Package
harvester-fips-upgrade-helper
Component
github.com/kube-logging/logging-operator
Latest update
9.9
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
CVE-2026-54680 is a Fluentd-renderer config-injection RCE in the logging-operator controllers, which Harvester does not compile — it vendors logging-operator only for pkg/resources/kubetool (K8s volume helpers). The patched pseudo-version v0.0.0-20260608145523 requires controller-runtime v0.24, apimachinery/client-go v0.36, and prometheus-operator v0.91, but Harvester replace-pins apimachinery/client-go to v0.33.7 and uses kubevirt v1.7.x, so bumping fails to build (undefined runtime.ApplyConfiguration, resourcelock.NewWithLabels, kubevirt Endpoint). Pending an upstream Harvester release adopting a compatible logging-operator.
Status