← Back to feed Search feed

Kubernetes vulnerabilities

58 entries matching kubernetes — updated 2026-09-19 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-61682kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior tCRITICAL9.9NVD2026-09-18
CVE-2026-61672Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, ForbiddenListSpec.ExactMatch in pHIGH7.1NVD2026-09-18
CVE-2026-61794Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, the Tenant update validaMEDIUM6.8NVD2026-09-18
CVE-2026-61795Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, hostnameRegexHandler.OnUMEDIUM6.8NVD2026-09-18
CVE-2026-45726Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a stHIGH7.61%ileNVD2026-09-17
CVE-2026-50125MKP is a Model Context Protocol server for Kubernetes. Prior to 0.4.1, cmd/server/main.go exposes the default HTTP endpoHIGH7.535%ileNVD2026-09-17
CVE-2026-45720Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.0 until 1.7.3, SAML.HIGH7.02%ileNVD2026-09-17
CVE-2026-45723Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.CreatLOW2.732%ileNVD2026-09-17
CVE-2026-92568MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allowsMEDIUM5.322%ileNVD2026-09-16
CVE-2026-61549Woodpecker is a CI/CD engine. From 1.0.0 until 3.16.0, pipeline/backend/kubernetes/backend_options.go defines backend_opCRITICAL9.06%ileNVD2026-09-15
CVE-2026-44300OpenCost provides cost monitoring for Kubernetes workloads and cloud costs. Prior to 1.121.0, the POST /serviceKey endpoHIGH8.835%ileNVD2026-09-15
CVE-2026-55225Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. IHIGH8.09%ileNVD2026-09-15
CVE-2026-53941Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and LiMEDIUM6.932%ileNVD2026-09-15
CVE-2026-52724Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2MEDIUM5.816%ileNVD2026-09-15
CVE-2026-55636Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.6, charts/capsule/templatesMEDIUM5.720%ileNVD2026-09-15
CVE-2026-50166Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2MEDIUM5.58%ileNVD2026-09-15
CVE-2026-55226Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. IMEDIUM5.48%ileNVD2026-09-15
CVE-2026-59341A security vulnerability exists in the Sealed Secrets controller's unauthenticated POST endpoints. By submitting a modifMEDIUM4.224%ileNVD2026-09-15
CVE-2026-44778Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and LiLOW2.939%ileNVD2026-09-15
CVE-2026-53713Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gatewayCRITICAL9.135%ileNVD2026-09-14
CVE-2026-47701The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/otel-allocatoHIGH7.721%ileNVD2026-09-14
CVE-2026-53714Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gatewayHIGH7.421%ileNVD2026-09-14
CVE-2026-53717Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gatewayMEDIUM6.552%ileNVD2026-09-14
CVE-2026-53716Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gatewayMEDIUM6.551%ileNVD2026-09-14
CVE-2026-53719Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gatewayMEDIUM6.551%ileNVD2026-09-14
CVE-2026-53718Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gatewayMEDIUM6.426%ileNVD2026-09-14
CVE-2026-54246Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.27.13, the routesrv component serves cluMEDIUM5.727%ileNVD2026-09-14
CVE-2026-53715Envoy Gateway is an open source project for managing Envoy Proxy as a standalone or Kubernetes-based application gatewayMEDIUM5.330%ileNVD2026-09-14
CVE-2026-54247Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.22, Handler in dataclients/kubernetesMEDIUM4.314%ileNVD2026-09-14
CVE-2026-56855Prevent DoS on deadlocked established channel in golang.org/x/crypto/sshHIGH7.532%ileMicrosoft2026-09-08
CVE-2026-78662Prevent DoS on deadlocked undecided channel in golang.org/x/crypto/sshHIGH7.525%ileMicrosoft2026-09-08
CVE-2026-50516Microsoft Azure Kubernetes Service Elevation of Privilege VulnerabilityCRITICAL9.456%ileMicrosoft2026-08-11
CVE-2026-73499etcd: Watch API authorization bypass via open-ended range requestsUNKNOWN30%ileMicrosoft2026-08-11
CVE-2026-73500etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadlineUNKNOWN34%ileMicrosoft2026-08-11
CVE-2026-32193Azure Kubernetes Service (AKS) Remote Code Execution VulnerabilityHIGH8.827%ileMicrosoft2026-06-09
CVE-2026-10722cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer overflowLOW3.38%ileMicrosoft2026-06-09
CVE-2026-39821Invoking failure to reject ASCII-only Punycode-encoded labels in golang.org/x/net/idnaCRITICAL10.051%ileMicrosoft2026-05-12
CVE-2026-39830Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/sshCRITICAL9.148%ileMicrosoft2026-05-12
CVE-2026-39834Invoking infinite loop on large channel writes in golang.org/x/crypto/sshCRITICAL9.143%ileMicrosoft2026-05-12
CVE-2026-39831Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/sshCRITICAL9.136%ileMicrosoft2026-05-12
CVE-2026-33814Infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE in net/http/internal/http2 in golang.org/x/netHIGH7.554%ileMicrosoft2026-05-12
CVE-2026-39829Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/sshHIGH7.540%ileMicrosoft2026-05-12
CVE-2026-46597Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/sshHIGH7.540%ileMicrosoft2026-05-12
CVE-2026-25680Invoking denial of service when parsing arbitrary HTML in golang.org/x/net/htmlMEDIUM6.526%ileMicrosoft2026-05-12
CVE-2026-39827Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/sshMEDIUM6.521%ileMicrosoft2026-05-12
CVE-2026-39828Invoking bypass of certificate restrictions in golang.org/x/crypto/sshMEDIUM6.331%ileMicrosoft2026-05-12
CVE-2026-25681Invoking incorrect handling of character references in DOCTYPE nodes in golang.org/x/net/htmlMEDIUM6.113%ileMicrosoft2026-05-12
CVE-2026-27136Invoking duplicate attributes can cause XSS in golang.org/x/net/htmlMEDIUM6.113%ileMicrosoft2026-05-12
CVE-2026-42502Invoking incorrect handling of HTML elements in foreign content in golang.org/x/net/htmlMEDIUM6.113%ileMicrosoft2026-05-12
CVE-2026-42506Invoking incorrect handling of namespaced elements in foreign content in golang.org/x/net/htmlMEDIUM6.115%ileMicrosoft2026-05-12
CVE-2026-39835Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/sshMEDIUM5.342%ileMicrosoft2026-05-12
CVE-2026-39824Invoking integer overflow in NewNTUnicodeString in golang.org/x/sys/windowsLOW3.32%ileMicrosoft2026-05-12
CVE-2026-33105Microsoft Azure Kubernetes Service Elevation of Privilege VulnerabilityCRITICAL10.052%ileMicrosoft2026-04-14
CVE-2026-35469SpdyStream: DOS on CRIHIGH8.150%ileMicrosoft2026-04-14
CVE-2025-65637A denial-of-service vulnerability exists in github.com/sirupsen/logrus when using Entry.Writer() to log a single-line paMEDIUM5.949%ileMicrosoft2025-12-09
CVE-2025-13281Portworx Half-Blind SSRF in kube-controller-managerMEDIUM5.833%ileMicrosoft2025-12-09
CVE-2025-22869Potential denial of service in golang.org/x/cryptoHIGH7.559%ileMicrosoft2025-02-11
CVE-2025-0426A security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthenMEDIUM6.231%ileMicrosoft2025-02-11