58 entries matching kubernetes — updated 2026-09-19 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-61682 | kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior t | CRITICAL | 9.9 | — | NVD | 2026-09-18 |
| CVE-2026-61672 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, ForbiddenListSpec.ExactMatch in p | HIGH | 7.1 | — | NVD | 2026-09-18 |
| CVE-2026-61794 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, the Tenant update valida | MEDIUM | 6.8 | — | NVD | 2026-09-18 |
| CVE-2026-61795 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, hostnameRegexHandler.OnU | MEDIUM | 6.8 | — | NVD | 2026-09-18 |
| CVE-2026-45726 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a st | HIGH | 7.6 | 1%ile | NVD | 2026-09-17 |
| CVE-2026-50125 | MKP is a Model Context Protocol server for Kubernetes. Prior to 0.4.1, cmd/server/main.go exposes the default HTTP endpo | HIGH | 7.5 | 35%ile | NVD | 2026-09-17 |
| CVE-2026-45720 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.0 until 1.7.3, SAML. | HIGH | 7.0 | 2%ile | NVD | 2026-09-17 |
| CVE-2026-45723 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.Creat | LOW | 2.7 | 32%ile | NVD | 2026-09-17 |
| CVE-2026-92568 | MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows | MEDIUM | 5.3 | 22%ile | NVD | 2026-09-16 |
| CVE-2026-61549 | Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_op | CRITICAL | 9.0 | 6%ile | NVD | 2026-09-15 |
| CVE-2026-44300 | OpenCost provides cost monitoring for Kubernetes workloads and cloud costs. Prior to 1.121.0, the POST /serviceKey endpo | HIGH | 8.8 | 35%ile | NVD | 2026-09-15 |
| CVE-2026-55225 | Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. I | HIGH | 8.0 | 9%ile | NVD | 2026-09-15 |
| CVE-2026-53941 | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li | MEDIUM | 6.9 | 32%ile | NVD | 2026-09-15 |
| CVE-2026-52724 | Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2 | MEDIUM | 5.8 | 16%ile | NVD | 2026-09-15 |
| CVE-2026-55636 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.6, charts/capsule/templates | MEDIUM | 5.7 | 20%ile | NVD | 2026-09-15 |
| CVE-2026-50166 | Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2 | MEDIUM | 5.5 | 8%ile | NVD | 2026-09-15 |
| CVE-2026-55226 | Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. I | MEDIUM | 5.4 | 8%ile | NVD | 2026-09-15 |
| CVE-2026-59341 | A security vulnerability exists in the Sealed Secrets controller's unauthenticated POST endpoints. By submitting a modif | MEDIUM | 4.2 | 24%ile | NVD | 2026-09-15 |
| CVE-2026-44778 | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li | LOW | 2.9 | 39%ile | NVD | 2026-09-15 |
| CVE-2026-53713 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway | CRITICAL | 9.1 | 35%ile | NVD | 2026-09-14 |
| CVE-2026-47701 | The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/otel-allocato | HIGH | 7.7 | 21%ile | NVD | 2026-09-14 |
| CVE-2026-53714 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway | HIGH | 7.4 | 21%ile | NVD | 2026-09-14 |
| CVE-2026-53717 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway | MEDIUM | 6.5 | 52%ile | NVD | 2026-09-14 |
| CVE-2026-53716 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway | MEDIUM | 6.5 | 51%ile | NVD | 2026-09-14 |
| CVE-2026-53719 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway | MEDIUM | 6.5 | 51%ile | NVD | 2026-09-14 |
| CVE-2026-53718 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway | MEDIUM | 6.4 | 26%ile | NVD | 2026-09-14 |
| CVE-2026-54246 | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.13, the routesrv component serves clu | MEDIUM | 5.7 | 27%ile | NVD | 2026-09-14 |
| CVE-2026-53715 | Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gateway | MEDIUM | 5.3 | 30%ile | NVD | 2026-09-14 |
| CVE-2026-54247 | Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.22, Handler in dataclients/kubernetes | MEDIUM | 4.3 | 14%ile | NVD | 2026-09-14 |
| CVE-2026-56855 | Prevent DoS on deadlocked established channel in golang.org/x/crypto/ssh | HIGH | 7.5 | 32%ile | Microsoft | 2026-09-08 |
| CVE-2026-78662 | Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/ssh | HIGH | 7.5 | 25%ile | Microsoft | 2026-09-08 |
| CVE-2026-50516 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | CRITICAL | 9.4 | 56%ile | Microsoft | 2026-08-11 |
| CVE-2026-73499 | etcd: Watch API authorization bypass via open-ended range requests | UNKNOWN | — | 30%ile | Microsoft | 2026-08-11 |
| CVE-2026-73500 | etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline | UNKNOWN | — | 34%ile | Microsoft | 2026-08-11 |
| CVE-2026-32193 | Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability | HIGH | 8.8 | 27%ile | Microsoft | 2026-06-09 |
| CVE-2026-10722 | cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflow | LOW | 3.3 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-39821 | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | CRITICAL | 10.0 | 51%ile | Microsoft | 2026-05-12 |
| CVE-2026-39830 | Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh | CRITICAL | 9.1 | 48%ile | Microsoft | 2026-05-12 |
| CVE-2026-39834 | Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh | CRITICAL | 9.1 | 43%ile | Microsoft | 2026-05-12 |
| CVE-2026-39831 | Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh | CRITICAL | 9.1 | 36%ile | Microsoft | 2026-05-12 |
| CVE-2026-33814 | Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | HIGH | 7.5 | 54%ile | Microsoft | 2026-05-12 |
| CVE-2026-39829 | Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh | HIGH | 7.5 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-46597 | Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh | HIGH | 7.5 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-25680 | Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html | MEDIUM | 6.5 | 26%ile | Microsoft | 2026-05-12 |
| CVE-2026-39827 | Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh | MEDIUM | 6.5 | 21%ile | Microsoft | 2026-05-12 |
| CVE-2026-39828 | Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh | MEDIUM | 6.3 | 31%ile | Microsoft | 2026-05-12 |
| CVE-2026-25681 | Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html | MEDIUM | 6.1 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-27136 | Invoking duplicate attributes can cause XSS in golang.org/x/net/html | MEDIUM | 6.1 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-42502 | Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html | MEDIUM | 6.1 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-42506 | Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html | MEDIUM | 6.1 | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-39835 | Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh | MEDIUM | 5.3 | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-39824 | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows | LOW | 3.3 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-33105 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 52%ile | Microsoft | 2026-04-14 |
| CVE-2026-35469 | SpdyStream: DOS on CRI | HIGH | 8.1 | 50%ile | Microsoft | 2026-04-14 |
| CVE-2025-65637 | A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line pa | MEDIUM | 5.9 | 49%ile | Microsoft | 2025-12-09 |
| CVE-2025-13281 | Portworx Half-Blind SSRF in kube-controller-manager | MEDIUM | 5.8 | 33%ile | Microsoft | 2025-12-09 |
| CVE-2025-22869 | Potential denial of service in golang.org/x/crypto | HIGH | 7.5 | 59%ile | Microsoft | 2025-02-11 |
| CVE-2025-0426 | A security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthen | MEDIUM | 6.2 | 31%ile | Microsoft | 2025-02-11 |