Package
rke2-runtime-1.33
Component
golang.org/x/net
Latest update
Fixed version
1.33.12.2.1-r2
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Fixed version
1.33.12.2.1-r2Status
Impact
The rke2 binary in rke2-runtime-1.33 embeds golang.org/x/net v0.50.0, which is vulnerable to CVE-2026-27141. A fix is available in golang.org/x/net v0.51.0, but the remediation PR fails because the rke2 server and agent processes crash during the functional test, and rke2-runtime-1.33 upstream has not yet released a version incorporating the patched dependency.
Status
Impact
Govulncheck found vulnerable symbols in Go binary at usr/bin/rke2.
Status