The go binaries used in the nma modules in vertica have critical vulnerabilities
Environment
Vertica Analytics Database: version 23.4, 24.x 25.x
Situation
Vertica ships a few Go binaries, namely vcluster, vcluster_server and node_management_agent, which contain multiple known and fixed security vulnerabilities which are detected when scanning the binaries with vulnerability scanners like Trivy. All these vulnerabilities can be fixed by upgrading either vulnerable libraries or Go compiler itself. At least one vulnerability has Critical severity and flags the container image as unsafe to use, so it can't be deployed in environments with admission policies disallowing images with known fixed critical vulnerabilities.