← Back to feed Search feed

Kubernetes vulnerabilities

38 entries matching kubernetes — updated 2026-08-04 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-67309Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX providerHIGH7.840%ileNVD2026-08-01
CVE-2026-54725vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1CRITICAL9.624%ileNVD2026-07-31
CVE-2026-10079A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACHIGH8.56%ileNVD2026-07-31
GHSA-pqh8-p93p-2rx7@dynatrace-oss/dynatrace-mcp-server has a DQL injection via parameters not documented as DQLMEDIUM4.3GitHub2026-07-31
CVE-2026-62246Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane datHIGH8.519%ileNVD2026-07-30
CVE-2026-18381A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom rHIGH7.610%ileNVD2026-07-30
CVE-2026-65834Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.8, CapsuleConfiguration.Spec.NodeMetMEDIUM6.819%ileNVD2026-07-30
CVE-2026-65835Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVEMEDIUM6.69%ileNVD2026-07-30
CVE-2026-62845Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore drivMEDIUM4.710%ileNVD2026-07-30
CVE-2026-54680Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the FluentdCRITICAL9.935%ileNVD2026-07-29
CVE-2026-15228Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a clustHIGH7.14%ileNVD2026-07-29
CVE-2026-16543Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation prHIGH7.14%ileNVD2026-07-29
CVE-2026-50569Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checksMEDIUM4.314%ileGitHub2026-07-28
CVE-2026-56163Microsoft Azure Kubernetes Service Elevation of Privilege VulnerabilityCRITICAL10.056%ileMicrosoft2026-07-14
CVE-2026-32193Azure Kubernetes Service (AKS) Remote Code Execution VulnerabilityHIGH8.826%ileMicrosoft2026-06-09
CVE-2026-10722cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflowLOW3.38%ileMicrosoft2026-06-09
CVE-2026-39821Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idnaCRITICAL10.048%ileMicrosoft2026-05-12
CVE-2026-39824Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windowsCRITICAL9.82%ileMicrosoft2026-05-12
CVE-2026-39830Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/sshCRITICAL9.146%ileMicrosoft2026-05-12
CVE-2026-39831Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/sshCRITICAL9.135%ileMicrosoft2026-05-12
CVE-2026-39834Invoking infinite loop on large channel writes in golang.org/x/crypto/sshCRITICAL9.142%ileMicrosoft2026-05-12
CVE-2026-33814Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/netHIGH7.552%ileMicrosoft2026-05-12
CVE-2026-39829Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/sshHIGH7.538%ileMicrosoft2026-05-12
CVE-2026-46597Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/sshHIGH7.538%ileMicrosoft2026-05-12
CVE-2026-39827Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/sshMEDIUM6.520%ileMicrosoft2026-05-12
CVE-2026-25680Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/htmlMEDIUM6.525%ileMicrosoft2026-05-12
CVE-2026-39828Invoking bypass of certificate restrictions in golang.org/x/crypto/sshMEDIUM6.330%ileMicrosoft2026-05-12
CVE-2026-42506Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/htmlMEDIUM6.115%ileMicrosoft2026-05-12
CVE-2026-42502Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/htmlMEDIUM6.113%ileMicrosoft2026-05-12
CVE-2026-27136Invoking duplicate attributes can cause XSS in golang.org/x/net/htmlMEDIUM6.113%ileMicrosoft2026-05-12
CVE-2026-25681Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/htmlMEDIUM6.113%ileMicrosoft2026-05-12
CVE-2026-39835Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/sshMEDIUM5.340%ileMicrosoft2026-05-12
CVE-2026-33105Microsoft Azure Kubernetes Service Elevation of Privilege VulnerabilityCRITICAL10.050%ileMicrosoft2026-04-14
CVE-2025-47291containerd CRI plugin: Incorrect cgroup hierarchy assignment for containers running in usernamespaced Kubernetes pods.HIGH7.516%ileMicrosoft2025-05-13
CVE-2024-29990Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege VulnerabilityCRITICAL9.097%ileMicrosoft2024-04-09
CVE-2023-45288HTTP/2 CONTINUATION flood in net/httpHIGH7.5100%ileMicrosoft2024-04-09
CVE-2024-28917Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege VulnerabilityMEDIUM6.256%ileMicrosoft2024-04-09
CVE-2024-3177Bypassing mountable secrets policy imposed by the ServiceAccount admission pluginLOW2.781%ileMicrosoft2024-04-09