
EPSS Score0.295%
EPSS Percentile22nd percentile
Description

unspecified : CVE--2026--9079

Affected range<8.21.0-r0
Fixed version8.21.0-r0
EPSS Score0.584%
EPSS Percentile45th percentile
Description

unspecified : CVE--2026--8932

Affected range<8.21.0-r0
Fixed version8.21.0-r0
EPSS Score0.396%
EPSS Percentile33rd percentile
Description

unspecified : CVE--2026--8927

Affected range<8.21.0-r0
Fixed version8.21.0-r0
EPSS Score0.440%
EPSS Percentile37th percentile
Description

unspecified : CVE--2026--8926

Affected range<8.21.0-r0
Fixed version8.21.0-r0
EPSS Score0.376%
EPSS Percentile31st percentile
Description

unspecified : CVE--2026--8925

Affected range<8.21.0-r0
Fixed version8.21.0-r0
EPSS Score0.592%
EPSS Percentile46th percentile
Description

unspecified : CVE--2026--8924

Affected range<8.21.0-r0
Fixed version8.21.0-r0
EPSS Score0.560%
EPSS Percentile44th percentile
Description

unspecified : CVE--2026--8458

Affected range<8.21.0-r0
Fixed version8.21.0-r0
EPSS Score0.315%
EPSS Percentile24th percentile
Description

unspecified : CVE--2026--8286

Affected range<8.21.0-r0
Fixed version8.21.0-r0
EPSS Score0.309%
EPSS Percentile24th percentile
Description
critical: 1 high: 5 medium: 2 low: 0 unspecified: 2stdlib 1.26.4 (golang)

pkg:golang/stdlib@1.26.4

# kubectl-release.dockerfile (5:5)
FROM alpine/kubectl:1.36.2

critical : CVE--2026--39821

Affected range
>=1.26.0-0
<1.26.6
Fixed version1.26.6
EPSS Score0.655%
EPSS Percentile49th percentile
Description

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error.

This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

high : CVE--2026--56862

Affected range
>=1.26.0-0
<1.26.6
Fixed version1.26.6
EPSS Score0.483%
EPSS Percentile40th percentile
Description

Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.

high : CVE--2026--56859

Affected range
>=1.26.0-0
<1.26.6
Fixed version1.26.6
EPSS Score0.483%
EPSS Percentile40th percentile
Description

Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.

high : CVE--2026--56853

Affected range
>=1.26.0-0
<1.26.6
Fixed version1.26.6
EPSS Score0.590%
EPSS Percentile46th percentile
Description

When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.

high : CVE--2026--46600

Affected range
>=1.26.0-0
<1.26.6
Fixed version1.26.6
EPSS Score0.350%
EPSS Percentile28th percentile
Description

Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.

high : CVE--2026--33818

Affected range
>=1.26.0-0
<1.26.6
Fixed version1.26.6
EPSS Score0.465%
EPSS Percentile39th percentile
Description

Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.

medium : CVE--2026--56858

Affected range
>=1.26.0-0
<1.26.6
Fixed version1.26.6
EPSS Score0.263%
EPSS Percentile18th percentile
Description

Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.

medium : CVE--2026--56860

Affected range
>=1.26.0-0
<1.26.6
Fixed version1.26.6
EPSS Score0.441%
EPSS Percentile37th percentile
Description

Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead.

Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.

unspecified : CVE--2026--42505

Affected range
>=1.26.0-0
<1.26.5
Fixed version1.26.5
EPSS Score0.382%
EPSS Percentile32nd percentile
Description

Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.

unspecified : CVE--2026--39822

Affected range
>=1.26.0-0
<1.26.5
Fixed version1.26.5
EPSS Score0.232%
EPSS Percentile14th percentile
Description

On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /.

For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.

critical: 1 high: 2 medium: 5 low: 0 golang.org/x/net 0.49.0 (golang)

pkg:golang/golang.org/x/net@0.49.0

# kubectl-release.dockerfile (5:5)
FROM alpine/kubectl:1.36.2

critical : CVE--2026--39821

Affected range<0.55.0
Fixed version0.55.0
EPSS Score0.655%
EPSS Percentile49th percentile
Description

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error.

This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

high : CVE--2026--46600

Affected range<0.56.0
Fixed version0.56.0
EPSS Score0.350%
EPSS Percentile28th percentile
Description

Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.

high : CVE--2026--33814

Affected range<0.53.0
Fixed version0.53.0
EPSS Score0.781%
EPSS Percentile53rd percentile
Description

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

medium 6.5: CVE--2026--25680 Uncontrolled Resource Consumption

Affected range<0.55.0
Fixed version0.55.0
CVSS Score6.5
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score0.326%
EPSS Percentile26th percentile
Description

In Go Net (golang.org/x/net) before verion 0.55.0, parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.

medium : CVE--2026--42506

Affected range<0.55.0
Fixed version0.55.0
EPSS Score0.235%
EPSS Percentile15th percentile
Description

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

medium : CVE--2026--42502

Affected range<0.55.0
Fixed version0.55.0
EPSS Score0.223%
EPSS Percentile13th percentile
Description

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

medium : CVE--2026--27136

Affected range<0.55.0
Fixed version0.55.0
EPSS Score0.223%
EPSS Percentile13th percentile
Description

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

medium : CVE--2026--25681

Affected range<0.55.0
Fixed version0.55.0
EPSS Score0.223%
EPSS Percentile13th percentile
Description

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

critical: 0 high: 0 medium: 1 low: 1 k8s.io/kubernetes 1.36.2 (golang)

pkg:golang/k8s.io/kubernetes@1.36.2

# kubectl-release.dockerfile (5:5)
FROM alpine/kubectl:1.36.2

medium : CVE--2025--1767

Affected range>=0
Fixed versionNot Fixed
EPSS Score0.539%
EPSS Percentile43rd percentile
Description

Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes

low : CVE--2024--7598

Affected range>=1.3.0
Fixed versionNot Fixed
EPSS Score0.314%
EPSS Percentile24th percentile
Description

Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes

critical: 0 high: 0 medium: 1 low: 0 go.opentelemetry.io/otel 1.41.0 (golang)

pkg:golang/go.opentelemetry.io/otel@1.41.0

# kubectl-release.dockerfile (5:5)
FROM alpine/kubectl:1.36.2

medium : CVE--2026--41178

Affected range
>=1.41.0
<1.42.0
Fixed version1.42.0
EPSS Score0.237%
EPSS Percentile15th percentile
Description

Opentelemetry-go's baggage parsing no longer caps raw header length in go.opentelemetry.io/otel

critical: 0 high: 0 medium: 0 low: 1 golang.org/x/sys 0.40.0 (golang)

pkg:golang/golang.org/x/sys@0.40.0

# kubectl-release.dockerfile (5:5)
FROM alpine/kubectl:1.36.2

low : CVE--2026--39824

Affected range<0.44.0
Fixed version0.44.0
EPSS Score0.114%
EPSS Percentile2nd percentile
Description

NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error.

critical: 0 high: 0 medium: 0 low: 0 unspecified: 1nghttp2 1.69.0-r0 (apk)

pkg:apk/alpine/nghttp2@1.69.0-r0?os_name=alpine&os_version=3.24

# kubectl-release.dockerfile (5:5)
FROM alpine/kubectl:1.36.2

unspecified : CVE--2026--58055

Affected range<1.70.0-r0
Fixed version1.70.0-r0
EPSS Score0.263%
EPSS Percentile18th percentile
Description
critical: 0 high: 0 medium: 0 low: 0 unspecified: 1golang.org/x/text 0.33.0 (golang)

pkg:golang/golang.org/x/text@0.33.0

# kubectl-release.dockerfile (5:5)
FROM alpine/kubectl:1.36.2

unspecified : CVE--2026--56852

Affected range<0.39.0
Fixed version0.39.0
EPSS Score0.446%
EPSS Percentile37th percentile
Description

A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

critical: 0 high: 0 medium: 0 low: 0 unspecified: 1c-ares 1.34.6-r0 (apk)

pkg:apk/alpine/c-ares@1.34.6-r0?os_name=alpine&os_version=3.24

# kubectl-release.dockerfile (5:5)
FROM alpine/kubectl:1.36.2

unspecified : CVE--2026--33630

Affected range<1.34.8-r0
Fixed version1.34.8-r0
Description