k8s.io/kubernetes
Activity
- Latest release
- 2w ago
- Total releases
- 73
- Cadence
- ~19 days
- Last 12 months
- 26
Details
- First release
- Mar 11, 2015
| Version | Released | |
|---|---|---|
v1.37.0
minor
2 CVEs
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev |
v1.37.0
minor
Dependencies (112)
+ 104 more |
|
v1.35.8
patch
2 CVEs
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev |
v1.35.8
patch
Dependencies (111)
+ 103 more |
|
v1.36.4
patch
2 CVEs
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev |
v1.36.4
patch
Dependencies (110)
+ 102 more |
|
v1.37.0-rc.1
pre
2 CVEs
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev |
v1.37.0-rc.1
pre
Dependencies (112)
+ 104 more |
|
v1.37.0-rc.0
pre
2 CVEs
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev |
v1.37.0-rc.0
pre
Dependencies (112)
+ 104 more |
|
v1.38.0-alpha.0
pre
2 CVEs
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev |
v1.38.0-alpha.0
pre
Dependencies (112)
+ 104 more |
|
v1.36.3
patch
2 CVEs
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev |
v1.36.3
patch
Dependencies (110)
+ 102 more |
|
v1.35.7
patch
2 CVEs
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev |
v1.35.7
patch
Dependencies (111)
+ 103 more |
|
v1.34.10
minor
2 CVEs
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev |
v1.34.10
minor
Dependencies (112)
+ 104 more |
|
v1.37.0-beta.0
pre
2 CVEs
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev |
v1.37.0-beta.0
pre
Dependencies (112)
+ 104 more |
|
v1.37.0-alpha.3
pre
2 CVEs
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev |
v1.37.0-alpha.3
pre
Dependencies (110)
+ 102 more |
|
v1.37.0-alpha.2
pre
2 CVEs
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev |
v1.37.0-alpha.2
pre
Dependencies (110)
+ 102 more |
|
v1.36.2
patch
2 CVEs
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev |
v1.36.2
patch
Dependencies (110)
+ 102 more |
|
v1.35.6
patch
2 CVEs
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev |
v1.35.6
patch
Dependencies (111)
+ 103 more |
|
v1.37.0-alpha.1
pre
2 CVEs
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev |
v1.37.0-alpha.1
pre
Dependencies (110)
+ 102 more |
|
v1.36.1
patch
2 CVEs
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev |
v1.36.1
patch
Dependencies (110)
+ 102 more |
|
v1.35.5
minor
2 CVEs
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev |
v1.35.5
minor
Dependencies (111)
+ 103 more |
|
v1.36.0
minor
2 CVEs
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev |
v1.36.0
minor
Dependencies (110)
+ 102 more |
|
v1.36.0-rc.1
pre
2 CVEs
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev |
v1.36.0-rc.1
pre
Dependencies (110)
+ 102 more |
|
v1.36.0-rc.0
pre
2 CVEs
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev |
v1.36.0-rc.0
pre
Dependencies (110)
+ 102 more |
|
v1.37.0-alpha.0
pre
2 CVEs
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev |
v1.37.0-alpha.0
pre
Dependencies (110)
+ 102 more |
|
v1.36.0-beta.0
pre
2 CVEs
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev |
v1.36.0-beta.0
pre
Dependencies (110)
+ 102 more |
|
v1.36.0-alpha.2
pre
2 CVEs
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev |
v1.36.0-alpha.2
pre
Dependencies (108)
+ 100 more |
|
v1.36.0-alpha.1
pre
2 CVEs
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev |
v1.36.0-alpha.1
pre
Dependencies (108)
+ 100 more |
|
v1.36.0-alpha.0
pre
2 CVEs
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev |
v1.36.0-alpha.0
pre
Dependencies (111)
+ 103 more |
|
v1.35.0-alpha.2
pre
2 CVEs
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev |
v1.35.0-alpha.2
pre
Dependencies (111)
+ 103 more |
|
v1.34.0-alpha.1
pre
3 CVEs
CVE-2025-13281
GO-2025-4240
GHSA-r6j8-c6r2-37rr
Dec 16, 2025
Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Fixed in
1.32.10
1.33.6
1.34.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev |
v1.34.0-alpha.1
pre
Dependencies (109)
+ 101 more |
|
v1.30.0-rc.2
pre
5 CVEs
CVE-2025-13281
GO-2025-4240
GHSA-r6j8-c6r2-37rr
Dec 16, 2025
Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Fixed in
1.32.10
1.33.6
1.34.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5187
GO-2025-3915
GHSA-4x4m-3c2p-qppc
Sep 18, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Fixed in
1.31.12
1.32.8
1.33.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-9042
GO-2025-3522
GHSA-vv39-3w5q-974q
Mar 25, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Fixed in
1.29.13
1.30.9
1.31.5
1.32.1
References
Updated Feb 04, 2026 · Source: OSV.dev |
v1.30.0-rc.2
pre
Dependencies (114)
+ 106 more |
|
v1.29.0-alpha.1
pre
6 CVEs
CVE-2025-13281
GO-2025-4240
GHSA-r6j8-c6r2-37rr
Dec 16, 2025
Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Fixed in
1.32.10
1.33.6
1.34.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5187
GO-2025-3915
GHSA-4x4m-3c2p-qppc
Sep 18, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Fixed in
1.31.12
1.32.8
1.33.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-9042
GO-2025-3522
GHSA-vv39-3w5q-974q
Mar 25, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Fixed in
1.29.13
1.30.9
1.31.5
1.32.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-0426
GO-2025-3465
GHSA-jgfp-53c3-624w
Mar 03, 2025
Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Fixed in
1.29.14
1.30.10
1.31.6
1.32.2
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.29.0-alpha.1
pre
Dependencies (120)
+ 112 more |
|
v1.24.16
patch
14 CVEs
CVE-2025-13281
GO-2025-4240
GHSA-r6j8-c6r2-37rr
Dec 16, 2025
Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Fixed in
1.32.10
1.33.6
1.34.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5187
GO-2025-3915
GHSA-4x4m-3c2p-qppc
Sep 18, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Fixed in
1.31.12
1.32.8
1.33.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-9042
GO-2025-3522
GHSA-vv39-3w5q-974q
Mar 25, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Fixed in
1.29.13
1.30.9
1.31.5
1.32.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-0426
GO-2025-3465
GHSA-jgfp-53c3-624w
Mar 03, 2025
Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Fixed in
1.29.14
1.30.10
1.31.6
1.32.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10220
GO-2024-3286
GHSA-27wf-5967-98gx
Nov 27, 2024
Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Fixed in
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-0793
GO-2024-3277
GHSA-h7wq-jj8r-qm7p
Nov 19, 2024
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Fixed in
1.27.0-alpha.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25743
GO-2022-0983
GHSA-f9jg-8p32-2f55
Aug 21, 2024
ANSI escape characters not filtered in kubectl in k8s.io/kubernetes ANSI escape characters not filtered in kubectl in k8s.io/kubernetes Fixed in
1.26.0-alpha.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5528
GO-2023-2341
GHSA-hq6q-c2x6-hmch
Aug 21, 2024
Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Fixed in
1.25.16
1.26.11
1.27.8
1.28.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3955
GO-2023-2170
GHSA-q78c-gwqw-jcmc
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes and k8s.io/mount-utils A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3676
GO-2023-2330
GHSA-7fxm-f474-hf8w
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5321
GO-2024-2994
GHSA-82m2-cv7p-4m75
Jul 22, 2024
Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Fixed in
1.27.16
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-3177
GO-2024-2746
GHSA-pxhw-596r-rwq5
Jun 04, 2024
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Fixed in
1.27.13
1.28.9
1.29.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.24.16
patch
Dependencies (118)
+ 110 more |
|
v1.22.18-rc.0
pre
17 CVEs
CVE-2025-13281
GO-2025-4240
GHSA-r6j8-c6r2-37rr
Dec 16, 2025
Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Fixed in
1.32.10
1.33.6
1.34.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5187
GO-2025-3915
GHSA-4x4m-3c2p-qppc
Sep 18, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Fixed in
1.31.12
1.32.8
1.33.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-9042
GO-2025-3522
GHSA-vv39-3w5q-974q
Mar 25, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Fixed in
1.29.13
1.30.9
1.31.5
1.32.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-0426
GO-2025-3465
GHSA-jgfp-53c3-624w
Mar 03, 2025
Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Fixed in
1.29.14
1.30.10
1.31.6
1.32.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10220
GO-2024-3286
GHSA-27wf-5967-98gx
Nov 27, 2024
Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Fixed in
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-0793
GO-2024-3277
GHSA-h7wq-jj8r-qm7p
Nov 19, 2024
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Fixed in
1.27.0-alpha.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25743
GO-2022-0983
GHSA-f9jg-8p32-2f55
Aug 21, 2024
ANSI escape characters not filtered in kubectl in k8s.io/kubernetes ANSI escape characters not filtered in kubectl in k8s.io/kubernetes Fixed in
1.26.0-alpha.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5528
GO-2023-2341
GHSA-hq6q-c2x6-hmch
Aug 21, 2024
Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Fixed in
1.25.16
1.26.11
1.27.8
1.28.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3955
GO-2023-2170
GHSA-q78c-gwqw-jcmc
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes and k8s.io/mount-utils A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3676
GO-2023-2330
GHSA-7fxm-f474-hf8w
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2431
GO-2023-1864
GHSA-xc8m-28vv-4pjc
Aug 20, 2024
Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Fixed in
1.24.14
1.25.10
1.26.5
1.27.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2728
GO-2023-1892
GHSA-cgcv-5272-97pr
Aug 20, 2024
Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2727
GO-2023-1891
GHSA-qc2g-gmh6-95p4
Aug 20, 2024
Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5321
GO-2024-2994
GHSA-82m2-cv7p-4m75
Jul 22, 2024
Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Fixed in
1.27.16
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-3177
GO-2024-2746
GHSA-pxhw-596r-rwq5
Jun 04, 2024
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Fixed in
1.27.13
1.28.9
1.29.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.22.18-rc.0
pre
Dependencies (119)
+ 111 more |
|
v1.24.8
minor
17 CVEs
CVE-2025-13281
GO-2025-4240
GHSA-r6j8-c6r2-37rr
Dec 16, 2025
Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Fixed in
1.32.10
1.33.6
1.34.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5187
GO-2025-3915
GHSA-4x4m-3c2p-qppc
Sep 18, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Fixed in
1.31.12
1.32.8
1.33.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-9042
GO-2025-3522
GHSA-vv39-3w5q-974q
Mar 25, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Fixed in
1.29.13
1.30.9
1.31.5
1.32.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-0426
GO-2025-3465
GHSA-jgfp-53c3-624w
Mar 03, 2025
Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Fixed in
1.29.14
1.30.10
1.31.6
1.32.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10220
GO-2024-3286
GHSA-27wf-5967-98gx
Nov 27, 2024
Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Fixed in
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-0793
GO-2024-3277
GHSA-h7wq-jj8r-qm7p
Nov 19, 2024
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Fixed in
1.27.0-alpha.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25743
GO-2022-0983
GHSA-f9jg-8p32-2f55
Aug 21, 2024
ANSI escape characters not filtered in kubectl in k8s.io/kubernetes ANSI escape characters not filtered in kubectl in k8s.io/kubernetes Fixed in
1.26.0-alpha.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5528
GO-2023-2341
GHSA-hq6q-c2x6-hmch
Aug 21, 2024
Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Fixed in
1.25.16
1.26.11
1.27.8
1.28.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3955
GO-2023-2170
GHSA-q78c-gwqw-jcmc
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes and k8s.io/mount-utils A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3676
GO-2023-2330
GHSA-7fxm-f474-hf8w
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2431
GO-2023-1864
GHSA-xc8m-28vv-4pjc
Aug 20, 2024
Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Fixed in
1.24.14
1.25.10
1.26.5
1.27.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2728
GO-2023-1892
GHSA-cgcv-5272-97pr
Aug 20, 2024
Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2727
GO-2023-1891
GHSA-qc2g-gmh6-95p4
Aug 20, 2024
Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5321
GO-2024-2994
GHSA-82m2-cv7p-4m75
Jul 22, 2024
Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Fixed in
1.27.16
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-3177
GO-2024-2746
GHSA-pxhw-596r-rwq5
Jun 04, 2024
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Fixed in
1.27.13
1.28.9
1.29.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.24.8
minor
Dependencies (118)
+ 110 more |
|
v1.26.0-alpha.3
pre
10 CVEs
CVE-2025-13281
GO-2025-4240
GHSA-r6j8-c6r2-37rr
Dec 16, 2025
Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Fixed in
1.32.10
1.33.6
1.34.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5187
GO-2025-3915
GHSA-4x4m-3c2p-qppc
Sep 18, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Fixed in
1.31.12
1.32.8
1.33.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-9042
GO-2025-3522
GHSA-vv39-3w5q-974q
Mar 25, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Fixed in
1.29.13
1.30.9
1.31.5
1.32.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-0426
GO-2025-3465
GHSA-jgfp-53c3-624w
Mar 03, 2025
Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Fixed in
1.29.14
1.30.10
1.31.6
1.32.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10220
GO-2024-3286
GHSA-27wf-5967-98gx
Nov 27, 2024
Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Fixed in
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-0793
GO-2024-3277
GHSA-h7wq-jj8r-qm7p
Nov 19, 2024
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Fixed in
1.27.0-alpha.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5321
GO-2024-2994
GHSA-82m2-cv7p-4m75
Jul 22, 2024
Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Fixed in
1.27.16
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-3177
GO-2024-2746
GHSA-pxhw-596r-rwq5
Jun 04, 2024
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Fixed in
1.27.13
1.28.9
1.29.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.26.0-alpha.3
pre
Dependencies (117)
+ 109 more |
|
v1.23.10
patch
19 CVEs
CVE-2025-13281
GO-2025-4240
GHSA-r6j8-c6r2-37rr
Dec 16, 2025
Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Fixed in
1.32.10
1.33.6
1.34.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5187
GO-2025-3915
GHSA-4x4m-3c2p-qppc
Sep 18, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Fixed in
1.31.12
1.32.8
1.33.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-9042
GO-2025-3522
GHSA-vv39-3w5q-974q
Mar 25, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Fixed in
1.29.13
1.30.9
1.31.5
1.32.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-0426
GO-2025-3465
GHSA-jgfp-53c3-624w
Mar 03, 2025
Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Fixed in
1.29.14
1.30.10
1.31.6
1.32.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10220
GO-2024-3286
GHSA-27wf-5967-98gx
Nov 27, 2024
Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Fixed in
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-0793
GO-2024-3277
GHSA-h7wq-jj8r-qm7p
Nov 19, 2024
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Fixed in
1.27.0-alpha.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25743
GO-2022-0983
GHSA-f9jg-8p32-2f55
Aug 21, 2024
ANSI escape characters not filtered in kubectl in k8s.io/kubernetes ANSI escape characters not filtered in kubectl in k8s.io/kubernetes Fixed in
1.26.0-alpha.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5528
GO-2023-2341
GHSA-hq6q-c2x6-hmch
Aug 21, 2024
Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Fixed in
1.25.16
1.26.11
1.27.8
1.28.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3955
GO-2023-2170
GHSA-q78c-gwqw-jcmc
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes and k8s.io/mount-utils A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3676
GO-2023-2330
GHSA-7fxm-f474-hf8w
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2431
GO-2023-1864
GHSA-xc8m-28vv-4pjc
Aug 20, 2024
Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Fixed in
1.24.14
1.25.10
1.26.5
1.27.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2728
GO-2023-1892
GHSA-cgcv-5272-97pr
Aug 20, 2024
Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2727
GO-2023-1891
GHSA-qc2g-gmh6-95p4
Aug 20, 2024
Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-3294
GO-2023-1629
GHSA-jh36-q97c-9928
Aug 20, 2024
Kubernetes vulnerable to validation bypass in k8s.io/kubernetes Kubernetes vulnerable to validation bypass in k8s.io/kubernetes Fixed in
1.22.16
1.23.14
1.24.8
1.25.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-3162
GO-2023-1628
GHSA-2394-5535-8j88
Aug 20, 2024
Kubernetes vulnerable to path traversal in k8s.io/kubernetes Kubernetes vulnerable to path traversal in k8s.io/kubernetes Fixed in
1.22.16
1.23.14
1.24.8
1.25.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-5321
GO-2024-2994
GHSA-82m2-cv7p-4m75
Jul 22, 2024
Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Fixed in
1.27.16
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-3177
GO-2024-2746
GHSA-pxhw-596r-rwq5
Jun 04, 2024
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Fixed in
1.27.13
1.28.9
1.29.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.23.10
patch
Dependencies (118)
+ 110 more |
|
v1.25.0-rc.1
pre
12 CVEs
CVE-2025-13281
GO-2025-4240
GHSA-r6j8-c6r2-37rr
Dec 16, 2025
Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Fixed in
1.32.10
1.33.6
1.34.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5187
GO-2025-3915
GHSA-4x4m-3c2p-qppc
Sep 18, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Fixed in
1.31.12
1.32.8
1.33.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-9042
GO-2025-3522
GHSA-vv39-3w5q-974q
Mar 25, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Fixed in
1.29.13
1.30.9
1.31.5
1.32.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-0426
GO-2025-3465
GHSA-jgfp-53c3-624w
Mar 03, 2025
Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Fixed in
1.29.14
1.30.10
1.31.6
1.32.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10220
GO-2024-3286
GHSA-27wf-5967-98gx
Nov 27, 2024
Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Fixed in
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-0793
GO-2024-3277
GHSA-h7wq-jj8r-qm7p
Nov 19, 2024
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Fixed in
1.27.0-alpha.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25743
GO-2022-0983
GHSA-f9jg-8p32-2f55
Aug 21, 2024
ANSI escape characters not filtered in kubectl in k8s.io/kubernetes ANSI escape characters not filtered in kubectl in k8s.io/kubernetes Fixed in
1.26.0-alpha.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5528
GO-2023-2341
GHSA-hq6q-c2x6-hmch
Aug 21, 2024
Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Fixed in
1.25.16
1.26.11
1.27.8
1.28.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5321
GO-2024-2994
GHSA-82m2-cv7p-4m75
Jul 22, 2024
Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Fixed in
1.27.16
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-3177
GO-2024-2746
GHSA-pxhw-596r-rwq5
Jun 04, 2024
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Fixed in
1.27.13
1.28.9
1.29.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.25.0-rc.1
pre
Dependencies (119)
+ 111 more |
|
v1.21.13
minor
20 CVEs
CVE-2025-13281
GO-2025-4240
GHSA-r6j8-c6r2-37rr
Dec 16, 2025
Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Fixed in
1.32.10
1.33.6
1.34.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5187
GO-2025-3915
GHSA-4x4m-3c2p-qppc
Sep 18, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Fixed in
1.31.12
1.32.8
1.33.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-9042
GO-2025-3522
GHSA-vv39-3w5q-974q
Mar 25, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Fixed in
1.29.13
1.30.9
1.31.5
1.32.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-0426
GO-2025-3465
GHSA-jgfp-53c3-624w
Mar 03, 2025
Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Fixed in
1.29.14
1.30.10
1.31.6
1.32.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10220
GO-2024-3286
GHSA-27wf-5967-98gx
Nov 27, 2024
Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Fixed in
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-0793
GO-2024-3277
GHSA-h7wq-jj8r-qm7p
Nov 19, 2024
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Fixed in
1.27.0-alpha.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25743
GO-2022-0983
GHSA-f9jg-8p32-2f55
Aug 21, 2024
ANSI escape characters not filtered in kubectl in k8s.io/kubernetes ANSI escape characters not filtered in kubectl in k8s.io/kubernetes Fixed in
1.26.0-alpha.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5528
GO-2023-2341
GHSA-hq6q-c2x6-hmch
Aug 21, 2024
Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Fixed in
1.25.16
1.26.11
1.27.8
1.28.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3955
GO-2023-2170
GHSA-q78c-gwqw-jcmc
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes and k8s.io/mount-utils A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3676
GO-2023-2330
GHSA-7fxm-f474-hf8w
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2431
GO-2023-1864
GHSA-xc8m-28vv-4pjc
Aug 20, 2024
Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Fixed in
1.24.14
1.25.10
1.26.5
1.27.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2728
GO-2023-1892
GHSA-cgcv-5272-97pr
Aug 20, 2024
Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2727
GO-2023-1891
GHSA-qc2g-gmh6-95p4
Aug 20, 2024
Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5321
GO-2024-2994
GHSA-82m2-cv7p-4m75
Jul 22, 2024
Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Fixed in
1.27.16
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-3177
GO-2024-2746
GHSA-pxhw-596r-rwq5
Jun 04, 2024
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Fixed in
1.27.13
1.28.9
1.29.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8554
GHSA-j9wf-vvm6-4r9w
Feb 08, 2022
Unverified Ownership in Kubernetes
5.0
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
Low
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-25740
GHSA-vw47-mr44-3jf9
Sep 21, 2021
Confused Deputy in Kubernetes
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8561
GHSA-74j8-88mm-7496
Sep 21, 2021
Confused Deputy in Kubernetes
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs. References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.21.13
minor
Dependencies (120)
+ 112 more |
|
v1.23.6
minor
19 CVEs
CVE-2025-13281
GO-2025-4240
GHSA-r6j8-c6r2-37rr
Dec 16, 2025
Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Fixed in
1.32.10
1.33.6
1.34.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5187
GO-2025-3915
GHSA-4x4m-3c2p-qppc
Sep 18, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Fixed in
1.31.12
1.32.8
1.33.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-9042
GO-2025-3522
GHSA-vv39-3w5q-974q
Mar 25, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Fixed in
1.29.13
1.30.9
1.31.5
1.32.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-0426
GO-2025-3465
GHSA-jgfp-53c3-624w
Mar 03, 2025
Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Fixed in
1.29.14
1.30.10
1.31.6
1.32.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10220
GO-2024-3286
GHSA-27wf-5967-98gx
Nov 27, 2024
Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Fixed in
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-0793
GO-2024-3277
GHSA-h7wq-jj8r-qm7p
Nov 19, 2024
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Fixed in
1.27.0-alpha.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25743
GO-2022-0983
GHSA-f9jg-8p32-2f55
Aug 21, 2024
ANSI escape characters not filtered in kubectl in k8s.io/kubernetes ANSI escape characters not filtered in kubectl in k8s.io/kubernetes Fixed in
1.26.0-alpha.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5528
GO-2023-2341
GHSA-hq6q-c2x6-hmch
Aug 21, 2024
Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Fixed in
1.25.16
1.26.11
1.27.8
1.28.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3955
GO-2023-2170
GHSA-q78c-gwqw-jcmc
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes and k8s.io/mount-utils A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3676
GO-2023-2330
GHSA-7fxm-f474-hf8w
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2431
GO-2023-1864
GHSA-xc8m-28vv-4pjc
Aug 20, 2024
Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Fixed in
1.24.14
1.25.10
1.26.5
1.27.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2728
GO-2023-1892
GHSA-cgcv-5272-97pr
Aug 20, 2024
Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2727
GO-2023-1891
GHSA-qc2g-gmh6-95p4
Aug 20, 2024
Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-3294
GO-2023-1629
GHSA-jh36-q97c-9928
Aug 20, 2024
Kubernetes vulnerable to validation bypass in k8s.io/kubernetes Kubernetes vulnerable to validation bypass in k8s.io/kubernetes Fixed in
1.22.16
1.23.14
1.24.8
1.25.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-3162
GO-2023-1628
GHSA-2394-5535-8j88
Aug 20, 2024
Kubernetes vulnerable to path traversal in k8s.io/kubernetes Kubernetes vulnerable to path traversal in k8s.io/kubernetes Fixed in
1.22.16
1.23.14
1.24.8
1.25.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-5321
GO-2024-2994
GHSA-82m2-cv7p-4m75
Jul 22, 2024
Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Fixed in
1.27.16
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-3177
GO-2024-2746
GHSA-pxhw-596r-rwq5
Jun 04, 2024
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Fixed in
1.27.13
1.28.9
1.29.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.23.6
minor
Dependencies (118)
+ 110 more |
|
v1.22.8
patch
19 CVEs
CVE-2025-13281
GO-2025-4240
GHSA-r6j8-c6r2-37rr
Dec 16, 2025
Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Fixed in
1.32.10
1.33.6
1.34.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5187
GO-2025-3915
GHSA-4x4m-3c2p-qppc
Sep 18, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Fixed in
1.31.12
1.32.8
1.33.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-9042
GO-2025-3522
GHSA-vv39-3w5q-974q
Mar 25, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Fixed in
1.29.13
1.30.9
1.31.5
1.32.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-0426
GO-2025-3465
GHSA-jgfp-53c3-624w
Mar 03, 2025
Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Fixed in
1.29.14
1.30.10
1.31.6
1.32.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10220
GO-2024-3286
GHSA-27wf-5967-98gx
Nov 27, 2024
Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Fixed in
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-0793
GO-2024-3277
GHSA-h7wq-jj8r-qm7p
Nov 19, 2024
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Fixed in
1.27.0-alpha.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25743
GO-2022-0983
GHSA-f9jg-8p32-2f55
Aug 21, 2024
ANSI escape characters not filtered in kubectl in k8s.io/kubernetes ANSI escape characters not filtered in kubectl in k8s.io/kubernetes Fixed in
1.26.0-alpha.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5528
GO-2023-2341
GHSA-hq6q-c2x6-hmch
Aug 21, 2024
Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Fixed in
1.25.16
1.26.11
1.27.8
1.28.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3955
GO-2023-2170
GHSA-q78c-gwqw-jcmc
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes and k8s.io/mount-utils A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3676
GO-2023-2330
GHSA-7fxm-f474-hf8w
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2431
GO-2023-1864
GHSA-xc8m-28vv-4pjc
Aug 20, 2024
Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Fixed in
1.24.14
1.25.10
1.26.5
1.27.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2728
GO-2023-1892
GHSA-cgcv-5272-97pr
Aug 20, 2024
Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2727
GO-2023-1891
GHSA-qc2g-gmh6-95p4
Aug 20, 2024
Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-3294
GO-2023-1629
GHSA-jh36-q97c-9928
Aug 20, 2024
Kubernetes vulnerable to validation bypass in k8s.io/kubernetes Kubernetes vulnerable to validation bypass in k8s.io/kubernetes Fixed in
1.22.16
1.23.14
1.24.8
1.25.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-3162
GO-2023-1628
GHSA-2394-5535-8j88
Aug 20, 2024
Kubernetes vulnerable to path traversal in k8s.io/kubernetes Kubernetes vulnerable to path traversal in k8s.io/kubernetes Fixed in
1.22.16
1.23.14
1.24.8
1.25.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-5321
GO-2024-2994
GHSA-82m2-cv7p-4m75
Jul 22, 2024
Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Fixed in
1.27.16
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-3177
GO-2024-2746
GHSA-pxhw-596r-rwq5
Jun 04, 2024
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Fixed in
1.27.13
1.28.9
1.29.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.22.8
patch
Dependencies (119)
+ 111 more |
|
v1.21.11-rc.0
pre
20 CVEs
CVE-2025-13281
GO-2025-4240
GHSA-r6j8-c6r2-37rr
Dec 16, 2025
Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Fixed in
1.32.10
1.33.6
1.34.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5187
GO-2025-3915
GHSA-4x4m-3c2p-qppc
Sep 18, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Fixed in
1.31.12
1.32.8
1.33.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-9042
GO-2025-3522
GHSA-vv39-3w5q-974q
Mar 25, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Fixed in
1.29.13
1.30.9
1.31.5
1.32.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-0426
GO-2025-3465
GHSA-jgfp-53c3-624w
Mar 03, 2025
Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Fixed in
1.29.14
1.30.10
1.31.6
1.32.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10220
GO-2024-3286
GHSA-27wf-5967-98gx
Nov 27, 2024
Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Fixed in
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-0793
GO-2024-3277
GHSA-h7wq-jj8r-qm7p
Nov 19, 2024
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Fixed in
1.27.0-alpha.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25743
GO-2022-0983
GHSA-f9jg-8p32-2f55
Aug 21, 2024
ANSI escape characters not filtered in kubectl in k8s.io/kubernetes ANSI escape characters not filtered in kubectl in k8s.io/kubernetes Fixed in
1.26.0-alpha.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5528
GO-2023-2341
GHSA-hq6q-c2x6-hmch
Aug 21, 2024
Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Fixed in
1.25.16
1.26.11
1.27.8
1.28.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3955
GO-2023-2170
GHSA-q78c-gwqw-jcmc
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes and k8s.io/mount-utils A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3676
GO-2023-2330
GHSA-7fxm-f474-hf8w
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2431
GO-2023-1864
GHSA-xc8m-28vv-4pjc
Aug 20, 2024
Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Fixed in
1.24.14
1.25.10
1.26.5
1.27.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2728
GO-2023-1892
GHSA-cgcv-5272-97pr
Aug 20, 2024
Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2727
GO-2023-1891
GHSA-qc2g-gmh6-95p4
Aug 20, 2024
Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5321
GO-2024-2994
GHSA-82m2-cv7p-4m75
Jul 22, 2024
Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Fixed in
1.27.16
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-3177
GO-2024-2746
GHSA-pxhw-596r-rwq5
Jun 04, 2024
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Fixed in
1.27.13
1.28.9
1.29.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8554
GHSA-j9wf-vvm6-4r9w
Feb 08, 2022
Unverified Ownership in Kubernetes
5.0
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
Low
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-25740
GHSA-vw47-mr44-3jf9
Sep 21, 2021
Confused Deputy in Kubernetes
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8561
GHSA-74j8-88mm-7496
Sep 21, 2021
Confused Deputy in Kubernetes
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs. References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.21.11-rc.0
pre
Dependencies (120)
+ 112 more |
|
v1.22.6
minor
19 CVEs
CVE-2025-13281
GO-2025-4240
GHSA-r6j8-c6r2-37rr
Dec 16, 2025
Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Fixed in
1.32.10
1.33.6
1.34.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5187
GO-2025-3915
GHSA-4x4m-3c2p-qppc
Sep 18, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Fixed in
1.31.12
1.32.8
1.33.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-9042
GO-2025-3522
GHSA-vv39-3w5q-974q
Mar 25, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Fixed in
1.29.13
1.30.9
1.31.5
1.32.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-0426
GO-2025-3465
GHSA-jgfp-53c3-624w
Mar 03, 2025
Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Fixed in
1.29.14
1.30.10
1.31.6
1.32.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10220
GO-2024-3286
GHSA-27wf-5967-98gx
Nov 27, 2024
Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Fixed in
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-0793
GO-2024-3277
GHSA-h7wq-jj8r-qm7p
Nov 19, 2024
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Fixed in
1.27.0-alpha.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25743
GO-2022-0983
GHSA-f9jg-8p32-2f55
Aug 21, 2024
ANSI escape characters not filtered in kubectl in k8s.io/kubernetes ANSI escape characters not filtered in kubectl in k8s.io/kubernetes Fixed in
1.26.0-alpha.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5528
GO-2023-2341
GHSA-hq6q-c2x6-hmch
Aug 21, 2024
Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Fixed in
1.25.16
1.26.11
1.27.8
1.28.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3955
GO-2023-2170
GHSA-q78c-gwqw-jcmc
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes and k8s.io/mount-utils A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3676
GO-2023-2330
GHSA-7fxm-f474-hf8w
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2431
GO-2023-1864
GHSA-xc8m-28vv-4pjc
Aug 20, 2024
Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Fixed in
1.24.14
1.25.10
1.26.5
1.27.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2728
GO-2023-1892
GHSA-cgcv-5272-97pr
Aug 20, 2024
Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2727
GO-2023-1891
GHSA-qc2g-gmh6-95p4
Aug 20, 2024
Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-3294
GO-2023-1629
GHSA-jh36-q97c-9928
Aug 20, 2024
Kubernetes vulnerable to validation bypass in k8s.io/kubernetes Kubernetes vulnerable to validation bypass in k8s.io/kubernetes Fixed in
1.22.16
1.23.14
1.24.8
1.25.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-3162
GO-2023-1628
GHSA-2394-5535-8j88
Aug 20, 2024
Kubernetes vulnerable to path traversal in k8s.io/kubernetes Kubernetes vulnerable to path traversal in k8s.io/kubernetes Fixed in
1.22.16
1.23.14
1.24.8
1.25.4
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-5321
GO-2024-2994
GHSA-82m2-cv7p-4m75
Jul 22, 2024
Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Fixed in
1.27.16
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-3177
GO-2024-2746
GHSA-pxhw-596r-rwq5
Jun 04, 2024
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Fixed in
1.27.13
1.28.9
1.29.4
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.22.6
minor
Dependencies (119)
+ 111 more |
|
v1.21.6-rc.0
pre
20 CVEs
CVE-2025-13281
GO-2025-4240
GHSA-r6j8-c6r2-37rr
Dec 16, 2025
Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Fixed in
1.32.10
1.33.6
1.34.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5187
GO-2025-3915
GHSA-4x4m-3c2p-qppc
Sep 18, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Fixed in
1.31.12
1.32.8
1.33.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-9042
GO-2025-3522
GHSA-vv39-3w5q-974q
Mar 25, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Fixed in
1.29.13
1.30.9
1.31.5
1.32.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-0426
GO-2025-3465
GHSA-jgfp-53c3-624w
Mar 03, 2025
Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Fixed in
1.29.14
1.30.10
1.31.6
1.32.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10220
GO-2024-3286
GHSA-27wf-5967-98gx
Nov 27, 2024
Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Fixed in
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-0793
GO-2024-3277
GHSA-h7wq-jj8r-qm7p
Nov 19, 2024
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Fixed in
1.27.0-alpha.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25743
GO-2022-0983
GHSA-f9jg-8p32-2f55
Aug 21, 2024
ANSI escape characters not filtered in kubectl in k8s.io/kubernetes ANSI escape characters not filtered in kubectl in k8s.io/kubernetes Fixed in
1.26.0-alpha.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5528
GO-2023-2341
GHSA-hq6q-c2x6-hmch
Aug 21, 2024
Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Fixed in
1.25.16
1.26.11
1.27.8
1.28.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3955
GO-2023-2170
GHSA-q78c-gwqw-jcmc
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes and k8s.io/mount-utils A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3676
GO-2023-2330
GHSA-7fxm-f474-hf8w
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2431
GO-2023-1864
GHSA-xc8m-28vv-4pjc
Aug 20, 2024
Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Fixed in
1.24.14
1.25.10
1.26.5
1.27.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2728
GO-2023-1892
GHSA-cgcv-5272-97pr
Aug 20, 2024
Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2727
GO-2023-1891
GHSA-qc2g-gmh6-95p4
Aug 20, 2024
Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5321
GO-2024-2994
GHSA-82m2-cv7p-4m75
Jul 22, 2024
Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Fixed in
1.27.16
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-3177
GO-2024-2746
GHSA-pxhw-596r-rwq5
Jun 04, 2024
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Fixed in
1.27.13
1.28.9
1.29.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8554
GHSA-j9wf-vvm6-4r9w
Feb 08, 2022
Unverified Ownership in Kubernetes
5.0
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
Low
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-25740
GHSA-vw47-mr44-3jf9
Sep 21, 2021
Confused Deputy in Kubernetes
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8561
GHSA-74j8-88mm-7496
Sep 21, 2021
Confused Deputy in Kubernetes
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs. References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.21.6-rc.0
pre
Dependencies (120)
+ 112 more |
|
v1.19.6-rc.1
pre
27 CVEs
CVE-2025-13281
GO-2025-4240
GHSA-r6j8-c6r2-37rr
Dec 16, 2025
Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Fixed in
1.32.10
1.33.6
1.34.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5187
GO-2025-3915
GHSA-4x4m-3c2p-qppc
Sep 18, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Fixed in
1.31.12
1.32.8
1.33.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-9042
GO-2025-3522
GHSA-vv39-3w5q-974q
Mar 25, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Fixed in
1.29.13
1.30.9
1.31.5
1.32.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-0426
GO-2025-3465
GHSA-jgfp-53c3-624w
Mar 03, 2025
Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Fixed in
1.29.14
1.30.10
1.31.6
1.32.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10220
GO-2024-3286
GHSA-27wf-5967-98gx
Nov 27, 2024
Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Fixed in
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-0793
GO-2024-3277
GHSA-h7wq-jj8r-qm7p
Nov 19, 2024
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Fixed in
1.27.0-alpha.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25743
GO-2022-0983
GHSA-f9jg-8p32-2f55
Aug 21, 2024
ANSI escape characters not filtered in kubectl in k8s.io/kubernetes ANSI escape characters not filtered in kubectl in k8s.io/kubernetes Fixed in
1.26.0-alpha.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25735
GO-2022-0907
GHSA-g42g-737j-qx6j
Aug 21, 2024
Access Restriction Bypass in kube-apiserver in k8s.io/kubernetes Access Restriction Bypass in kube-apiserver in k8s.io/kubernetes Fixed in
1.18.18
1.19.10
1.20.6
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25741
GO-2022-0910
GHSA-f5f7-6478-qm6p
Aug 21, 2024
Files or Directories Accessible to External Parties in kubernetes in k8s.io/kubernetes Files or Directories Accessible to External Parties in kubernetes in k8s.io/kubernetes Fixed in
1.19.15
1.20.11
1.21.5
1.22.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25737
GO-2022-0908
GHSA-mfv7-gq43-w965
Aug 21, 2024
Incomplete List of Disallowed Inputs in Kubernetes in k8s.io/kubernetes Incomplete List of Disallowed Inputs in Kubernetes in k8s.io/kubernetes Fixed in
1.18.19
1.19.11
1.20.7
1.21.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-5528
GO-2023-2341
GHSA-hq6q-c2x6-hmch
Aug 21, 2024
Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Fixed in
1.25.16
1.26.11
1.27.8
1.28.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25736
GO-2023-2159
GHSA-35c7-w35f-xwgh
Aug 21, 2024
Kube-proxy may unintentionally forward traffic in k8s.io/kubernetes Kube-proxy may unintentionally forward traffic in k8s.io/kubernetes Fixed in
1.21.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3955
GO-2023-2170
GHSA-q78c-gwqw-jcmc
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes and k8s.io/mount-utils A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3676
GO-2023-2330
GHSA-7fxm-f474-hf8w
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2431
GO-2023-1864
GHSA-xc8m-28vv-4pjc
Aug 20, 2024
Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Fixed in
1.24.14
1.25.10
1.26.5
1.27.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2728
GO-2023-1892
GHSA-cgcv-5272-97pr
Aug 20, 2024
Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2727
GO-2023-1891
GHSA-qc2g-gmh6-95p4
Aug 20, 2024
Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5321
GO-2024-2994
GHSA-82m2-cv7p-4m75
Jul 22, 2024
Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Fixed in
1.27.16
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-3177
GO-2024-2746
GHSA-pxhw-596r-rwq5
Jun 04, 2024
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Fixed in
1.27.13
1.28.9
1.29.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8565
GHSA-8cfg-vx93-jvxw
GO-2021-0064
Feb 06, 2023
Kubernetes client-go vulnerable to Sensitive Information Leak via Log File
4.7
/ 10
Medium
Local
High
Low
None
Unchanged
High
None
None
In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.5, <= v1.18.13, <= v1.17.15, < v1.20.0-alpha2. Fixed in
1.20.0-alpha.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8564
GHSA-8mjg-8c8g-6h85
GO-2021-0066
Feb 06, 2023
Kubernetes Sensitive Information leak via Log File
4.7
/ 10
Medium
Local
High
Low
None
Unchanged
High
None
None
In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19.3, < v1.18.10, < v1.17.13. Fixed in
1.20.0-alpha.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8554
GHSA-j9wf-vvm6-4r9w
Feb 08, 2022
Unverified Ownership in Kubernetes
5.0
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
Low
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8562
GHSA-qh36-44jv-c8xj
Feb 02, 2022
Potential proxy IP restriction bypass in Kubernetes
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Services, Pods, Nodes, or StorageClass service providers. As part of this mitigation Kubernetes does a DNS name resolution check and validates that response IPs are not in the link-local (169.254.0.0/16) or localhost (127.0.0.0/8) range. Kubernetes then performs a second DNS resolution without validation for the actual connection. If a non-standard DNS server returns different non-cached responses, a user may be able to bypass the proxy IP restriction and access private networks on the control plane. All versions of Kubernetes are impacted, and there is no fix in place. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-25740
GHSA-vw47-mr44-3jf9
Sep 21, 2021
Confused Deputy in Kubernetes
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8561
GHSA-74j8-88mm-7496
Sep 21, 2021
Confused Deputy in Kubernetes
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs. References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.19.6-rc.1
pre
Dependencies (119)
+ 111 more |
|
v1.18.7
minor
29 CVEs
CVE-2025-13281
GO-2025-4240
GHSA-r6j8-c6r2-37rr
Dec 16, 2025
Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Fixed in
1.32.10
1.33.6
1.34.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5187
GO-2025-3915
GHSA-4x4m-3c2p-qppc
Sep 18, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Fixed in
1.31.12
1.32.8
1.33.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-9042
GO-2025-3522
GHSA-vv39-3w5q-974q
Mar 25, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Fixed in
1.29.13
1.30.9
1.31.5
1.32.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-0426
GO-2025-3465
GHSA-jgfp-53c3-624w
Mar 03, 2025
Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Fixed in
1.29.14
1.30.10
1.31.6
1.32.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10220
GO-2024-3286
GHSA-27wf-5967-98gx
Nov 27, 2024
Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Fixed in
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-0793
GO-2024-3277
GHSA-h7wq-jj8r-qm7p
Nov 19, 2024
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Fixed in
1.27.0-alpha.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25743
GO-2022-0983
GHSA-f9jg-8p32-2f55
Aug 21, 2024
ANSI escape characters not filtered in kubectl in k8s.io/kubernetes ANSI escape characters not filtered in kubectl in k8s.io/kubernetes Fixed in
1.26.0-alpha.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25735
GO-2022-0907
GHSA-g42g-737j-qx6j
Aug 21, 2024
Access Restriction Bypass in kube-apiserver in k8s.io/kubernetes Access Restriction Bypass in kube-apiserver in k8s.io/kubernetes Fixed in
1.18.18
1.19.10
1.20.6
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25741
GO-2022-0910
GHSA-f5f7-6478-qm6p
Aug 21, 2024
Files or Directories Accessible to External Parties in kubernetes in k8s.io/kubernetes Files or Directories Accessible to External Parties in kubernetes in k8s.io/kubernetes Fixed in
1.19.15
1.20.11
1.21.5
1.22.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25737
GO-2022-0908
GHSA-mfv7-gq43-w965
Aug 21, 2024
Incomplete List of Disallowed Inputs in Kubernetes in k8s.io/kubernetes Incomplete List of Disallowed Inputs in Kubernetes in k8s.io/kubernetes Fixed in
1.18.19
1.19.11
1.20.7
1.21.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-5528
GO-2023-2341
GHSA-hq6q-c2x6-hmch
Aug 21, 2024
Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Fixed in
1.25.16
1.26.11
1.27.8
1.28.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25736
GO-2023-2159
GHSA-35c7-w35f-xwgh
Aug 21, 2024
Kube-proxy may unintentionally forward traffic in k8s.io/kubernetes Kube-proxy may unintentionally forward traffic in k8s.io/kubernetes Fixed in
1.21.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3955
GO-2023-2170
GHSA-q78c-gwqw-jcmc
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes and k8s.io/mount-utils A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3676
GO-2023-2330
GHSA-7fxm-f474-hf8w
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2431
GO-2023-1864
GHSA-xc8m-28vv-4pjc
Aug 20, 2024
Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Fixed in
1.24.14
1.25.10
1.26.5
1.27.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2728
GO-2023-1892
GHSA-cgcv-5272-97pr
Aug 20, 2024
Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2727
GO-2023-1891
GHSA-qc2g-gmh6-95p4
Aug 20, 2024
Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5321
GO-2024-2994
GHSA-82m2-cv7p-4m75
Jul 22, 2024
Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Fixed in
1.27.16
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8563
GO-2024-2755
GHSA-5xfg-wv98-264m
Jun 05, 2024
Sensitive Information leak for VSphere users via Log File in k8s.io/kubernetes Sensitive Information leak for VSphere users via Log File in k8s.io/kubernetes Fixed in
1.19.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3177
GO-2024-2746
GHSA-pxhw-596r-rwq5
Jun 04, 2024
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Fixed in
1.27.13
1.28.9
1.29.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8566
GO-2024-2754
GHSA-5x96-j797-5qqw
Jun 04, 2024
Sensitive Information leak for users of Ceph RBD via Log File in k8s.io/kubernetes Sensitive Information leak for users of Ceph RBD via Log File in k8s.io/kubernetes Fixed in
1.17.13
1.18.10
1.19.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-8565
GHSA-8cfg-vx93-jvxw
GO-2021-0064
Feb 06, 2023
Kubernetes client-go vulnerable to Sensitive Information Leak via Log File
4.7
/ 10
Medium
Local
High
Low
None
Unchanged
High
None
None
In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.5, <= v1.18.13, <= v1.17.15, < v1.20.0-alpha2. Fixed in
1.20.0-alpha.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8564
GHSA-8mjg-8c8g-6h85
GO-2021-0066
Feb 06, 2023
Kubernetes Sensitive Information leak via Log File
4.7
/ 10
Medium
Local
High
Low
None
Unchanged
High
None
None
In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19.3, < v1.18.10, < v1.17.13. Fixed in
1.20.0-alpha.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8554
GHSA-j9wf-vvm6-4r9w
Feb 08, 2022
Unverified Ownership in Kubernetes
5.0
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
Low
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8562
GHSA-qh36-44jv-c8xj
Feb 02, 2022
Potential proxy IP restriction bypass in Kubernetes
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Services, Pods, Nodes, or StorageClass service providers. As part of this mitigation Kubernetes does a DNS name resolution check and validates that response IPs are not in the link-local (169.254.0.0/16) or localhost (127.0.0.0/8) range. Kubernetes then performs a second DNS resolution without validation for the actual connection. If a non-standard DNS server returns different non-cached responses, a user may be able to bypass the proxy IP restriction and access private networks on the control plane. All versions of Kubernetes are impacted, and there is no fix in place. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-25740
GHSA-vw47-mr44-3jf9
Sep 21, 2021
Confused Deputy in Kubernetes
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8561
GHSA-74j8-88mm-7496
Sep 21, 2021
Confused Deputy in Kubernetes
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs. References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.18.7
minor
Dependencies (127)
+ 119 more |
|
v1.15.11-beta.0
pre
34 CVEs
CVE-2025-13281
GO-2025-4240
GHSA-r6j8-c6r2-37rr
Dec 16, 2025
Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Fixed in
1.32.10
1.33.6
1.34.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5187
GO-2025-3915
GHSA-4x4m-3c2p-qppc
Sep 18, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Fixed in
1.31.12
1.32.8
1.33.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-9042
GO-2025-3522
GHSA-vv39-3w5q-974q
Mar 25, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Fixed in
1.29.13
1.30.9
1.31.5
1.32.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-0426
GO-2025-3465
GHSA-jgfp-53c3-624w
Mar 03, 2025
Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Fixed in
1.29.14
1.30.10
1.31.6
1.32.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10220
GO-2024-3286
GHSA-27wf-5967-98gx
Nov 27, 2024
Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Fixed in
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-0793
GO-2024-3277
GHSA-h7wq-jj8r-qm7p
Nov 19, 2024
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Fixed in
1.27.0-alpha.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25743
GO-2022-0983
GHSA-f9jg-8p32-2f55
Aug 21, 2024
ANSI escape characters not filtered in kubectl in k8s.io/kubernetes ANSI escape characters not filtered in kubectl in k8s.io/kubernetes Fixed in
1.26.0-alpha.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25735
GO-2022-0907
GHSA-g42g-737j-qx6j
Aug 21, 2024
Access Restriction Bypass in kube-apiserver in k8s.io/kubernetes Access Restriction Bypass in kube-apiserver in k8s.io/kubernetes Fixed in
1.18.18
1.19.10
1.20.6
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8555
GO-2022-0890
GHSA-x6mj-w4jf-jmgw
Aug 21, 2024
Server Side Request Forgery (SSRF) in Kubernetes in k8s.io/kubernetes Server Side Request Forgery (SSRF) in Kubernetes in k8s.io/kubernetes Fixed in
1.15.12
1.16.9
1.17.4
1.18.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25741
GO-2022-0910
GHSA-f5f7-6478-qm6p
Aug 21, 2024
Files or Directories Accessible to External Parties in kubernetes in k8s.io/kubernetes Files or Directories Accessible to External Parties in kubernetes in k8s.io/kubernetes Fixed in
1.19.15
1.20.11
1.21.5
1.22.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8558
GO-2022-0885
GHSA-wqv3-8cm6-h6wg
Aug 21, 2024
Improper Authentication in Kubernetes in k8s.io/kubernetes Improper Authentication in Kubernetes in k8s.io/kubernetes Fixed in
1.16.11
1.17.7
1.18.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2019-11251
GO-2022-0802
GHSA-6qfg-8799-r575
Aug 21, 2024
Kubernetes kubectl cp Vulnerable to Symlink Attack in k8s.io/kubernetes Kubernetes kubectl cp Vulnerable to Symlink Attack in k8s.io/kubernetes Fixed in
1.13.11
1.14.7
1.16.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-5528
GO-2023-2341
GHSA-hq6q-c2x6-hmch
Aug 21, 2024
Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Fixed in
1.25.16
1.26.11
1.27.8
1.28.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25736
GO-2023-2159
GHSA-35c7-w35f-xwgh
Aug 21, 2024
Kube-proxy may unintentionally forward traffic in k8s.io/kubernetes Kube-proxy may unintentionally forward traffic in k8s.io/kubernetes Fixed in
1.21.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3955
GO-2023-2170
GHSA-q78c-gwqw-jcmc
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes and k8s.io/mount-utils A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3676
GO-2023-2330
GHSA-7fxm-f474-hf8w
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2431
GO-2023-1864
GHSA-xc8m-28vv-4pjc
Aug 20, 2024
Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Fixed in
1.24.14
1.25.10
1.26.5
1.27.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2728
GO-2023-1892
GHSA-cgcv-5272-97pr
Aug 20, 2024
Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2727
GO-2023-1891
GHSA-qc2g-gmh6-95p4
Aug 20, 2024
Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5321
GO-2024-2994
GHSA-82m2-cv7p-4m75
Jul 22, 2024
Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Fixed in
1.27.16
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8557
GO-2024-2753
GHSA-55qj-gj3x-jq9r
Jun 10, 2024
Denial of service in Kubernetes in k8s.io/kubernetes Denial of service in Kubernetes in k8s.io/kubernetes Fixed in
1.16.13
1.17.9
1.18.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-8563
GO-2024-2755
GHSA-5xfg-wv98-264m
Jun 05, 2024
Sensitive Information leak for VSphere users via Log File in k8s.io/kubernetes Sensitive Information leak for VSphere users via Log File in k8s.io/kubernetes Fixed in
1.19.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3177
GO-2024-2746
GHSA-pxhw-596r-rwq5
Jun 04, 2024
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Fixed in
1.27.13
1.28.9
1.29.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8566
GO-2024-2754
GHSA-5x96-j797-5qqw
Jun 04, 2024
Sensitive Information leak for users of Ceph RBD via Log File in k8s.io/kubernetes Sensitive Information leak for users of Ceph RBD via Log File in k8s.io/kubernetes Fixed in
1.17.13
1.18.10
1.19.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-8559
GO-2024-2748
GHSA-33c5-9fx5-fvjm
May 20, 2024
Privilege Escalation in Kubernetes in k8s.io/apimachinery The Kubernetes kube-apiserver is vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise. Fixed in
1.16.13
1.17.9
1.18.7
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8565
GHSA-8cfg-vx93-jvxw
GO-2021-0064
Feb 06, 2023
Kubernetes client-go vulnerable to Sensitive Information Leak via Log File
4.7
/ 10
Medium
Local
High
Low
None
Unchanged
High
None
None
In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.5, <= v1.18.13, <= v1.17.15, < v1.20.0-alpha2. Fixed in
1.20.0-alpha.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8564
GHSA-8mjg-8c8g-6h85
GO-2021-0066
Feb 06, 2023
Kubernetes Sensitive Information leak via Log File
4.7
/ 10
Medium
Local
High
Low
None
Unchanged
High
None
None
In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19.3, < v1.18.10, < v1.17.13. Fixed in
1.20.0-alpha.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11250
GHSA-jmrx-5g74-6v2f
GO-2021-0065
May 24, 2022
Kubernetes client-go library logs may disclose credentials to unauthorized users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected. Fixed in
1.16.0-beta.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8554
GHSA-j9wf-vvm6-4r9w
Feb 08, 2022
Unverified Ownership in Kubernetes
5.0
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
Low
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8562
GHSA-qh36-44jv-c8xj
Feb 02, 2022
Potential proxy IP restriction bypass in Kubernetes
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Services, Pods, Nodes, or StorageClass service providers. As part of this mitigation Kubernetes does a DNS name resolution check and validates that response IPs are not in the link-local (169.254.0.0/16) or localhost (127.0.0.0/8) range. Kubernetes then performs a second DNS resolution without validation for the actual connection. If a non-standard DNS server returns different non-cached responses, a user may be able to bypass the proxy IP restriction and access private networks on the control plane. All versions of Kubernetes are impacted, and there is no fix in place. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-25740
GHSA-vw47-mr44-3jf9
Sep 21, 2021
Confused Deputy in Kubernetes
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8561
GHSA-74j8-88mm-7496
Sep 21, 2021
Confused Deputy in Kubernetes
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs. References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.15.11-beta.0
pre
Dependencies (138)
+ 130 more |
|
v1.16.8-beta.0
pre
33 CVEs
CVE-2025-13281
GO-2025-4240
GHSA-r6j8-c6r2-37rr
Dec 16, 2025
Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Fixed in
1.32.10
1.33.6
1.34.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5187
GO-2025-3915
GHSA-4x4m-3c2p-qppc
Sep 18, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Fixed in
1.31.12
1.32.8
1.33.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-9042
GO-2025-3522
GHSA-vv39-3w5q-974q
Mar 25, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Fixed in
1.29.13
1.30.9
1.31.5
1.32.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-0426
GO-2025-3465
GHSA-jgfp-53c3-624w
Mar 03, 2025
Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Fixed in
1.29.14
1.30.10
1.31.6
1.32.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10220
GO-2024-3286
GHSA-27wf-5967-98gx
Nov 27, 2024
Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Fixed in
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-0793
GO-2024-3277
GHSA-h7wq-jj8r-qm7p
Nov 19, 2024
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Fixed in
1.27.0-alpha.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25743
GO-2022-0983
GHSA-f9jg-8p32-2f55
Aug 21, 2024
ANSI escape characters not filtered in kubectl in k8s.io/kubernetes ANSI escape characters not filtered in kubectl in k8s.io/kubernetes Fixed in
1.26.0-alpha.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25735
GO-2022-0907
GHSA-g42g-737j-qx6j
Aug 21, 2024
Access Restriction Bypass in kube-apiserver in k8s.io/kubernetes Access Restriction Bypass in kube-apiserver in k8s.io/kubernetes Fixed in
1.18.18
1.19.10
1.20.6
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8555
GO-2022-0890
GHSA-x6mj-w4jf-jmgw
Aug 21, 2024
Server Side Request Forgery (SSRF) in Kubernetes in k8s.io/kubernetes Server Side Request Forgery (SSRF) in Kubernetes in k8s.io/kubernetes Fixed in
1.15.12
1.16.9
1.17.4
1.18.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25741
GO-2022-0910
GHSA-f5f7-6478-qm6p
Aug 21, 2024
Files or Directories Accessible to External Parties in kubernetes in k8s.io/kubernetes Files or Directories Accessible to External Parties in kubernetes in k8s.io/kubernetes Fixed in
1.19.15
1.20.11
1.21.5
1.22.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25737
GO-2022-0908
GHSA-mfv7-gq43-w965
Aug 21, 2024
Incomplete List of Disallowed Inputs in Kubernetes in k8s.io/kubernetes Incomplete List of Disallowed Inputs in Kubernetes in k8s.io/kubernetes Fixed in
1.18.19
1.19.11
1.20.7
1.21.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-8558
GO-2022-0885
GHSA-wqv3-8cm6-h6wg
Aug 21, 2024
Improper Authentication in Kubernetes in k8s.io/kubernetes Improper Authentication in Kubernetes in k8s.io/kubernetes Fixed in
1.16.11
1.17.7
1.18.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5528
GO-2023-2341
GHSA-hq6q-c2x6-hmch
Aug 21, 2024
Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Fixed in
1.25.16
1.26.11
1.27.8
1.28.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25736
GO-2023-2159
GHSA-35c7-w35f-xwgh
Aug 21, 2024
Kube-proxy may unintentionally forward traffic in k8s.io/kubernetes Kube-proxy may unintentionally forward traffic in k8s.io/kubernetes Fixed in
1.21.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3955
GO-2023-2170
GHSA-q78c-gwqw-jcmc
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes and k8s.io/mount-utils A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3676
GO-2023-2330
GHSA-7fxm-f474-hf8w
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2431
GO-2023-1864
GHSA-xc8m-28vv-4pjc
Aug 20, 2024
Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Fixed in
1.24.14
1.25.10
1.26.5
1.27.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2728
GO-2023-1892
GHSA-cgcv-5272-97pr
Aug 20, 2024
Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2727
GO-2023-1891
GHSA-qc2g-gmh6-95p4
Aug 20, 2024
Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5321
GO-2024-2994
GHSA-82m2-cv7p-4m75
Jul 22, 2024
Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Fixed in
1.27.16
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8557
GO-2024-2753
GHSA-55qj-gj3x-jq9r
Jun 10, 2024
Denial of service in Kubernetes in k8s.io/kubernetes Denial of service in Kubernetes in k8s.io/kubernetes Fixed in
1.16.13
1.17.9
1.18.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-8563
GO-2024-2755
GHSA-5xfg-wv98-264m
Jun 05, 2024
Sensitive Information leak for VSphere users via Log File in k8s.io/kubernetes Sensitive Information leak for VSphere users via Log File in k8s.io/kubernetes Fixed in
1.19.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3177
GO-2024-2746
GHSA-pxhw-596r-rwq5
Jun 04, 2024
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Fixed in
1.27.13
1.28.9
1.29.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8566
GO-2024-2754
GHSA-5x96-j797-5qqw
Jun 04, 2024
Sensitive Information leak for users of Ceph RBD via Log File in k8s.io/kubernetes Sensitive Information leak for users of Ceph RBD via Log File in k8s.io/kubernetes Fixed in
1.17.13
1.18.10
1.19.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-8559
GO-2024-2748
GHSA-33c5-9fx5-fvjm
May 20, 2024
Privilege Escalation in Kubernetes in k8s.io/apimachinery The Kubernetes kube-apiserver is vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise. Fixed in
1.16.13
1.17.9
1.18.7
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8565
GHSA-8cfg-vx93-jvxw
GO-2021-0064
Feb 06, 2023
Kubernetes client-go vulnerable to Sensitive Information Leak via Log File
4.7
/ 10
Medium
Local
High
Low
None
Unchanged
High
None
None
In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.5, <= v1.18.13, <= v1.17.15, < v1.20.0-alpha2. Fixed in
1.20.0-alpha.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8564
GHSA-8mjg-8c8g-6h85
GO-2021-0066
Feb 06, 2023
Kubernetes Sensitive Information leak via Log File
4.7
/ 10
Medium
Local
High
Low
None
Unchanged
High
None
None
In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19.3, < v1.18.10, < v1.17.13. Fixed in
1.20.0-alpha.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8554
GHSA-j9wf-vvm6-4r9w
Feb 08, 2022
Unverified Ownership in Kubernetes
5.0
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
Low
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8562
GHSA-qh36-44jv-c8xj
Feb 02, 2022
Potential proxy IP restriction bypass in Kubernetes
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Services, Pods, Nodes, or StorageClass service providers. As part of this mitigation Kubernetes does a DNS name resolution check and validates that response IPs are not in the link-local (169.254.0.0/16) or localhost (127.0.0.0/8) range. Kubernetes then performs a second DNS resolution without validation for the actual connection. If a non-standard DNS server returns different non-cached responses, a user may be able to bypass the proxy IP restriction and access private networks on the control plane. All versions of Kubernetes are impacted, and there is no fix in place. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-25740
GHSA-vw47-mr44-3jf9
Sep 21, 2021
Confused Deputy in Kubernetes
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8561
GHSA-74j8-88mm-7496
Sep 21, 2021
Confused Deputy in Kubernetes
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs. References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.16.8-beta.0
pre
Dependencies (128)
+ 120 more |
|
v1.16.5
minor
34 CVEs
CVE-2025-13281
GO-2025-4240
GHSA-r6j8-c6r2-37rr
Dec 16, 2025
Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Fixed in
1.32.10
1.33.6
1.34.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5187
GO-2025-3915
GHSA-4x4m-3c2p-qppc
Sep 18, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Fixed in
1.31.12
1.32.8
1.33.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-9042
GO-2025-3522
GHSA-vv39-3w5q-974q
Mar 25, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Fixed in
1.29.13
1.30.9
1.31.5
1.32.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-0426
GO-2025-3465
GHSA-jgfp-53c3-624w
Mar 03, 2025
Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Fixed in
1.29.14
1.30.10
1.31.6
1.32.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10220
GO-2024-3286
GHSA-27wf-5967-98gx
Nov 27, 2024
Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Fixed in
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-0793
GO-2024-3277
GHSA-h7wq-jj8r-qm7p
Nov 19, 2024
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Fixed in
1.27.0-alpha.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25743
GO-2022-0983
GHSA-f9jg-8p32-2f55
Aug 21, 2024
ANSI escape characters not filtered in kubectl in k8s.io/kubernetes ANSI escape characters not filtered in kubectl in k8s.io/kubernetes Fixed in
1.26.0-alpha.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25735
GO-2022-0907
GHSA-g42g-737j-qx6j
Aug 21, 2024
Access Restriction Bypass in kube-apiserver in k8s.io/kubernetes Access Restriction Bypass in kube-apiserver in k8s.io/kubernetes Fixed in
1.18.18
1.19.10
1.20.6
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8555
GO-2022-0890
GHSA-x6mj-w4jf-jmgw
Aug 21, 2024
Server Side Request Forgery (SSRF) in Kubernetes in k8s.io/kubernetes Server Side Request Forgery (SSRF) in Kubernetes in k8s.io/kubernetes Fixed in
1.15.12
1.16.9
1.17.4
1.18.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25741
GO-2022-0910
GHSA-f5f7-6478-qm6p
Aug 21, 2024
Files or Directories Accessible to External Parties in kubernetes in k8s.io/kubernetes Files or Directories Accessible to External Parties in kubernetes in k8s.io/kubernetes Fixed in
1.19.15
1.20.11
1.21.5
1.22.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25737
GO-2022-0908
GHSA-mfv7-gq43-w965
Aug 21, 2024
Incomplete List of Disallowed Inputs in Kubernetes in k8s.io/kubernetes Incomplete List of Disallowed Inputs in Kubernetes in k8s.io/kubernetes Fixed in
1.18.19
1.19.11
1.20.7
1.21.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-8558
GO-2022-0885
GHSA-wqv3-8cm6-h6wg
Aug 21, 2024
Improper Authentication in Kubernetes in k8s.io/kubernetes Improper Authentication in Kubernetes in k8s.io/kubernetes Fixed in
1.16.11
1.17.7
1.18.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8551
GO-2022-0867
GHSA-qhm4-jxv7-j9pq
Aug 21, 2024
Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes in k8s.io/kubernetes Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes in k8s.io/kubernetes Fixed in
1.15.10
1.16.6
1.17.2
References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2023-5528
GO-2023-2341
GHSA-hq6q-c2x6-hmch
Aug 21, 2024
Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Fixed in
1.25.16
1.26.11
1.27.8
1.28.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25736
GO-2023-2159
GHSA-35c7-w35f-xwgh
Aug 21, 2024
Kube-proxy may unintentionally forward traffic in k8s.io/kubernetes Kube-proxy may unintentionally forward traffic in k8s.io/kubernetes Fixed in
1.21.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3955
GO-2023-2170
GHSA-q78c-gwqw-jcmc
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes and k8s.io/mount-utils A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3676
GO-2023-2330
GHSA-7fxm-f474-hf8w
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2431
GO-2023-1864
GHSA-xc8m-28vv-4pjc
Aug 20, 2024
Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Fixed in
1.24.14
1.25.10
1.26.5
1.27.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2728
GO-2023-1892
GHSA-cgcv-5272-97pr
Aug 20, 2024
Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2727
GO-2023-1891
GHSA-qc2g-gmh6-95p4
Aug 20, 2024
Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5321
GO-2024-2994
GHSA-82m2-cv7p-4m75
Jul 22, 2024
Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Fixed in
1.27.16
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8557
GO-2024-2753
GHSA-55qj-gj3x-jq9r
Jun 10, 2024
Denial of service in Kubernetes in k8s.io/kubernetes Denial of service in Kubernetes in k8s.io/kubernetes Fixed in
1.16.13
1.17.9
1.18.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-8563
GO-2024-2755
GHSA-5xfg-wv98-264m
Jun 05, 2024
Sensitive Information leak for VSphere users via Log File in k8s.io/kubernetes Sensitive Information leak for VSphere users via Log File in k8s.io/kubernetes Fixed in
1.19.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3177
GO-2024-2746
GHSA-pxhw-596r-rwq5
Jun 04, 2024
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Fixed in
1.27.13
1.28.9
1.29.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8566
GO-2024-2754
GHSA-5x96-j797-5qqw
Jun 04, 2024
Sensitive Information leak for users of Ceph RBD via Log File in k8s.io/kubernetes Sensitive Information leak for users of Ceph RBD via Log File in k8s.io/kubernetes Fixed in
1.17.13
1.18.10
1.19.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-8559
GO-2024-2748
GHSA-33c5-9fx5-fvjm
May 20, 2024
Privilege Escalation in Kubernetes in k8s.io/apimachinery The Kubernetes kube-apiserver is vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise. Fixed in
1.16.13
1.17.9
1.18.7
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8565
GHSA-8cfg-vx93-jvxw
GO-2021-0064
Feb 06, 2023
Kubernetes client-go vulnerable to Sensitive Information Leak via Log File
4.7
/ 10
Medium
Local
High
Low
None
Unchanged
High
None
None
In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.5, <= v1.18.13, <= v1.17.15, < v1.20.0-alpha2. Fixed in
1.20.0-alpha.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8564
GHSA-8mjg-8c8g-6h85
GO-2021-0066
Feb 06, 2023
Kubernetes Sensitive Information leak via Log File
4.7
/ 10
Medium
Local
High
Low
None
Unchanged
High
None
None
In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19.3, < v1.18.10, < v1.17.13. Fixed in
1.20.0-alpha.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8554
GHSA-j9wf-vvm6-4r9w
Feb 08, 2022
Unverified Ownership in Kubernetes
5.0
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
Low
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8562
GHSA-qh36-44jv-c8xj
Feb 02, 2022
Potential proxy IP restriction bypass in Kubernetes
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Services, Pods, Nodes, or StorageClass service providers. As part of this mitigation Kubernetes does a DNS name resolution check and validates that response IPs are not in the link-local (169.254.0.0/16) or localhost (127.0.0.0/8) range. Kubernetes then performs a second DNS resolution without validation for the actual connection. If a non-standard DNS server returns different non-cached responses, a user may be able to bypass the proxy IP restriction and access private networks on the control plane. All versions of Kubernetes are impacted, and there is no fix in place. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-25740
GHSA-vw47-mr44-3jf9
Sep 21, 2021
Confused Deputy in Kubernetes
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8561
GHSA-74j8-88mm-7496
Sep 21, 2021
Confused Deputy in Kubernetes
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs. References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.16.5
minor
Dependencies (128)
+ 120 more |
|
v1.16.5-beta.0
pre
34 CVEs
CVE-2025-13281
GO-2025-4240
GHSA-r6j8-c6r2-37rr
Dec 16, 2025
Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Fixed in
1.32.10
1.33.6
1.34.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5187
GO-2025-3915
GHSA-4x4m-3c2p-qppc
Sep 18, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Fixed in
1.31.12
1.32.8
1.33.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-9042
GO-2025-3522
GHSA-vv39-3w5q-974q
Mar 25, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Fixed in
1.29.13
1.30.9
1.31.5
1.32.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-0426
GO-2025-3465
GHSA-jgfp-53c3-624w
Mar 03, 2025
Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Fixed in
1.29.14
1.30.10
1.31.6
1.32.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10220
GO-2024-3286
GHSA-27wf-5967-98gx
Nov 27, 2024
Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Fixed in
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-0793
GO-2024-3277
GHSA-h7wq-jj8r-qm7p
Nov 19, 2024
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Fixed in
1.27.0-alpha.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25743
GO-2022-0983
GHSA-f9jg-8p32-2f55
Aug 21, 2024
ANSI escape characters not filtered in kubectl in k8s.io/kubernetes ANSI escape characters not filtered in kubectl in k8s.io/kubernetes Fixed in
1.26.0-alpha.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25735
GO-2022-0907
GHSA-g42g-737j-qx6j
Aug 21, 2024
Access Restriction Bypass in kube-apiserver in k8s.io/kubernetes Access Restriction Bypass in kube-apiserver in k8s.io/kubernetes Fixed in
1.18.18
1.19.10
1.20.6
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8555
GO-2022-0890
GHSA-x6mj-w4jf-jmgw
Aug 21, 2024
Server Side Request Forgery (SSRF) in Kubernetes in k8s.io/kubernetes Server Side Request Forgery (SSRF) in Kubernetes in k8s.io/kubernetes Fixed in
1.15.12
1.16.9
1.17.4
1.18.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25741
GO-2022-0910
GHSA-f5f7-6478-qm6p
Aug 21, 2024
Files or Directories Accessible to External Parties in kubernetes in k8s.io/kubernetes Files or Directories Accessible to External Parties in kubernetes in k8s.io/kubernetes Fixed in
1.19.15
1.20.11
1.21.5
1.22.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25737
GO-2022-0908
GHSA-mfv7-gq43-w965
Aug 21, 2024
Incomplete List of Disallowed Inputs in Kubernetes in k8s.io/kubernetes Incomplete List of Disallowed Inputs in Kubernetes in k8s.io/kubernetes Fixed in
1.18.19
1.19.11
1.20.7
1.21.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-8558
GO-2022-0885
GHSA-wqv3-8cm6-h6wg
Aug 21, 2024
Improper Authentication in Kubernetes in k8s.io/kubernetes Improper Authentication in Kubernetes in k8s.io/kubernetes Fixed in
1.16.11
1.17.7
1.18.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8551
GO-2022-0867
GHSA-qhm4-jxv7-j9pq
Aug 21, 2024
Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes in k8s.io/kubernetes Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes in k8s.io/kubernetes Fixed in
1.15.10
1.16.6
1.17.2
References
Updated Aug 07, 2026 · Source: OSV.dev
CVE-2023-5528
GO-2023-2341
GHSA-hq6q-c2x6-hmch
Aug 21, 2024
Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Fixed in
1.25.16
1.26.11
1.27.8
1.28.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25736
GO-2023-2159
GHSA-35c7-w35f-xwgh
Aug 21, 2024
Kube-proxy may unintentionally forward traffic in k8s.io/kubernetes Kube-proxy may unintentionally forward traffic in k8s.io/kubernetes Fixed in
1.21.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3955
GO-2023-2170
GHSA-q78c-gwqw-jcmc
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes and k8s.io/mount-utils A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3676
GO-2023-2330
GHSA-7fxm-f474-hf8w
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2431
GO-2023-1864
GHSA-xc8m-28vv-4pjc
Aug 20, 2024
Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Fixed in
1.24.14
1.25.10
1.26.5
1.27.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2728
GO-2023-1892
GHSA-cgcv-5272-97pr
Aug 20, 2024
Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2727
GO-2023-1891
GHSA-qc2g-gmh6-95p4
Aug 20, 2024
Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5321
GO-2024-2994
GHSA-82m2-cv7p-4m75
Jul 22, 2024
Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Fixed in
1.27.16
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8557
GO-2024-2753
GHSA-55qj-gj3x-jq9r
Jun 10, 2024
Denial of service in Kubernetes in k8s.io/kubernetes Denial of service in Kubernetes in k8s.io/kubernetes Fixed in
1.16.13
1.17.9
1.18.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-8563
GO-2024-2755
GHSA-5xfg-wv98-264m
Jun 05, 2024
Sensitive Information leak for VSphere users via Log File in k8s.io/kubernetes Sensitive Information leak for VSphere users via Log File in k8s.io/kubernetes Fixed in
1.19.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3177
GO-2024-2746
GHSA-pxhw-596r-rwq5
Jun 04, 2024
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Fixed in
1.27.13
1.28.9
1.29.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8566
GO-2024-2754
GHSA-5x96-j797-5qqw
Jun 04, 2024
Sensitive Information leak for users of Ceph RBD via Log File in k8s.io/kubernetes Sensitive Information leak for users of Ceph RBD via Log File in k8s.io/kubernetes Fixed in
1.17.13
1.18.10
1.19.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-8559
GO-2024-2748
GHSA-33c5-9fx5-fvjm
May 20, 2024
Privilege Escalation in Kubernetes in k8s.io/apimachinery The Kubernetes kube-apiserver is vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise. Fixed in
1.16.13
1.17.9
1.18.7
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8565
GHSA-8cfg-vx93-jvxw
GO-2021-0064
Feb 06, 2023
Kubernetes client-go vulnerable to Sensitive Information Leak via Log File
4.7
/ 10
Medium
Local
High
Low
None
Unchanged
High
None
None
In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.5, <= v1.18.13, <= v1.17.15, < v1.20.0-alpha2. Fixed in
1.20.0-alpha.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8564
GHSA-8mjg-8c8g-6h85
GO-2021-0066
Feb 06, 2023
Kubernetes Sensitive Information leak via Log File
4.7
/ 10
Medium
Local
High
Low
None
Unchanged
High
None
None
In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19.3, < v1.18.10, < v1.17.13. Fixed in
1.20.0-alpha.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8554
GHSA-j9wf-vvm6-4r9w
Feb 08, 2022
Unverified Ownership in Kubernetes
5.0
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
Low
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8562
GHSA-qh36-44jv-c8xj
Feb 02, 2022
Potential proxy IP restriction bypass in Kubernetes
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Services, Pods, Nodes, or StorageClass service providers. As part of this mitigation Kubernetes does a DNS name resolution check and validates that response IPs are not in the link-local (169.254.0.0/16) or localhost (127.0.0.0/8) range. Kubernetes then performs a second DNS resolution without validation for the actual connection. If a non-standard DNS server returns different non-cached responses, a user may be able to bypass the proxy IP restriction and access private networks on the control plane. All versions of Kubernetes are impacted, and there is no fix in place. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-25740
GHSA-vw47-mr44-3jf9
Sep 21, 2021
Confused Deputy in Kubernetes
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8561
GHSA-74j8-88mm-7496
Sep 21, 2021
Confused Deputy in Kubernetes
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs. References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.16.5-beta.0
pre
Dependencies (128)
+ 120 more |
|
v1.17.0-beta.0
pre
29 CVEs
CVE-2025-13281
GO-2025-4240
GHSA-r6j8-c6r2-37rr
Dec 16, 2025
Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Fixed in
1.32.10
1.33.6
1.34.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5187
GO-2025-3915
GHSA-4x4m-3c2p-qppc
Sep 18, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Fixed in
1.31.12
1.32.8
1.33.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-9042
GO-2025-3522
GHSA-vv39-3w5q-974q
Mar 25, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Fixed in
1.29.13
1.30.9
1.31.5
1.32.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-0426
GO-2025-3465
GHSA-jgfp-53c3-624w
Mar 03, 2025
Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Fixed in
1.29.14
1.30.10
1.31.6
1.32.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10220
GO-2024-3286
GHSA-27wf-5967-98gx
Nov 27, 2024
Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Fixed in
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-0793
GO-2024-3277
GHSA-h7wq-jj8r-qm7p
Nov 19, 2024
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Fixed in
1.27.0-alpha.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25743
GO-2022-0983
GHSA-f9jg-8p32-2f55
Aug 21, 2024
ANSI escape characters not filtered in kubectl in k8s.io/kubernetes ANSI escape characters not filtered in kubectl in k8s.io/kubernetes Fixed in
1.26.0-alpha.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25735
GO-2022-0907
GHSA-g42g-737j-qx6j
Aug 21, 2024
Access Restriction Bypass in kube-apiserver in k8s.io/kubernetes Access Restriction Bypass in kube-apiserver in k8s.io/kubernetes Fixed in
1.18.18
1.19.10
1.20.6
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25741
GO-2022-0910
GHSA-f5f7-6478-qm6p
Aug 21, 2024
Files or Directories Accessible to External Parties in kubernetes in k8s.io/kubernetes Files or Directories Accessible to External Parties in kubernetes in k8s.io/kubernetes Fixed in
1.19.15
1.20.11
1.21.5
1.22.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25737
GO-2022-0908
GHSA-mfv7-gq43-w965
Aug 21, 2024
Incomplete List of Disallowed Inputs in Kubernetes in k8s.io/kubernetes Incomplete List of Disallowed Inputs in Kubernetes in k8s.io/kubernetes Fixed in
1.18.19
1.19.11
1.20.7
1.21.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-5528
GO-2023-2341
GHSA-hq6q-c2x6-hmch
Aug 21, 2024
Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Fixed in
1.25.16
1.26.11
1.27.8
1.28.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25736
GO-2023-2159
GHSA-35c7-w35f-xwgh
Aug 21, 2024
Kube-proxy may unintentionally forward traffic in k8s.io/kubernetes Kube-proxy may unintentionally forward traffic in k8s.io/kubernetes Fixed in
1.21.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3955
GO-2023-2170
GHSA-q78c-gwqw-jcmc
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes and k8s.io/mount-utils A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3676
GO-2023-2330
GHSA-7fxm-f474-hf8w
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2431
GO-2023-1864
GHSA-xc8m-28vv-4pjc
Aug 20, 2024
Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Fixed in
1.24.14
1.25.10
1.26.5
1.27.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2728
GO-2023-1892
GHSA-cgcv-5272-97pr
Aug 20, 2024
Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2727
GO-2023-1891
GHSA-qc2g-gmh6-95p4
Aug 20, 2024
Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5321
GO-2024-2994
GHSA-82m2-cv7p-4m75
Jul 22, 2024
Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Fixed in
1.27.16
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8563
GO-2024-2755
GHSA-5xfg-wv98-264m
Jun 05, 2024
Sensitive Information leak for VSphere users via Log File in k8s.io/kubernetes Sensitive Information leak for VSphere users via Log File in k8s.io/kubernetes Fixed in
1.19.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3177
GO-2024-2746
GHSA-pxhw-596r-rwq5
Jun 04, 2024
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Fixed in
1.27.13
1.28.9
1.29.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8566
GO-2024-2754
GHSA-5x96-j797-5qqw
Jun 04, 2024
Sensitive Information leak for users of Ceph RBD via Log File in k8s.io/kubernetes Sensitive Information leak for users of Ceph RBD via Log File in k8s.io/kubernetes Fixed in
1.17.13
1.18.10
1.19.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-8565
GHSA-8cfg-vx93-jvxw
GO-2021-0064
Feb 06, 2023
Kubernetes client-go vulnerable to Sensitive Information Leak via Log File
4.7
/ 10
Medium
Local
High
Low
None
Unchanged
High
None
None
In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.5, <= v1.18.13, <= v1.17.15, < v1.20.0-alpha2. Fixed in
1.20.0-alpha.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8564
GHSA-8mjg-8c8g-6h85
GO-2021-0066
Feb 06, 2023
Kubernetes Sensitive Information leak via Log File
4.7
/ 10
Medium
Local
High
Low
None
Unchanged
High
None
None
In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19.3, < v1.18.10, < v1.17.13. Fixed in
1.20.0-alpha.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8554
GHSA-j9wf-vvm6-4r9w
Feb 08, 2022
Unverified Ownership in Kubernetes
5.0
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
Low
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8562
GHSA-qh36-44jv-c8xj
Feb 02, 2022
Potential proxy IP restriction bypass in Kubernetes
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Services, Pods, Nodes, or StorageClass service providers. As part of this mitigation Kubernetes does a DNS name resolution check and validates that response IPs are not in the link-local (169.254.0.0/16) or localhost (127.0.0.0/8) range. Kubernetes then performs a second DNS resolution without validation for the actual connection. If a non-standard DNS server returns different non-cached responses, a user may be able to bypass the proxy IP restriction and access private networks on the control plane. All versions of Kubernetes are impacted, and there is no fix in place. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-25740
GHSA-vw47-mr44-3jf9
Sep 21, 2021
Confused Deputy in Kubernetes
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8561
GHSA-74j8-88mm-7496
Sep 21, 2021
Confused Deputy in Kubernetes
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs. References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.17.0-beta.0
pre
Dependencies (127)
+ 119 more |
|
v1.14.9-beta.0
pre
33 CVEs
CVE-2025-13281
GO-2025-4240
GHSA-r6j8-c6r2-37rr
Dec 16, 2025
Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Fixed in
1.32.10
1.33.6
1.34.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5187
GO-2025-3915
GHSA-4x4m-3c2p-qppc
Sep 18, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Fixed in
1.31.12
1.32.8
1.33.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-9042
GO-2025-3522
GHSA-vv39-3w5q-974q
Mar 25, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Fixed in
1.29.13
1.30.9
1.31.5
1.32.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-0426
GO-2025-3465
GHSA-jgfp-53c3-624w
Mar 03, 2025
Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Fixed in
1.29.14
1.30.10
1.31.6
1.32.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10220
GO-2024-3286
GHSA-27wf-5967-98gx
Nov 27, 2024
Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Fixed in
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-0793
GO-2024-3277
GHSA-h7wq-jj8r-qm7p
Nov 19, 2024
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Fixed in
1.27.0-alpha.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25743
GO-2022-0983
GHSA-f9jg-8p32-2f55
Aug 21, 2024
ANSI escape characters not filtered in kubectl in k8s.io/kubernetes ANSI escape characters not filtered in kubectl in k8s.io/kubernetes Fixed in
1.26.0-alpha.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25735
GO-2022-0907
GHSA-g42g-737j-qx6j
Aug 21, 2024
Access Restriction Bypass in kube-apiserver in k8s.io/kubernetes Access Restriction Bypass in kube-apiserver in k8s.io/kubernetes Fixed in
1.18.18
1.19.10
1.20.6
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8555
GO-2022-0890
GHSA-x6mj-w4jf-jmgw
Aug 21, 2024
Server Side Request Forgery (SSRF) in Kubernetes in k8s.io/kubernetes Server Side Request Forgery (SSRF) in Kubernetes in k8s.io/kubernetes Fixed in
1.15.12
1.16.9
1.17.4
1.18.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25741
GO-2022-0910
GHSA-f5f7-6478-qm6p
Aug 21, 2024
Files or Directories Accessible to External Parties in kubernetes in k8s.io/kubernetes Files or Directories Accessible to External Parties in kubernetes in k8s.io/kubernetes Fixed in
1.19.15
1.20.11
1.21.5
1.22.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8558
GO-2022-0885
GHSA-wqv3-8cm6-h6wg
Aug 21, 2024
Improper Authentication in Kubernetes in k8s.io/kubernetes Improper Authentication in Kubernetes in k8s.io/kubernetes Fixed in
1.16.11
1.17.7
1.18.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-5528
GO-2023-2341
GHSA-hq6q-c2x6-hmch
Aug 21, 2024
Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Fixed in
1.25.16
1.26.11
1.27.8
1.28.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25736
GO-2023-2159
GHSA-35c7-w35f-xwgh
Aug 21, 2024
Kube-proxy may unintentionally forward traffic in k8s.io/kubernetes Kube-proxy may unintentionally forward traffic in k8s.io/kubernetes Fixed in
1.21.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3955
GO-2023-2170
GHSA-q78c-gwqw-jcmc
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes and k8s.io/mount-utils A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3676
GO-2023-2330
GHSA-7fxm-f474-hf8w
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2431
GO-2023-1864
GHSA-xc8m-28vv-4pjc
Aug 20, 2024
Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Fixed in
1.24.14
1.25.10
1.26.5
1.27.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2728
GO-2023-1892
GHSA-cgcv-5272-97pr
Aug 20, 2024
Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2727
GO-2023-1891
GHSA-qc2g-gmh6-95p4
Aug 20, 2024
Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5321
GO-2024-2994
GHSA-82m2-cv7p-4m75
Jul 22, 2024
Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Fixed in
1.27.16
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8557
GO-2024-2753
GHSA-55qj-gj3x-jq9r
Jun 10, 2024
Denial of service in Kubernetes in k8s.io/kubernetes Denial of service in Kubernetes in k8s.io/kubernetes Fixed in
1.16.13
1.17.9
1.18.6
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-8563
GO-2024-2755
GHSA-5xfg-wv98-264m
Jun 05, 2024
Sensitive Information leak for VSphere users via Log File in k8s.io/kubernetes Sensitive Information leak for VSphere users via Log File in k8s.io/kubernetes Fixed in
1.19.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3177
GO-2024-2746
GHSA-pxhw-596r-rwq5
Jun 04, 2024
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Fixed in
1.27.13
1.28.9
1.29.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8566
GO-2024-2754
GHSA-5x96-j797-5qqw
Jun 04, 2024
Sensitive Information leak for users of Ceph RBD via Log File in k8s.io/kubernetes Sensitive Information leak for users of Ceph RBD via Log File in k8s.io/kubernetes Fixed in
1.17.13
1.18.10
1.19.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-8559
GO-2024-2748
GHSA-33c5-9fx5-fvjm
May 20, 2024
Privilege Escalation in Kubernetes in k8s.io/apimachinery The Kubernetes kube-apiserver is vulnerable to an unvalidated redirect on proxied upgrade requests that could allow an attacker to escalate privileges from a node compromise to a full cluster compromise. Fixed in
1.16.13
1.17.9
1.18.7
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8565
GHSA-8cfg-vx93-jvxw
GO-2021-0064
Feb 06, 2023
Kubernetes client-go vulnerable to Sensitive Information Leak via Log File
4.7
/ 10
Medium
Local
High
Low
None
Unchanged
High
None
None
In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.5, <= v1.18.13, <= v1.17.15, < v1.20.0-alpha2. Fixed in
1.20.0-alpha.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8564
GHSA-8mjg-8c8g-6h85
GO-2021-0066
Feb 06, 2023
Kubernetes Sensitive Information leak via Log File
4.7
/ 10
Medium
Local
High
Low
None
Unchanged
High
None
None
In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19.3, < v1.18.10, < v1.17.13. Fixed in
1.20.0-alpha.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2019-11250
GHSA-jmrx-5g74-6v2f
GO-2021-0065
May 24, 2022
Kubernetes client-go library logs may disclose credentials to unauthorized users
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
High
None
None
The Kubernetes client-go library logs request headers at verbosity levels of 7 or higher. This can disclose credentials to unauthorized users via logs or command output. Kubernetes components (such as kube-apiserver) prior to v1.16.0, which make use of basic or bearer token authentication, and run at high verbosity levels, are affected. Fixed in
1.16.0-beta.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8554
GHSA-j9wf-vvm6-4r9w
Feb 08, 2022
Unverified Ownership in Kubernetes
5.0
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
Low
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8562
GHSA-qh36-44jv-c8xj
Feb 02, 2022
Potential proxy IP restriction bypass in Kubernetes
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Services, Pods, Nodes, or StorageClass service providers. As part of this mitigation Kubernetes does a DNS name resolution check and validates that response IPs are not in the link-local (169.254.0.0/16) or localhost (127.0.0.0/8) range. Kubernetes then performs a second DNS resolution without validation for the actual connection. If a non-standard DNS server returns different non-cached responses, a user may be able to bypass the proxy IP restriction and access private networks on the control plane. All versions of Kubernetes are impacted, and there is no fix in place. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-25740
GHSA-vw47-mr44-3jf9
Sep 21, 2021
Confused Deputy in Kubernetes
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8561
GHSA-74j8-88mm-7496
Sep 21, 2021
Confused Deputy in Kubernetes
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs. References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.14.9-beta.0
pre
|
|
v1.17.0-alpha.0
pre
29 CVEs
CVE-2025-13281
GO-2025-4240
GHSA-r6j8-c6r2-37rr
Dec 16, 2025
Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes Fixed in
1.32.10
1.33.6
1.34.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-5187
GO-2025-3915
GHSA-4x4m-3c2p-qppc
Sep 18, 2025
Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes Fixed in
1.31.12
1.32.8
1.33.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-1767
GO-2025-3521
GHSA-3wgm-2gw2-vh5m
Mar 25, 2025
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-7598
GO-2025-3547
GHSA-r56h-j38w-hrqq
Mar 25, 2025
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes References Updated Aug 07, 2026 · Source: OSV.dev
CVE-2024-9042
GO-2025-3522
GHSA-vv39-3w5q-974q
Mar 25, 2025
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes Fixed in
1.29.13
1.30.9
1.31.5
1.32.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-0426
GO-2025-3465
GHSA-jgfp-53c3-624w
Mar 03, 2025
Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes Fixed in
1.29.14
1.30.10
1.31.6
1.32.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-10220
GO-2024-3286
GHSA-27wf-5967-98gx
Nov 27, 2024
Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes Fixed in
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-0793
GO-2024-3277
GHSA-h7wq-jj8r-qm7p
Nov 19, 2024
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes Fixed in
1.27.0-alpha.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25743
GO-2022-0983
GHSA-f9jg-8p32-2f55
Aug 21, 2024
ANSI escape characters not filtered in kubectl in k8s.io/kubernetes ANSI escape characters not filtered in kubectl in k8s.io/kubernetes Fixed in
1.26.0-alpha.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25735
GO-2022-0907
GHSA-g42g-737j-qx6j
Aug 21, 2024
Access Restriction Bypass in kube-apiserver in k8s.io/kubernetes Access Restriction Bypass in kube-apiserver in k8s.io/kubernetes Fixed in
1.18.18
1.19.10
1.20.6
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25741
GO-2022-0910
GHSA-f5f7-6478-qm6p
Aug 21, 2024
Files or Directories Accessible to External Parties in kubernetes in k8s.io/kubernetes Files or Directories Accessible to External Parties in kubernetes in k8s.io/kubernetes Fixed in
1.19.15
1.20.11
1.21.5
1.22.2
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25737
GO-2022-0908
GHSA-mfv7-gq43-w965
Aug 21, 2024
Incomplete List of Disallowed Inputs in Kubernetes in k8s.io/kubernetes Incomplete List of Disallowed Inputs in Kubernetes in k8s.io/kubernetes Fixed in
1.18.19
1.19.11
1.20.7
1.21.1
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-5528
GO-2023-2341
GHSA-hq6q-c2x6-hmch
Aug 21, 2024
Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes Fixed in
1.25.16
1.26.11
1.27.8
1.28.4
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-25736
GO-2023-2159
GHSA-35c7-w35f-xwgh
Aug 21, 2024
Kube-proxy may unintentionally forward traffic in k8s.io/kubernetes Kube-proxy may unintentionally forward traffic in k8s.io/kubernetes Fixed in
1.21.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3955
GO-2023-2170
GHSA-q78c-gwqw-jcmc
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes and k8s.io/mount-utils A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-3676
GO-2023-2330
GHSA-7fxm-f474-hf8w
Aug 21, 2024
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes. Fixed in
1.24.17
1.25.13
1.26.8
1.27.5
1.28.1
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2431
GO-2023-1864
GHSA-xc8m-28vv-4pjc
Aug 20, 2024
Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes Fixed in
1.24.14
1.25.10
1.26.5
1.27.2
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2728
GO-2023-1892
GHSA-cgcv-5272-97pr
Aug 20, 2024
Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Kubernetes mountable secrets policy bypass in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2023-2727
GO-2023-1891
GHSA-qc2g-gmh6-95p4
Aug 20, 2024
Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes Fixed in
1.24.15
1.25.11
1.26.6
1.27.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2024-5321
GO-2024-2994
GHSA-82m2-cv7p-4m75
Jul 22, 2024
Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes Fixed in
1.27.16
1.28.12
1.29.7
1.30.3
References
Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8563
GO-2024-2755
GHSA-5xfg-wv98-264m
Jun 05, 2024
Sensitive Information leak for VSphere users via Log File in k8s.io/kubernetes Sensitive Information leak for VSphere users via Log File in k8s.io/kubernetes Fixed in
1.19.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2024-3177
GO-2024-2746
GHSA-pxhw-596r-rwq5
Jun 04, 2024
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes Fixed in
1.27.13
1.28.9
1.29.4
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2020-8566
GO-2024-2754
GHSA-5x96-j797-5qqw
Jun 04, 2024
Sensitive Information leak for users of Ceph RBD via Log File in k8s.io/kubernetes Sensitive Information leak for users of Ceph RBD via Log File in k8s.io/kubernetes Fixed in
1.17.13
1.18.10
1.19.3
References
Updated Mar 03, 2026 · Source: OSV.dev
CVE-2020-8565
GHSA-8cfg-vx93-jvxw
GO-2021-0064
Feb 06, 2023
Kubernetes client-go vulnerable to Sensitive Information Leak via Log File
4.7
/ 10
Medium
Local
High
Low
None
Unchanged
High
None
None
In Kubernetes, if the logging level is set to at least 9, authorization and bearer tokens will be written to log files. This can occur both in API server logs and client tool output like kubectl. This affects <= v1.19.5, <= v1.18.13, <= v1.17.15, < v1.20.0-alpha2. Fixed in
1.20.0-alpha.2
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8564
GHSA-8mjg-8c8g-6h85
GO-2021-0066
Feb 06, 2023
Kubernetes Sensitive Information leak via Log File
4.7
/ 10
Medium
Local
High
Low
None
Unchanged
High
None
None
In Kubernetes clusters using a logging level of at least 4, processing a malformed docker config file will result in the contents of the docker config file being leaked, which can include pull secrets or other registry credentials. This affects < v1.19.3, < v1.18.10, < v1.17.13. Fixed in
1.20.0-alpha.1
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8554
GHSA-j9wf-vvm6-4r9w
Feb 08, 2022
Unverified Ownership in Kubernetes
5.0
/ 10
Medium
Network
High
Low
None
Unchanged
Low
Low
Low
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8562
GHSA-qh36-44jv-c8xj
Feb 02, 2022
Potential proxy IP restriction bypass in Kubernetes
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Services, Pods, Nodes, or StorageClass service providers. As part of this mitigation Kubernetes does a DNS name resolution check and validates that response IPs are not in the link-local (169.254.0.0/16) or localhost (127.0.0.0/8) range. Kubernetes then performs a second DNS resolution without validation for the actual connection. If a non-standard DNS server returns different non-cached responses, a user may be able to bypass the proxy IP restriction and access private networks on the control plane. All versions of Kubernetes are impacted, and there is no fix in place. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2021-25740
GHSA-vw47-mr44-3jf9
Sep 21, 2021
Confused Deputy in Kubernetes
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack. References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2020-8561
GHSA-74j8-88mm-7496
Sep 21, 2021
Confused Deputy in Kubernetes
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs. References
Updated Sep 10, 2026 · Source: OSV.dev |
v1.17.0-alpha.0
pre
Dependencies (125)
+ 117 more |