github.com/k3s-io/k3s vulnerabilities
CVEs whose affected-version data names the github.com/k3s-io/k3s package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-54250Medium· 5.8K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression
K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression
▾ Sunlitk3s-io · github.com/k3s-io/k3sEPSS 0.17%via GHSA
CVE-2025-46599Medium· 6.8CNCF K3s Kubernetes kubelet configuration exposes credentials
CNCF K3s Kubernetes kubelet configuration exposes credentials
▾ Sunlitk3s-io · github.com/k3s-io/k3sEPSS 0.45%via OSV