StackRadar

CVE-2025-46599

Unscored

Advisory

Published 5 May 2025In the index since 5 Sept 2026
Severity
Unscored
worst across findings
CVSS
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
11
of 17,781 indexed, latest versions
Container images
7
deployed by those charts
Fix available
None
affected package

CNCF K3s Kubernetes kubelet configuration exposes credentials in github.com/k3s-io/k3s

Carried by container images the latest versions of 11 of 17,781 indexed charts deploy, on 7 images.

Affected packageAffected versionsFixed inImages
github.com/k3s-io/k3sgolangv1.25.3, v1.26.0, v1.27.3, v1.28.2+2 moreno fix listed7
OSV records
GO-2025-3646
Also known as
GHSA-864f-7xjm-2jp2

Charts affected

11 by stars
ChartLatestAffected imagesRadar Score
rancherrancher-stable2.15.11 of 2See more

rancher rancher-stable 2.15.1

1 of the 2 container images this version deploys carry CVE-2025-46599.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
github.com/k3s-io/k3s@v1.36.2
no fix listed

Open the chart page →

1,456
vclusterloftVerified publisher0.0.0-ci.31 of 2See more

vcluster loft 0.0.0-ci.3

1 of the 2 container images this version deploys carry CVE-2025-46599.

Container imageDigestPackageFixed in
rancher/k3s:v1.26.0-k3s19380f5dbae9a
github.com/k3s-io/k3s@v1.26.0
no fix listed

Open the chart page →

2,453
rancherrancher-latest2.15.11 of 2See more

rancher rancher-latest 2.15.1

1 of the 2 container images this version deploys carry CVE-2025-46599.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
github.com/k3s-io/k3s@v1.36.2
no fix listed

Open the chart page →

1,456
loftloftVerified publisher0.0.0-ci.141 of 1See more

loft loft 0.0.0-ci.14

1 of the 1 container images this version deploys carry CVE-2025-46599.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
github.com/k3s-io/k3s@v1.27.3
no fix listed

Open the chart page →

3,675
ranchercarbide-charts2.15.11 of 2See more

rancher carbide-charts 2.15.1

1 of the 2 container images this version deploys carry CVE-2025-46599.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
github.com/k3s-io/k3s@v1.36.2
no fix listed

Open the chart page →

1,456
mission-control-tenantflanksourceVerified publisher1.0.921 of 3See more

mission-control-tenant flanksource 1.0.92

1 of the 3 container images this version deploys carry CVE-2025-46599.

Container imageDigestPackageFixed in
rancher/k3s:v1.28.2-k3s18c2599ecfca8
github.com/k3s-io/k3s@v1.28.2
no fix listed

Open the chart page →

5,684
devpod-proloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

devpod-pro loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2025-46599.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
github.com/k3s-io/k3s@v1.28.4
no fix listed

Open the chart page →

3,225
vcluster-control-planeloftVerified publisher0.0.0-ci.4-do-not-use1 of 1See more

vcluster-control-plane loft 0.0.0-ci.4-do-not-use

1 of the 1 container images this version deploys carry CVE-2025-46599.

Container imageDigestPackageFixed in
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
github.com/k3s-io/k3s@v1.28.4
no fix listed

Open the chart page →

3,225
vcluster-proloftVerified publisher0.0.0-ci-run.101 of 2See more

vcluster-pro loft 0.0.0-ci-run.10

1 of the 2 container images this version deploys carry CVE-2025-46599.

Container imageDigestPackageFixed in
rancher/k3s:v1.26.0-k3s19380f5dbae9a
github.com/k3s-io/k3s@v1.26.0
no fix listed

Open the chart page →

5,085
smarter-k3s-edgesmarterVerified publisher0.0.121 of 2See more

smarter-k3s-edge smarter 0.0.12

1 of the 2 container images this version deploys carry CVE-2025-46599.

Container imageDigestPackageFixed in
rancher/k3s:v1.25.3-k3s1eaa270df79cc
github.com/k3s-io/k3s@v1.25.3
no fix listed

Open the chart page →

3,462
rancherwenerme2.15.11 of 2See more

rancher wenerme 2.15.1

1 of the 2 container images this version deploys carry CVE-2025-46599.

Container imageDigestPackageFixed in
rancher/rancher:v2.15.15f6c4dc52a05
github.com/k3s-io/k3s@v1.36.2
no fix listed

Open the chart page →

1,456

Container images carrying it

7 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
rancher/rancher:v2.15.15f6c4dc52a05
github.com/k3s-io/k3s@v1.36.2
no fix listed
4
rancher/k3s:v1.26.0-k3s19380f5dbae9a
github.com/k3s-io/k3s@v1.26.0
no fix listed
2
rancher/k3s:v1.28.2-k3s18c2599ecfca8
github.com/k3s-io/k3s@v1.28.2
no fix listed
1
rancher/k3s:v1.25.3-k3s1eaa270df79cc
github.com/k3s-io/k3s@v1.25.3
no fix listed
1
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
github.com/k3s-io/k3s@v1.28.4
no fix listed
1
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
github.com/k3s-io/k3s@v1.27.3
no fix listed
1
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
github.com/k3s-io/k3s@v1.28.4
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.