38 entries matching kubernetes — updated 2026-08-04 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-67309 | Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX provider | HIGH | 7.8 | 40%ile | NVD | 2026-08-01 |
| CVE-2026-54725 | vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1 | CRITICAL | 9.6 | 24%ile | NVD | 2026-07-31 |
| CVE-2026-10079 | A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, AC | HIGH | 8.5 | 6%ile | NVD | 2026-07-31 |
| GHSA-pqh8-p93p-2rx7 | @dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQL | MEDIUM | 4.3 | — | GitHub | 2026-07-31 |
| CVE-2026-62246 | Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane dat | HIGH | 8.5 | 19%ile | NVD | 2026-07-30 |
| CVE-2026-18381 | A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom r | HIGH | 7.6 | 10%ile | NVD | 2026-07-30 |
| CVE-2026-65834 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.8, CapsuleConfiguration.Spec.NodeMet | MEDIUM | 6.8 | 19%ile | NVD | 2026-07-30 |
| CVE-2026-65835 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE | MEDIUM | 6.6 | 9%ile | NVD | 2026-07-30 |
| CVE-2026-62845 | Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore driv | MEDIUM | 4.7 | 10%ile | NVD | 2026-07-30 |
| CVE-2026-54680 | Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd | CRITICAL | 9.9 | 35%ile | NVD | 2026-07-29 |
| CVE-2026-15228 | Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a clust | HIGH | 7.1 | 4%ile | NVD | 2026-07-29 |
| CVE-2026-16543 | Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation pr | HIGH | 7.1 | 4%ile | NVD | 2026-07-29 |
| CVE-2026-50569 | Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks | MEDIUM | 4.3 | 14%ile | GitHub | 2026-07-28 |
| CVE-2026-56163 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 56%ile | Microsoft | 2026-07-14 |
| CVE-2026-32193 | Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability | HIGH | 8.8 | 26%ile | Microsoft | 2026-06-09 |
| CVE-2026-10722 | cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflow | LOW | 3.3 | 8%ile | Microsoft | 2026-06-09 |
| CVE-2026-39821 | Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idna | CRITICAL | 10.0 | 48%ile | Microsoft | 2026-05-12 |
| CVE-2026-39824 | Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windows | CRITICAL | 9.8 | 2%ile | Microsoft | 2026-05-12 |
| CVE-2026-39830 | Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh | CRITICAL | 9.1 | 46%ile | Microsoft | 2026-05-12 |
| CVE-2026-39831 | Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh | CRITICAL | 9.1 | 35%ile | Microsoft | 2026-05-12 |
| CVE-2026-39834 | Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh | CRITICAL | 9.1 | 42%ile | Microsoft | 2026-05-12 |
| CVE-2026-33814 | Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/net | HIGH | 7.5 | 52%ile | Microsoft | 2026-05-12 |
| CVE-2026-39829 | Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh | HIGH | 7.5 | 38%ile | Microsoft | 2026-05-12 |
| CVE-2026-46597 | Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh | HIGH | 7.5 | 38%ile | Microsoft | 2026-05-12 |
| CVE-2026-39827 | Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh | MEDIUM | 6.5 | 20%ile | Microsoft | 2026-05-12 |
| CVE-2026-25680 | Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/html | MEDIUM | 6.5 | 25%ile | Microsoft | 2026-05-12 |
| CVE-2026-39828 | Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh | MEDIUM | 6.3 | 30%ile | Microsoft | 2026-05-12 |
| CVE-2026-42506 | Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/html | MEDIUM | 6.1 | 15%ile | Microsoft | 2026-05-12 |
| CVE-2026-42502 | Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/html | MEDIUM | 6.1 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-27136 | Invoking duplicate attributes can cause XSS in golang.org/x/net/html | MEDIUM | 6.1 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-25681 | Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/html | MEDIUM | 6.1 | 13%ile | Microsoft | 2026-05-12 |
| CVE-2026-39835 | Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh | MEDIUM | 5.3 | 40%ile | Microsoft | 2026-05-12 |
| CVE-2026-33105 | Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability | CRITICAL | 10.0 | 50%ile | Microsoft | 2026-04-14 |
| CVE-2025-47291 | containerd CRI plugin: Incorrect cgroup hierarchy assignment for containers running in usernamespaced Kubernetes pods. | HIGH | 7.5 | 16%ile | Microsoft | 2025-05-13 |
| CVE-2024-29990 | Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability | CRITICAL | 9.0 | 97%ile | Microsoft | 2024-04-09 |
| CVE-2023-45288 | HTTP/2 CONTINUATION flood in net/http | HIGH | 7.5 | 100%ile | Microsoft | 2024-04-09 |
| CVE-2024-28917 | Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability | MEDIUM | 6.2 | 56%ile | Microsoft | 2024-04-09 |
| CVE-2024-3177 | Bypassing mountable secrets policy imposed by the ServiceAccount admission plugin | LOW | 2.7 | 81%ile | Microsoft | 2024-04-09 |