Skip to content

gcr.io/google.com/cloudsdktool/cloud-sdk:latest (debian 12.13)

Trivy Image Scan

  • Image: gcr.io/google.com/cloudsdktool/cloud-sdk:latest (debian 12.13)
  • Scan date: 2026-04-24

gcr.io/google.com/cloudsdktool/cloud-sdk:latest (debian 12.13) (debian)

Package Vulnerability ID Severity Installed Version Fixed Version Links
apt CVE-2011-3374 LOW 2.6.1 no fix available
apt-transport-https CVE-2011-3374 LOW 2.6.1 no fix available
bash TEMP-0841856-B18BAF LOW 5.2.15-2+b10 no fix available
binutils CVE-2017-13716 LOW 2.40-2 no fix available
binutils CVE-2018-20673 LOW 2.40-2 no fix available
binutils CVE-2018-20712 LOW 2.40-2 no fix available
binutils CVE-2018-9996 LOW 2.40-2 no fix available
binutils CVE-2021-32256 LOW 2.40-2 no fix available
binutils CVE-2023-1972 LOW 2.40-2 no fix available
binutils CVE-2024-53589 LOW 2.40-2 no fix available
binutils CVE-2024-57360 LOW 2.40-2 no fix available
binutils CVE-2025-0840 LOW 2.40-2 no fix available
binutils CVE-2025-11081 LOW 2.40-2 no fix available
binutils CVE-2025-11082 LOW 2.40-2 no fix available
binutils CVE-2025-11083 LOW 2.40-2 no fix available
binutils CVE-2025-11412 LOW 2.40-2 no fix available
binutils CVE-2025-11413 LOW 2.40-2 no fix available
binutils CVE-2025-11414 LOW 2.40-2 no fix available
binutils CVE-2025-1147 LOW 2.40-2 no fix available
binutils CVE-2025-1148 LOW 2.40-2 no fix available
binutils CVE-2025-1149 LOW 2.40-2 no fix available
binutils CVE-2025-11494 LOW 2.40-2 no fix available
binutils CVE-2025-11495 LOW 2.40-2 no fix available
binutils CVE-2025-1150 LOW 2.40-2 no fix available
binutils CVE-2025-1151 LOW 2.40-2 no fix available
binutils CVE-2025-1152 LOW 2.40-2 no fix available
binutils CVE-2025-1153 LOW 2.40-2 no fix available
binutils CVE-2025-1176 LOW 2.40-2 no fix available
binutils CVE-2025-1178 LOW 2.40-2 no fix available
binutils CVE-2025-1179 LOW 2.40-2 no fix available
binutils CVE-2025-1180 LOW 2.40-2 no fix available
binutils CVE-2025-1181 LOW 2.40-2 no fix available
binutils CVE-2025-1182 LOW 2.40-2 no fix available
binutils CVE-2025-11839 LOW 2.40-2 no fix available
binutils CVE-2025-11840 LOW 2.40-2 no fix available
binutils CVE-2025-3198 LOW 2.40-2 no fix available
binutils CVE-2025-5244 LOW 2.40-2 no fix available
binutils CVE-2025-5245 LOW 2.40-2 no fix available
binutils CVE-2025-66861 LOW 2.40-2 no fix available
binutils CVE-2025-66862 LOW 2.40-2 no fix available
binutils CVE-2025-66863 LOW 2.40-2 no fix available
binutils CVE-2025-66864 LOW 2.40-2 no fix available
binutils CVE-2025-66865 LOW 2.40-2 no fix available
binutils CVE-2025-66866 LOW 2.40-2 no fix available
binutils CVE-2025-69644 LOW 2.40-2 no fix available
binutils CVE-2025-69645 LOW 2.40-2 no fix available
binutils CVE-2025-69646 LOW 2.40-2 no fix available
binutils CVE-2025-69647 LOW 2.40-2 no fix available
binutils CVE-2025-69648 LOW 2.40-2 no fix available
binutils CVE-2025-69649 LOW 2.40-2 no fix available
2081 other vulnerabilities found...
No Misconfigurations found

Java (jar)

Package Vulnerability ID Severity Installed Version Fixed Version Links
org.eclipse.jetty.ee10:jetty-ee10-jaspi CVE-2026-5795 HIGH 12.1.6 12.1.8, 12.0.34
org.eclipse.jetty.ee11:jetty-ee11-jaspi CVE-2026-5795 HIGH 12.1.6 12.1.8, 12.0.34
org.eclipse.jetty.ee9:jetty-ee9-jaspi CVE-2026-5795 HIGH 12.1.6 12.1.8, 12.0.34
org.eclipse.jetty:jetty-http CVE-2026-2332 HIGH 12.1.6 12.1.7, 12.0.33, 11.0.28, 10.0.28, 9.4.60
No Misconfigurations found

Python (python-pkg)

Package Vulnerability ID Severity Installed Version Fixed Version Links
cryptography CVE-2026-26007 HIGH 43.0.1 46.0.5
cryptography CVE-2024-12797 LOW 43.0.1 44.0.1
cryptography CVE-2026-34073 LOW 43.0.1 46.0.6
pip CVE-2026-1703 LOW 25.3 26.0
pyOpenSSL CVE-2026-27459 HIGH 24.2.1 26.0.0
pyOpenSSL CVE-2026-27448 LOW 24.2.1 26.0.0
No Misconfigurations found

usr/lib/google-cloud-sdk/bin/anthoscli (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
github.com/sirupsen/logrus CVE-2025-65637 HIGH v1.9.0 1.8.3, 1.9.1, 1.9.3
golang.org/x/crypto CVE-2025-47914 MEDIUM v0.42.0 0.45.0
golang.org/x/crypto CVE-2025-58181 MEDIUM v0.42.0 0.45.0
google.golang.org/grpc CVE-2026-33186 CRITICAL v1.58.3 1.79.3
stdlib CVE-2025-68121 CRITICAL v1.25.3 1.24.13, 1.25.7, 1.26.0-rc.3
stdlib CVE-2025-61726 HIGH v1.25.3 1.24.12, 1.25.6
stdlib CVE-2025-61728 HIGH v1.25.3 1.24.12, 1.25.6
stdlib CVE-2025-61729 HIGH v1.25.3 1.24.11, 1.25.5
stdlib CVE-2026-25679 HIGH v1.25.3 1.25.8, 1.26.1
stdlib CVE-2026-32280 HIGH v1.25.3 1.25.9, 1.26.2
stdlib CVE-2026-32281 HIGH v1.25.3 1.25.9, 1.26.2
stdlib CVE-2026-32283 HIGH v1.25.3 1.25.9, 1.26.2
stdlib CVE-2025-61727 MEDIUM v1.25.3 1.24.11, 1.25.5
stdlib CVE-2025-61730 MEDIUM v1.25.3 1.24.12, 1.25.6
stdlib CVE-2026-27142 MEDIUM v1.25.3 1.25.8, 1.26.1
stdlib CVE-2026-32282 MEDIUM v1.25.3 1.25.9, 1.26.2
stdlib CVE-2026-32288 MEDIUM v1.25.3 1.25.9, 1.26.2
stdlib CVE-2026-32289 MEDIUM v1.25.3 1.25.9, 1.26.2
stdlib CVE-2026-27139 LOW v1.25.3 1.25.8, 1.26.1
No Misconfigurations found

usr/lib/google-cloud-sdk/bin/cbt (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
github.com/go-jose/go-jose/v4 CVE-2026-34986 HIGH v4.0.5 4.1.4
go.opentelemetry.io/otel/sdk CVE-2026-24051 HIGH v1.36.0 1.40.0
go.opentelemetry.io/otel/sdk CVE-2026-39883 HIGH v1.36.0 1.43.0
golang.org/x/crypto CVE-2025-47914 MEDIUM v0.41.0 0.45.0
golang.org/x/crypto CVE-2025-58181 MEDIUM v0.41.0 0.45.0
google.golang.org/grpc CVE-2026-33186 CRITICAL v1.74.2 1.79.3
stdlib CVE-2025-68121 CRITICAL v1.24.11 1.24.13, 1.25.7, 1.26.0-rc.3
stdlib CVE-2025-61726 HIGH v1.24.11 1.24.12, 1.25.6
stdlib CVE-2025-61728 HIGH v1.24.11 1.24.12, 1.25.6
stdlib CVE-2026-25679 HIGH v1.24.11 1.25.8, 1.26.1
stdlib CVE-2026-32280 HIGH v1.24.11 1.25.9, 1.26.2
stdlib CVE-2026-32281 HIGH v1.24.11 1.25.9, 1.26.2
stdlib CVE-2026-32283 HIGH v1.24.11 1.25.9, 1.26.2
stdlib CVE-2025-61730 MEDIUM v1.24.11 1.24.12, 1.25.6
stdlib CVE-2026-27142 MEDIUM v1.24.11 1.25.8, 1.26.1
stdlib CVE-2026-32282 MEDIUM v1.24.11 1.25.9, 1.26.2
stdlib CVE-2026-32288 MEDIUM v1.24.11 1.25.9, 1.26.2
stdlib CVE-2026-32289 MEDIUM v1.24.11 1.25.9, 1.26.2
stdlib CVE-2026-27139 LOW v1.24.11 1.25.8, 1.26.1
No Misconfigurations found

usr/lib/google-cloud-sdk/bin/cloud_spanner_emulator/gateway_main (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2025-68121 CRITICAL v1.23.6 1.24.13, 1.25.7, 1.26.0-rc.3
stdlib CVE-2025-47907 HIGH v1.23.6 1.23.12, 1.24.6
stdlib CVE-2025-58183 HIGH v1.23.6 1.24.8, 1.25.2
stdlib CVE-2025-61726 HIGH v1.23.6 1.24.12, 1.25.6
stdlib CVE-2025-61728 HIGH v1.23.6 1.24.12, 1.25.6
stdlib CVE-2025-61729 HIGH v1.23.6 1.24.11, 1.25.5
stdlib CVE-2026-25679 HIGH v1.23.6 1.25.8, 1.26.1
stdlib CVE-2026-32280 HIGH v1.23.6 1.25.9, 1.26.2
stdlib CVE-2026-32281 HIGH v1.23.6 1.25.9, 1.26.2
stdlib CVE-2026-32283 HIGH v1.23.6 1.25.9, 1.26.2
stdlib CVE-2025-0913 MEDIUM v1.23.6 1.23.10, 1.24.4
stdlib CVE-2025-22870 MEDIUM v1.23.6 1.23.7, 1.24.1
stdlib CVE-2025-22871 MEDIUM v1.23.6 1.23.8, 1.24.2
stdlib CVE-2025-22873 MEDIUM v1.23.6 1.23.9, 1.24.3
stdlib CVE-2025-4673 MEDIUM v1.23.6 1.23.10, 1.24.4
stdlib CVE-2025-47906 MEDIUM v1.23.6 1.23.12, 1.24.6
stdlib CVE-2025-47912 MEDIUM v1.23.6 1.24.8, 1.25.2
stdlib CVE-2025-58185 MEDIUM v1.23.6 1.24.8, 1.25.2
stdlib CVE-2025-58186 MEDIUM v1.23.6 1.24.8, 1.25.2
stdlib CVE-2025-58187 MEDIUM v1.23.6 1.24.9, 1.25.3
stdlib CVE-2025-58188 MEDIUM v1.23.6 1.24.8, 1.25.2
stdlib CVE-2025-58189 MEDIUM v1.23.6 1.24.8, 1.25.2
stdlib CVE-2025-61723 MEDIUM v1.23.6 1.24.8, 1.25.2
stdlib CVE-2025-61724 MEDIUM v1.23.6 1.24.8, 1.25.2
stdlib CVE-2025-61725 MEDIUM v1.23.6 1.24.8, 1.25.2
stdlib CVE-2025-61727 MEDIUM v1.23.6 1.24.11, 1.25.5
stdlib CVE-2025-61730 MEDIUM v1.23.6 1.24.12, 1.25.6
stdlib CVE-2026-27142 MEDIUM v1.23.6 1.25.8, 1.26.1
stdlib CVE-2026-32282 MEDIUM v1.23.6 1.25.9, 1.26.2
stdlib CVE-2026-32288 MEDIUM v1.23.6 1.25.9, 1.26.2
stdlib CVE-2026-32289 MEDIUM v1.23.6 1.25.9, 1.26.2
stdlib CVE-2026-27139 LOW v1.23.6 1.25.8, 1.26.1
No Misconfigurations found

usr/lib/google-cloud-sdk/bin/gcloud-crc32c (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2026-32280 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32281 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32283 HIGH v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-33810 HIGH v1.26.1 1.26.2
stdlib CVE-2026-32282 MEDIUM v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32288 MEDIUM v1.26.1 1.25.9, 1.26.2
stdlib CVE-2026-32289 MEDIUM v1.26.1 1.25.9, 1.26.2
No Misconfigurations found

usr/lib/google-cloud-sdk/bin/gke-gcloud-auth-plugin (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2026-25679 HIGH v1.24.13 1.25.8, 1.26.1
stdlib CVE-2026-32280 HIGH v1.24.13 1.25.9, 1.26.2
stdlib CVE-2026-32281 HIGH v1.24.13 1.25.9, 1.26.2
stdlib CVE-2026-32283 HIGH v1.24.13 1.25.9, 1.26.2
stdlib CVE-2026-27142 MEDIUM v1.24.13 1.25.8, 1.26.1
stdlib CVE-2026-32282 MEDIUM v1.24.13 1.25.9, 1.26.2
stdlib CVE-2026-32288 MEDIUM v1.24.13 1.25.9, 1.26.2
stdlib CVE-2026-32289 MEDIUM v1.24.13 1.25.9, 1.26.2
stdlib CVE-2026-27139 LOW v1.24.13 1.25.8, 1.26.1
No Misconfigurations found

usr/lib/google-cloud-sdk/bin/kpt (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
github.com/docker/cli CVE-2025-15558 HIGH v28.1.1+incompatible 29.2.0
github.com/moby/spdystream CVE-2026-35469 HIGH v0.5.0 0.5.1
stdlib CVE-2025-68121 CRITICAL v1.25.6 1.24.13, 1.25.7, 1.26.0-rc.3
stdlib CVE-2026-25679 HIGH v1.25.6 1.25.8, 1.26.1
stdlib CVE-2026-32280 HIGH v1.25.6 1.25.9, 1.26.2
stdlib CVE-2026-32281 HIGH v1.25.6 1.25.9, 1.26.2
stdlib CVE-2026-32283 HIGH v1.25.6 1.25.9, 1.26.2
stdlib CVE-2026-27142 MEDIUM v1.25.6 1.25.8, 1.26.1
stdlib CVE-2026-32282 MEDIUM v1.25.6 1.25.9, 1.26.2
stdlib CVE-2026-32288 MEDIUM v1.25.6 1.25.9, 1.26.2
stdlib CVE-2026-32289 MEDIUM v1.25.6 1.25.9, 1.26.2
stdlib CVE-2026-27139 LOW v1.25.6 1.25.8, 1.26.1
No Misconfigurations found

usr/lib/google-cloud-sdk/bin/local-extract (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2026-25679 HIGH v1.26-20251026-RC00 1.25.8, 1.26.1
stdlib CVE-2026-27137 HIGH v1.26-20251026-RC00 1.26.1
stdlib CVE-2026-32280 HIGH v1.26-20251026-RC00 1.25.9, 1.26.2
stdlib CVE-2026-32281 HIGH v1.26-20251026-RC00 1.25.9, 1.26.2
stdlib CVE-2026-32283 HIGH v1.26-20251026-RC00 1.25.9, 1.26.2
stdlib CVE-2026-33810 HIGH v1.26-20251026-RC00 1.26.2
stdlib CVE-2026-27142 MEDIUM v1.26-20251026-RC00 1.25.8, 1.26.1
stdlib CVE-2026-32282 MEDIUM v1.26-20251026-RC00 1.25.9, 1.26.2
stdlib CVE-2026-32288 MEDIUM v1.26-20251026-RC00 1.25.9, 1.26.2
stdlib CVE-2026-32289 MEDIUM v1.26-20251026-RC00 1.25.9, 1.26.2
stdlib CVE-2026-27138 LOW v1.26-20251026-RC00 1.26.1
stdlib CVE-2026-27139 LOW v1.26-20251026-RC00 1.25.8, 1.26.1
No Misconfigurations found

usr/lib/google-cloud-sdk/platform/bigtable-emulator/cbtemulator (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
google.golang.org/grpc CVE-2026-33186 CRITICAL v1.72.0 1.79.3
stdlib CVE-2025-68121 CRITICAL v1.24.3 1.24.13, 1.25.7, 1.26.0-rc.3
stdlib CVE-2025-22874 HIGH v1.24.3 1.24.4
stdlib CVE-2025-47907 HIGH v1.24.3 1.23.12, 1.24.6
stdlib CVE-2025-58183 HIGH v1.24.3 1.24.8, 1.25.2
stdlib CVE-2025-61726 HIGH v1.24.3 1.24.12, 1.25.6
stdlib CVE-2025-61728 HIGH v1.24.3 1.24.12, 1.25.6
stdlib CVE-2025-61729 HIGH v1.24.3 1.24.11, 1.25.5
stdlib CVE-2026-25679 HIGH v1.24.3 1.25.8, 1.26.1
stdlib CVE-2026-32280 HIGH v1.24.3 1.25.9, 1.26.2
stdlib CVE-2026-32281 HIGH v1.24.3 1.25.9, 1.26.2
stdlib CVE-2026-32283 HIGH v1.24.3 1.25.9, 1.26.2
stdlib CVE-2025-0913 MEDIUM v1.24.3 1.23.10, 1.24.4
stdlib CVE-2025-4673 MEDIUM v1.24.3 1.23.10, 1.24.4
stdlib CVE-2025-47906 MEDIUM v1.24.3 1.23.12, 1.24.6
stdlib CVE-2025-47912 MEDIUM v1.24.3 1.24.8, 1.25.2
stdlib CVE-2025-58185 MEDIUM v1.24.3 1.24.8, 1.25.2
stdlib CVE-2025-58186 MEDIUM v1.24.3 1.24.8, 1.25.2
stdlib CVE-2025-58187 MEDIUM v1.24.3 1.24.9, 1.25.3
stdlib CVE-2025-58188 MEDIUM v1.24.3 1.24.8, 1.25.2
stdlib CVE-2025-58189 MEDIUM v1.24.3 1.24.8, 1.25.2
stdlib CVE-2025-61723 MEDIUM v1.24.3 1.24.8, 1.25.2
stdlib CVE-2025-61724 MEDIUM v1.24.3 1.24.8, 1.25.2
stdlib CVE-2025-61725 MEDIUM v1.24.3 1.24.8, 1.25.2
stdlib CVE-2025-61727 MEDIUM v1.24.3 1.24.11, 1.25.5
stdlib CVE-2025-61730 MEDIUM v1.24.3 1.24.12, 1.25.6
stdlib CVE-2026-27142 MEDIUM v1.24.3 1.25.8, 1.26.1
stdlib CVE-2026-32282 MEDIUM v1.24.3 1.25.9, 1.26.2
stdlib CVE-2026-32288 MEDIUM v1.24.3 1.25.9, 1.26.2
stdlib CVE-2026-32289 MEDIUM v1.24.3 1.25.9, 1.26.2
stdlib CVE-2026-27139 LOW v1.24.3 1.25.8, 1.26.1
No Misconfigurations found

usr/lib/google-cloud-sdk/platform/bundledpythonunix/lib/python3.13/site-packages/rust/Cargo.lock (cargo)

Package Vulnerability ID Severity Installed Version Fixed Version Links
openssl CVE-2026-41676 HIGH 0.10.66 0.10.78
openssl CVE-2026-41678 HIGH 0.10.66 0.10.78
openssl CVE-2026-41681 HIGH 0.10.66 0.10.78
openssl GHSA-hppc-g8h3-xhp3 HIGH 0.10.66 0.10.78
openssl CVE-2025-24898 MEDIUM 0.10.66 0.10.70
openssl GHSA-4fcv-w3qc-ppgg MEDIUM 0.10.66 0.10.72
openssl CVE-2026-41677 LOW 0.10.66 0.10.78
pyo3 CVE-2024-9979 MEDIUM 0.22.2 0.22.4
pyo3 GHSA-pph8-gcv7-4qj5 LOW 0.22.2 0.24.1
No Misconfigurations found

usr/lib/google-cloud-sdk/platform/google_appengine/go-app-stager (gobinary)

Package Vulnerability ID Severity Installed Version Fixed Version Links
stdlib CVE-2026-25679 HIGH v1.26-20260115-RC01 1.25.8, 1.26.1
stdlib CVE-2026-27137 HIGH v1.26-20260115-RC01 1.26.1
stdlib CVE-2026-32280 HIGH v1.26-20260115-RC01 1.25.9, 1.26.2
stdlib CVE-2026-32281 HIGH v1.26-20260115-RC01 1.25.9, 1.26.2
stdlib CVE-2026-32283 HIGH v1.26-20260115-RC01 1.25.9, 1.26.2
stdlib CVE-2026-33810 HIGH v1.26-20260115-RC01 1.26.2
stdlib CVE-2026-27142 MEDIUM v1.26-20260115-RC01 1.25.8, 1.26.1
stdlib CVE-2026-32282 MEDIUM v1.26-20260115-RC01 1.25.9, 1.26.2
stdlib CVE-2026-32288 MEDIUM v1.26-20260115-RC01 1.25.9, 1.26.2
stdlib CVE-2026-32289 MEDIUM v1.26-20260115-RC01 1.25.9, 1.26.2
stdlib CVE-2026-27138 LOW v1.26-20260115-RC01 1.26.1
stdlib CVE-2026-27139 LOW v1.26-20260115-RC01 1.25.8, 1.26.1
No Misconfigurations found