Skip to content

cluster-agent:7.77.2 vulnerable to Go SDK CVEs: CVE-2026-34742, CVE-2026-33252, GHSA-q382-vc8q-7jhj #49295

@schammah

Description

@schammah

Summary

The latest cluster-agent image (7.77.2) contains Go SDK vulnerabilities that require a Go toolchain rebuild to fix.

Affected image

  • registry.datadoghq.com/cluster-agent:7.77.2
  • Digest: sha256:bf8d4d80e164ebe9b35d514b7d4c1bad7770128fdf74edf78ad345b80734855d

CVEs

ID Source
CVE-2026-34742 Go SDK
CVE-2026-33252 Go SDK
GHSA-q382-vc8q-7jhj Go SDK

Details

All three vulnerabilities are in the Go standard library / SDK. The fix requires rebuilding the cluster agent with a patched Go toolchain version. The Go project has already issued fixes for these.

Steps to reproduce

Scan registry.datadoghq.com/cluster-agent:7.77.2 with any container vulnerability scanner (e.g. Wiz, Trivy).

Request

Please rebuild cluster-agent with a patched Go version and cut a new release. We are currently on the latest available version (7.77.2) with no patched version to upgrade to.

Metadata

Metadata

Assignees

No one assigned

    Labels

    oss/0External contributions priority 0pendingLabel for issues waiting a Datadog member's response.team/container-platformThe Container Platform Team

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions