kapsl Index
Docs Releases

k9s

1 tool · 1 release line

Terminal UI for managing Kubernetes clusters. Every tool here carries the same sandbox boundary.

Release lines we maintain · the project decides these

findings shown are the whole project at that line

Tag Resolves to Lifecycle Updated Findings What the tag promises
  • stable — floats, carries security updates
  • unstable — tracks pre-releases, may break
  • eol — frozen, upstream is done

Tools in this project · pick one to inspect

all share one boundary

Tool Capabilities Seccomp Findings Image Description
showing k9s from k9s@latest → 0.51.0 stable

Findings

C3H7M7L1?2

identical on amd64, arm64 — one table describes both

CVE Sev CVSS Affects Description
GHSA-cvxm-645q-p574 ↗ C 9.9 github.com/containerd/containerd/v2 containerd: CRI checkpoint import allows local image tag poisoning
GO-2026-5338 ↗ C 9.9 github.com/containerd/containerd containerd: CRI checkpoint import allows local image tag poisoning in github.com/containerd/containerd
GO-2026-5064 ↗ C 9.6 github.com/containerd/containerd containerd CRI checkpoint restore CDI annotation smuggling in github.com/containerd/containerd
GHSA-hrxh-6v49-42gf ↗ H 8.8 google.golang.org/grpc gRPC-Go: xDS RBAC and HTTP/2 Vulnerabilities
GHSA-xhf5-7wjv-pqxp ↗ H 8.7 github.com/containerd/containerd containerd CRI — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull
GHSA-33vj-92qq-66hc ↗ H 8.4 github.com/containerd/containerd/v2 containerd CRI checkpoint restore CDI annotation smuggling
GHSA-jxpm-75mh-9fp7 ↗ H 7.5 oras.land/oras-go/v2 oras-go blob upload vulnerable to credential forwarding via unvalidated Location header
GHSA-fxhp-mv3v-67qp ↗ H 7.1 oras.land/oras-go/v2 `oras-go` tar extraction: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution
GHSA-hc8v-wwc9-vgxm ↗ H 7.1 github.com/go-git/go-git/v5 go-git: Worktree operations may follow symlinks
GHSA-rgh6-rfwx-v388 ↗ H 7.1 github.com/containerd/containerd/v2 Arbitrary host CRI log file read via symlink following in CRI checkpoint restore
GHSA-8xwf-rjm4-xvhv ↗ M 6.9 oras.land/oras-go/v2 oras-go has file store write outside workingDir via symlink traversal
GHSA-jpcc-p29g-p8mq ↗ M 6.9 github.com/containerd/containerd containerd image-triggered runtime DoS via unbounded group parsing
GHSA-vh4v-2xq2-g5cg ↗ M 6.9 oras.land/oras-go/v2 ORAS Go forwards registry credentials across registry redirects
GO-2026-5622 ↗ M 6.5 github.com/containerd/containerd Arbitrary host CRI log file read via symlink following in CRI checkpoint restore in github.com/containerd/containerd
GHSA-qgq7-7hm3-q39j ↗ M 6.3 github.com/go-git/go-git/v5 go-git: Malicious reference names may modify files outside the reference storage
GHSA-xmrv-pmrh-hhx2 ↗ M 5.9 github.com/aws/aws-sdk-go-v2/service/s3 Denial of Service due to Panic in AWS SDK for Go v2 SDK EventStream Decoder
GO-2026-5158 ↗ M 5.3 go.opentelemetry.io/otel Opentelemetry-go's baggage parsing no longer caps raw header length in go.opentelemetry.io/otel
GHSA-xf85-363p-868w ↗ L 2.1 oras.land/oras-go/v2 oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens
GO-2026-5841 ↗ ? github.com/klauspost/compress Providing a specially crafted dictionary to s2.NewDict and using it to encode data can make the encoder read out of bounds.
GO-2026-5932 ↗ ? golang.org/x/crypto The golang.org/x/crypto/openpgp package is unsafe by design, has numerous known security issues, is not maintained, and should not be used.

These are the findings of k9s, which ships every tool in this project. kapsl reports and gates; it never edits an image to clear a finding.

Composition

default + kubectl
runtime none — self-contained
composes kubectl

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly.

Image

repository ghcr.io/kapsl-sh/k9s
platforms
size 130 MB unpacked · 1 layer
base scratch
signed cosign · · public key
last scan

Sandbox boundary

k9s

capabilities

netnomountro

Filled is granted to every invocation, outlined to some and not others — see per-subcommand below; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

  • ~/.kube
  • ~/.kube/cache · writable
  • ~/.config/k9s
  • ~/.config/k9s/config.yaml · writable
  • ~/.local/share/k9s · writable
  • ~/.local/state/k9s · writable

env passed through

13 forwarded

HELM_DRIVERHTTPS_PROXYHTTP_PROXYK9S_CLIPBOARDK9S_DEFAULT_PF_ADDRESSK9S_FEATURE_GATE_NODE_SHELLK9S_OSC52_MAXK9S_SKINNO_PROXYTMUXhttp_proxyhttps_proxyno_proxy

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by kapsl

none

none

per-subcommand

grants differ

completion + nomount netro
info net
version + nomount netro

Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere. Where it needs less, kapsl takes it away there too.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

20 findings across this project at latest. Counted once per advisory across every image the project builds.