Identified Vulnerabilities in cluster-autoscaler
Author: jparker999Created Sep 1, 2026Updated Sep 16, 2026
Labelsarea/cluster-autoscalerneeds-triage
cluster-autoscaler at 1.35.2 uses packages golang.org/x/crypto at 0.47.0, which is subject to the following public CVEs
CVE-2026-46595 CVE-2026-39833 CVE-2026-39830 CVE-2026-39834 CVE-2026-42508 CVE-2026-39832 CVE-2026-39831 CVE-2026-46597 CVE-2026-39829
Requesting that cluster-autoscaler 1.35.2 be patched to use golang.org/x/crypto 0.52.0
/area cluster-autoscaler
Source: kubernetes/autoscaler