Skip to main content
Testkube 2.14.0 is out! AI test creation, detailed error analysis, and much more! Read More

testkube-kubectl-1.36.3_linux_arm64

digestsha256:d55712bd9aa80ca417a9df125d702e9965eaa5537eca07e71d0bd084cf0d3283
vulnerabilitiescritical: 6 high: 21 medium: 10 low: 2 unspecified: 3
platformlinux/arm64
size24 MB
packages119
critical: 2 high: 7 medium: 1 low: 0 openssl 3.5.7-r0 (apk)

pkg:apk/alpine/openssl@3.5.7-r0?os_name=alpine&os_version=3.24

# kubectl-release.dockerfile (5:5)
FROM alpine/kubectl:1.36.3

critical : CVE--2026--63073

Affected range<3.5.8-r0
Fixed version3.5.8-r0
EPSS Score1.159%
EPSS Percentile66th percentile
Description

critical : CVE--2026--75803

Affected range<3.5.8-r0
Fixed version3.5.8-r0
EPSS Score0.221%
EPSS Percentile11th percentile
Description

high : CVE--2026--63076

Affected range<3.5.8-r0
Fixed version3.5.8-r0
EPSS Score1.823%
EPSS Percentile78th percentile
Description

high : CVE--2026--63075

Affected range<3.5.8-r0
Fixed version3.5.8-r0
EPSS Score0.778%
EPSS Percentile54th percentile
Description

high : CVE--2026--63072

Affected range<3.5.8-r0
Fixed version3.5.8-r0
EPSS Score1.009%
EPSS Percentile62nd percentile
Description

high : CVE--2026--54874

Affected range<3.5.8-r0
Fixed version3.5.8-r0
EPSS Score1.311%
EPSS Percentile70th percentile
Description

high : CVE--2026--18798

Affected range<3.5.8-r0
Fixed version3.5.8-r0
EPSS Score1.537%
EPSS Percentile74th percentile
Description

high : CVE--2026--14457

Affected range<3.5.8-r0
Fixed version3.5.8-r0
EPSS Score1.021%
EPSS Percentile62nd percentile
Description

high : CVE--2026--14456

Affected range<3.5.8-r0
Fixed version3.5.8-r0
EPSS Score0.729%
EPSS Percentile52nd percentile
Description

medium : CVE--2026--63074

Affected range<3.5.8-r0
Fixed version3.5.8-r0
EPSS Score0.560%
EPSS Percentile45th percentile
Description
critical: 2 high: 7 medium: 0 low: 0 unspecified: 1curl 8.21.0-r0 (apk)

pkg:apk/alpine/curl@8.21.0-r0?os_name=alpine&os_version=3.24

# kubectl-release.dockerfile (5:5)
FROM alpine/kubectl:1.36.3

critical : CVE--2026--19931

Affected range<8.22.0-r0
Fixed version8.22.0-r0
EPSS Score0.747%
EPSS Percentile53rd percentile
Description

critical : CVE--2026--18924

Affected range<8.22.0-r0
Fixed version8.22.0-r0
EPSS Score0.584%
EPSS Percentile46th percentile
Description

high : CVE--2026--82209

Affected range<8.22.0-r0
Fixed version8.22.0-r0
EPSS Score0.373%
EPSS Percentile29th percentile
Description

high : CVE--2026--82208

Affected range<8.22.0-r0
Fixed version8.22.0-r0
EPSS Score0.407%
EPSS Percentile33rd percentile
Description

high : CVE--2026--80255

Affected range<8.22.0-r0
Fixed version8.22.0-r0
EPSS Score0.478%
EPSS Percentile39th percentile
Description

high : CVE--2026--80231

Affected range<8.22.0-r0
Fixed version8.22.0-r0
EPSS Score0.898%
EPSS Percentile58th percentile
Description

high : CVE--2026--80230

Affected range<8.22.0-r0
Fixed version8.22.0-r0
EPSS Score0.371%
EPSS Percentile29th percentile
Description

high : CVE--2026--80229

Affected range<8.22.0-r0
Fixed version8.22.0-r0
EPSS Score0.563%
EPSS Percentile45th percentile
Description

high : CVE--2026--13608

Affected range<8.22.0-r0
Fixed version8.22.0-r0
EPSS Score0.479%
EPSS Percentile39th percentile
Description

unspecified : CVE--2026--80256

Affected range<8.22.0-r0
Fixed version8.22.0-r0
Description
critical: 1 high: 5 medium: 2 low: 0 stdlib 1.26.5 (golang)

pkg:golang/stdlib@1.26.5

# kubectl-release.dockerfile (5:5)
FROM alpine/kubectl:1.36.3

critical : CVE--2026--39821

Affected range
>=1.26.0-0
<1.26.6
Fixed version1.26.6
EPSS Score0.692%
EPSS Percentile51st percentile
Description

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error.

This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

high : CVE--2026--56862

Affected range
>=1.26.0-0
<1.26.6
Fixed version1.26.6
EPSS Score0.568%
EPSS Percentile45th percentile
Description

Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.

high : CVE--2026--56859

Affected range
>=1.26.0-0
<1.26.6
Fixed version1.26.6
EPSS Score0.568%
EPSS Percentile45th percentile
Description

Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.

high : CVE--2026--56853

Affected range
>=1.26.0-0
<1.26.6
Fixed version1.26.6
EPSS Score0.568%
EPSS Percentile45th percentile
Description

When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.

high : CVE--2026--46600

Affected range
>=1.26.0-0
<1.26.6
Fixed version1.26.6
EPSS Score0.630%
EPSS Percentile48th percentile
Description

Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.

high : CVE--2026--33818

Affected range
>=1.26.0-0
<1.26.6
Fixed version1.26.6
EPSS Score0.568%
EPSS Percentile45th percentile
Description

Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.

medium : CVE--2026--56858

Affected range
>=1.26.0-0
<1.26.6
Fixed version1.26.6
EPSS Score0.310%
EPSS Percentile21st percentile
Description

Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.

medium : CVE--2026--56860

Affected range
>=1.26.0-0
<1.26.6
Fixed version1.26.6
EPSS Score0.550%
EPSS Percentile44th percentile
Description

Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead.

Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.

critical: 1 high: 2 medium: 5 low: 0 golang.org/x/net 0.49.0 (golang)

pkg:golang/golang.org/x/net@0.49.0

# kubectl-release.dockerfile (5:5)
FROM alpine/kubectl:1.36.3

critical : CVE--2026--39821

Affected range<0.55.0
Fixed version0.55.0
EPSS Score0.692%
EPSS Percentile51st percentile
Description

The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error.

This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".

high : CVE--2026--46600

Affected range<0.56.0
Fixed version0.56.0
EPSS Score0.630%
EPSS Percentile48th percentile
Description

Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.

high : CVE--2026--33814

Affected range<0.53.0
Fixed version0.53.0
EPSS Score0.781%
EPSS Percentile54th percentile
Description

When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it receives a SETTINGS_MAX_FRAME_SIZE with a value of 0.

medium 6.5: CVE--2026--25680 Uncontrolled Resource Consumption

Affected range<0.55.0
Fixed version0.55.0
CVSS Score6.5
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score0.460%
EPSS Percentile37th percentile
Description

In Go Net (golang.org/x/net) before verion 0.55.0, parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.

medium : CVE--2026--42506

Affected range<0.55.0
Fixed version0.55.0
EPSS Score0.333%
EPSS Percentile24th percentile
Description

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

medium : CVE--2026--42502

Affected range<0.55.0
Fixed version0.55.0
EPSS Score0.223%
EPSS Percentile12th percentile
Description

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

medium : CVE--2026--27136

Affected range<0.55.0
Fixed version0.55.0
EPSS Score0.223%
EPSS Percentile12th percentile
Description

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

medium : CVE--2026--25681

Affected range<0.55.0
Fixed version0.55.0
EPSS Score0.223%
EPSS Percentile12th percentile
Description

Parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree. This can be leveraged to execute XSS attacks in applications that attempt to sanitize input HTML before rendering.

critical: 0 high: 0 medium: 1 low: 1 k8s.io/kubernetes 1.36.3 (golang)

pkg:golang/k8s.io/kubernetes@1.36.3

# kubectl-release.dockerfile (5:5)
FROM alpine/kubectl:1.36.3

medium : CVE--2025--1767

Affected range>=0
Fixed versionNot Fixed
EPSS Score0.689%
EPSS Percentile51st percentile
Description

Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes

low : CVE--2024--7598

Affected range>=1.3.0
Fixed versionNot Fixed
EPSS Score0.314%
EPSS Percentile22nd percentile
Description

Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes

critical: 0 high: 0 medium: 1 low: 0 go.opentelemetry.io/otel 1.41.0 (golang)

pkg:golang/go.opentelemetry.io/otel@1.41.0

# kubectl-release.dockerfile (5:5)
FROM alpine/kubectl:1.36.3

medium : CVE--2026--41178

Affected range
>=1.41.0
<1.42.0
Fixed version1.42.0
EPSS Score0.336%
EPSS Percentile25th percentile
Description

Opentelemetry-go's baggage parsing no longer caps raw header length in go.opentelemetry.io/otel

critical: 0 high: 0 medium: 0 low: 1 golang.org/x/sys 0.40.0 (golang)

pkg:golang/golang.org/x/sys@0.40.0

# kubectl-release.dockerfile (5:5)
FROM alpine/kubectl:1.36.3

low : CVE--2026--39824

Affected range<0.44.0
Fixed version0.44.0
EPSS Score0.158%
EPSS Percentile4th percentile
Description

NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum size of a NTUnicodeString (a 16-bit number of bytes), it returns a truncated string rather than an error.

critical: 0 high: 0 medium: 0 low: 0 unspecified: 1golang.org/x/text 0.33.0 (golang)

pkg:golang/golang.org/x/text@0.33.0

# kubectl-release.dockerfile (5:5)
FROM alpine/kubectl:1.36.3

unspecified : CVE--2026--56852

Affected range<0.39.0
Fixed version0.39.0
EPSS Score0.475%
EPSS Percentile39th percentile
Description

A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

critical: 0 high: 0 medium: 0 low: 0 unspecified: 1nghttp2 1.69.0-r0 (apk)

pkg:apk/alpine/nghttp2@1.69.0-r0?os_name=alpine&os_version=3.24

# kubectl-release.dockerfile (5:5)
FROM alpine/kubectl:1.36.3

unspecified : CVE--2026--58055

Affected range<1.70.0-r0
Fixed version1.70.0-r0
EPSS Score0.319%
EPSS Percentile22nd percentile
Description