Index › devops › k9s k9s 1 tool · 1 release line Terminal UI for managing Kubernetes clusters. Every tool here carries the same sandbox boundary. $ kapsl k9s ⧉ Source ↗ Registry ↗ Release lines we maintain · the project decides these findings shown are the whole project at that line Tag Resolves to Lifecycle Updated Findings What the tag promises ▸ latest 0.51.0 stable 2026-08-29 20 tracks the newest supported release stable — floats, carries security updates unstable — tracks pre-releases, may break eol — frozen, upstream is done Tools in this project · pick one to inspect all share one boundary Tool Capabilities Seccomp Findings Image Description ▸ k9s netnomountro default C3H7M7L1?2 k9s Terminal UI for managing Kubernetes clusters ▸ showing k9s from k9s@latest → 0.51.0 stable Findings C3H7M7L1?2 identical on amd64, arm64 — one table describes both CVE Sev CVSS Affects Description GHSA-cvxm-645q-p574 ↗ C 9.9 github.com/containerd/containerd/v2 containerd: CRI checkpoint import allows local image tag poisoning GO-2026-5338 ↗ C 9.9 github.com/containerd/containerd containerd: CRI checkpoint import allows local image tag poisoning in github.com/containerd/containerd GO-2026-5064 ↗ C 9.6 github.com/containerd/containerd containerd CRI checkpoint restore CDI annotation smuggling in github.com/containerd/containerd GHSA-hrxh-6v49-42gf ↗ H 8.8 google.golang.org/grpc gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities GHSA-xhf5-7wjv-pqxp ↗ H 8.7 github.com/containerd/containerd containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull GHSA-33vj-92qq-66hc ↗ H 8.4 github.com/containerd/containerd/v2 containerd CRI checkpoint restore CDI annotation smuggling GHSA-jxpm-75mh-9fp7 ↗ H 7.5 oras.land/oras-go/v2 oras-go blob upload vulnerable to credential forwarding via unvalidated Location header GHSA-fxhp-mv3v-67qp ↗ H 7.1 oras.land/oras-go/v2 `oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution GHSA-hc8v-wwc9-vgxm ↗ H 7.1 github.com/go-git/go-git/v5 go-git: Worktree operations may follow symlinks GHSA-rgh6-rfwx-v388 ↗ H 7.1 github.com/containerd/containerd/v2 Arbitrary host CRI log file read via symlink following in CRI checkpoint restore GHSA-8xwf-rjm4-xvhv ↗ M 6.9 oras.land/oras-go/v2 oras-go has file store write outside workingDir via symlink traversal GHSA-jpcc-p29g-p8mq ↗ M 6.9 github.com/containerd/containerd containerd image-triggered runtime DoS via unbounded group parsing GHSA-vh4v-2xq2-g5cg ↗ M 6.9 oras.land/oras-go/v2 ORAS Go forwards registry credentials across registry redirects GO-2026-5622 ↗ M 6.5 github.com/containerd/containerd Arbitrary host CRI log file read via symlink following in CRI checkpoint restore in github.com/containerd/containerd GHSA-qgq7-7hm3-q39j ↗ M 6.3 github.com/go-git/go-git/v5 go-git: Malicious reference names may modify files outside the reference storage GHSA-xmrv-pmrh-hhx2 ↗ M 5.9 github.com/aws/aws-sdk-go-v2/service/s3 Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder GO-2026-5158 ↗ M 5.3 go.opentelemetry.io/otel Opentelemetry-go's baggage parsing no longer caps raw header length in go.opentelemetry.io/otel GHSA-xf85-363p-868w ↗ L 2.1 oras.land/oras-go/v2 oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens GO-2026-5841 ↗ ? — github.com/klauspost/compress Providing a specially crafted dictionary to s2.NewDict and using it to encode data can make the encoder read out of bounds. GO-2026-5932 ↗ ? — golang.org/x/crypto The golang.org/x/crypto/openpgp package is unsafe by design, has numerous known security issues, is not maintained, and should not be used. These are the findings of k9s, which ships every tool in this project. kapsl reports and gates; it never edits an image to clear a finding. Composition default + kubectl runtime none — self-contained composes kubectl Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly. Image repository ghcr.io/kapsl-sh/k9s platforms amd64 sha256:0c14…7db6 copy arm64 sha256:6296…04db copy size 130 MB unpacked · 1 layer base scratch signed cosign · 2026-08-29 · public key last scan 2026-08-29 Sandbox boundary k9s capabilities netnomountro Filled is granted to every invocation, outlined to some and not others — see per-subcommand below; the rest need --cap at the point of use. seccomp tier per tool default The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier. dotfiles mapped in read-only unless noted ~/.kube ~/.kube/cache · writable ~/.config/k9s ~/.config/k9s/config.yaml · writable ~/.local/share/k9s · writable ~/.local/state/k9s · writable env passed through 13 forwarded HELM_DRIVERHTTPS_PROXYHTTP_PROXYK9S_CLIPBOARDK9S_DEFAULT_PF_ADDRESSK9S_FEATURE_GATE_NODE_SHELLK9S_OSC52_MAXK9S_SKINNO_PROXYTMUXhttp_proxyhttps_proxyno_proxy Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask. env set by kapsl none none per-subcommand grants differ completion + nomount − netro info − net version + nomount − netro Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Where it needs less, kapsl takes it away there too. Provenance sbom amd64 ↗ arm64 ↗ attestation amd64 ↗ arm64 ↗ scan report amd64 ↗ arm64 ↗ grype · 2026-08-29 vex amd64 ↗ arm64 ↗ Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust. 20 findings across this project at latest. Counted once per advisory across every image the project builds.