DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-2m36-wpw2-6h98

Package

harvester-fips-webhook

Component

github.com/rancher/rancher

Latest update

Fixed

Fixed version

1.8.1-r28

Aliases

Severity

8.8

High

CVSS V3

Eliminate CVEs with Chainguard hardened images

Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.

Start for free

References

  • https://nvd.nist.gov/vuln/detail/CVE-2026-41053

Updates

Status

Fixed

Fixed version

1.8.1-r28

Status

Pending upstream fix

Impact

This CVE is carried by the bundled github.com/rancher/rancher dependency and cannot be remediated as a package-level bump against harvester v1.8.1, which hard-pins its Kubernetes stack via go.mod replace directives (k8s.io/* => v0.33.7, cluster-api v1.9.5, controller-runtime v0.21.0). The earliest rancher revision containing the fix (d0c047bbc6d2) is built against Kubernetes 0.35.5 / cluster-api v1.12.2 — two minors ahead — and cluster-api ≥v1.12 removed the api/v1beta1 package harvester'''s own code imports; bumping rancher therefore fails to compile. Same blocker as CVE-2026-41052 (k8s 0.35.4) and CVE-2025-67601 (cluster-api v1.12+). Pending upstream: resolves when harvester migrates off api/v1beta1 onto the Kubernetes 0.35+/cluster-api ≥v1.12 stack (v1.8.2 / v1.9.0).

Status

Under investigation


The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.