kubevirt.io/kubevirt
Activity
- Latest release
- 1w ago
- Total releases
- 66
- Cadence
- ~20 days
- Last 12 months
- 22
Details
- First release
- Jan 09, 2017
| Version | Released | |
|---|---|---|
v1.10.0-alpha.0
pre
5 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.10.0-alpha.0
pre
Dependencies (86)
+ 78 more |
|
v1.9.0
minor
5 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.9.0
minor
Dependencies (85)
+ 77 more |
|
v1.9.0-rc.2
pre
5 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.9.0-rc.2
pre
Dependencies (85)
+ 77 more |
|
v1.9.0-rc.1
pre
5 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.9.0-rc.1
pre
Dependencies (85)
+ 77 more |
|
v1.9.0-rc.0
pre
5 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.9.0-rc.0
pre
Dependencies (85)
+ 77 more |
|
v1.8.4
patch
5 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.8.4
patch
Dependencies (81)
+ 73 more |
|
v1.8.3
patch
5 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.8.3
patch
Dependencies (81)
+ 73 more |
|
v1.7.4
minor
5 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.7.4
minor
Dependencies (80)
+ 72 more |
|
v1.9.0-beta.0
pre
5 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.9.0-beta.0
pre
Dependencies (81)
+ 73 more |
|
v1.9.0-alpha.0
pre
5 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.9.0-alpha.0
pre
Dependencies (80)
+ 72 more |
|
v1.7.3
patch
6 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.7.3
patch
Dependencies (80)
+ 72 more |
|
v1.8.2
patch
6 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.8.2
patch
Dependencies (81)
+ 73 more |
|
v1.8.1
minor
6 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.8.1
minor
Dependencies (81)
+ 73 more |
|
v1.8.0
minor
6 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.8.0
minor
Dependencies (81)
+ 73 more |
|
v1.8.0-rc.1
pre
6 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.8.0-rc.1
pre
Dependencies (81)
+ 73 more |
|
v1.7.2
patch
6 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.7.2
patch
Dependencies (80)
+ 72 more |
|
v1.8.0-rc.0
pre
6 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.8.0-rc.0
pre
Dependencies (81)
+ 73 more |
|
v1.7.1
patch
6 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.7.1
patch
Dependencies (80)
+ 72 more |
|
v1.8.0-beta.0
pre
6 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.8.0-beta.0
pre
Dependencies (78)
+ 70 more |
|
v1.8.0-alpha.0
pre
6 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.8.0-alpha.0
pre
Dependencies (78)
+ 70 more |
|
v1.7.0
minor
6 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.7.0
minor
Dependencies (80)
+ 72 more |
|
v1.7.0-rc.0
pre
7 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.7.0-rc.0
pre
Dependencies (80)
+ 72 more |
|
v1.6.2
minor
10 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.6.2
minor
Dependencies (82)
+ 74 more |
|
v1.2.0-alpha.0
pre
13 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64437
GO-2025-4102
GHSA-2r4r-5x78-mvqf
Nov 17, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801202148-3ce9f41c54d0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64434
GO-2025-4107
GHSA-ggp9-c99x-54gp
Nov 17, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64433
GO-2025-4109
GHSA-qw6q-3pgr-5cwq
Nov 17, 2025
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801195231-a81b27d4600c
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.2.0-alpha.0
pre
Dependencies (84)
+ 76 more |
|
v1.1.0
minor
13 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64437
GO-2025-4102
GHSA-2r4r-5x78-mvqf
Nov 17, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801202148-3ce9f41c54d0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64434
GO-2025-4107
GHSA-ggp9-c99x-54gp
Nov 17, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64433
GO-2025-4109
GHSA-qw6q-3pgr-5cwq
Nov 17, 2025
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801195231-a81b27d4600c
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.1.0
minor
Dependencies (84)
+ 76 more |
|
v1.1.0-rc.0
pre
13 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64437
GO-2025-4102
GHSA-2r4r-5x78-mvqf
Nov 17, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801202148-3ce9f41c54d0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64434
GO-2025-4107
GHSA-ggp9-c99x-54gp
Nov 17, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64433
GO-2025-4109
GHSA-qw6q-3pgr-5cwq
Nov 17, 2025
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801195231-a81b27d4600c
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.1.0-rc.0
pre
Dependencies (84)
+ 76 more |
|
v1.0.1
major
13 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64437
GO-2025-4102
GHSA-2r4r-5x78-mvqf
Nov 17, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801202148-3ce9f41c54d0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64434
GO-2025-4107
GHSA-ggp9-c99x-54gp
Nov 17, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64433
GO-2025-4109
GHSA-qw6q-3pgr-5cwq
Nov 17, 2025
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801195231-a81b27d4600c
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.0.1
major
Dependencies (81)
+ 73 more |
|
v1.0.0-rc.0
pre
13 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64437
GO-2025-4102
GHSA-2r4r-5x78-mvqf
Nov 17, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801202148-3ce9f41c54d0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64434
GO-2025-4107
GHSA-ggp9-c99x-54gp
Nov 17, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64433
GO-2025-4109
GHSA-qw6q-3pgr-5cwq
Nov 17, 2025
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801195231-a81b27d4600c
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev |
v1.0.0-rc.0
pre
Dependencies (82)
+ 74 more |
|
v0.59.0
minor
14 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64437
GO-2025-4102
GHSA-2r4r-5x78-mvqf
Nov 17, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801202148-3ce9f41c54d0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64434
GO-2025-4107
GHSA-ggp9-c99x-54gp
Nov 17, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64433
GO-2025-4109
GHSA-qw6q-3pgr-5cwq
Nov 17, 2025
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801195231-a81b27d4600c
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2023-26484
GHSA-cp96-jpmq-xrr2
Mar 16, 2023
On a compromised node, the virt-handler service account can be used to modify all node specs
8.2
/ 10
High
Network
High
Low
None
Changed
High
High
None
ImpactIf a malicious user has taken over a Kubernetes node where virt-handler (the KubeVirt node-daemon) is running, the virt-handler service account can be used to modify all node specs. This can be misused to lure-in system-level-privileged components (which can for instance read all secrets on the cluster, or can exec into pods on other nodes). This way a compromised node can be used to elevate privileges beyond the node until potentially having full privileged access to the whole cluster. The simplest way to exploit this, once a user could compromise a specific node, is to set with the virt-handler service account all other nodes to unschedulable and simply wait until system-critical components with high privileges appear on its node. Since this requires a node to be compromised first, the severity of this finding is considered Medium. PatchesNot yet available. WorkaroundsGatekeeper users can add a webhook which will block the An example policy, preventing virt-handler from changing the node spec may look like this:
and applying this template to node modifications. CreditsSpecial thanks to the discoverers of this issue: Nanzi Yang (nzyang@stu.xidian.edu.cn) Xin Guo (guox@stu.xidian.edu.cn) Jietao Xiao (jietaoXiao@stu.xidian.edu.cn) Wenbo Shen (shenwenbo@zju.edu.cn) Jinku Li (jkli@xidian.edu.cn) Referenceshttps://github.com/kubevirt/kubevirt/issues/9109 References Updated Nov 08, 2023 · Source: OSV.dev |
v0.59.0
minor
Dependencies (85)
+ 77 more |
|
v0.59.0-rc.0
pre
14 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64437
GO-2025-4102
GHSA-2r4r-5x78-mvqf
Nov 17, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801202148-3ce9f41c54d0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64434
GO-2025-4107
GHSA-ggp9-c99x-54gp
Nov 17, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64433
GO-2025-4109
GHSA-qw6q-3pgr-5cwq
Nov 17, 2025
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801195231-a81b27d4600c
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2023-26484
GHSA-cp96-jpmq-xrr2
Mar 16, 2023
On a compromised node, the virt-handler service account can be used to modify all node specs
8.2
/ 10
High
Network
High
Low
None
Changed
High
High
None
ImpactIf a malicious user has taken over a Kubernetes node where virt-handler (the KubeVirt node-daemon) is running, the virt-handler service account can be used to modify all node specs. This can be misused to lure-in system-level-privileged components (which can for instance read all secrets on the cluster, or can exec into pods on other nodes). This way a compromised node can be used to elevate privileges beyond the node until potentially having full privileged access to the whole cluster. The simplest way to exploit this, once a user could compromise a specific node, is to set with the virt-handler service account all other nodes to unschedulable and simply wait until system-critical components with high privileges appear on its node. Since this requires a node to be compromised first, the severity of this finding is considered Medium. PatchesNot yet available. WorkaroundsGatekeeper users can add a webhook which will block the An example policy, preventing virt-handler from changing the node spec may look like this:
and applying this template to node modifications. CreditsSpecial thanks to the discoverers of this issue: Nanzi Yang (nzyang@stu.xidian.edu.cn) Xin Guo (guox@stu.xidian.edu.cn) Jietao Xiao (jietaoXiao@stu.xidian.edu.cn) Wenbo Shen (shenwenbo@zju.edu.cn) Jinku Li (jkli@xidian.edu.cn) Referenceshttps://github.com/kubevirt/kubevirt/issues/9109 References Updated Nov 08, 2023 · Source: OSV.dev |
v0.59.0-rc.0
pre
Dependencies (85)
+ 77 more |
|
v0.59.0-alpha.2
pre
14 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64437
GO-2025-4102
GHSA-2r4r-5x78-mvqf
Nov 17, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801202148-3ce9f41c54d0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64434
GO-2025-4107
GHSA-ggp9-c99x-54gp
Nov 17, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64433
GO-2025-4109
GHSA-qw6q-3pgr-5cwq
Nov 17, 2025
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801195231-a81b27d4600c
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2023-26484
GHSA-cp96-jpmq-xrr2
Mar 16, 2023
On a compromised node, the virt-handler service account can be used to modify all node specs
8.2
/ 10
High
Network
High
Low
None
Changed
High
High
None
ImpactIf a malicious user has taken over a Kubernetes node where virt-handler (the KubeVirt node-daemon) is running, the virt-handler service account can be used to modify all node specs. This can be misused to lure-in system-level-privileged components (which can for instance read all secrets on the cluster, or can exec into pods on other nodes). This way a compromised node can be used to elevate privileges beyond the node until potentially having full privileged access to the whole cluster. The simplest way to exploit this, once a user could compromise a specific node, is to set with the virt-handler service account all other nodes to unschedulable and simply wait until system-critical components with high privileges appear on its node. Since this requires a node to be compromised first, the severity of this finding is considered Medium. PatchesNot yet available. WorkaroundsGatekeeper users can add a webhook which will block the An example policy, preventing virt-handler from changing the node spec may look like this:
and applying this template to node modifications. CreditsSpecial thanks to the discoverers of this issue: Nanzi Yang (nzyang@stu.xidian.edu.cn) Xin Guo (guox@stu.xidian.edu.cn) Jietao Xiao (jietaoXiao@stu.xidian.edu.cn) Wenbo Shen (shenwenbo@zju.edu.cn) Jinku Li (jkli@xidian.edu.cn) Referenceshttps://github.com/kubevirt/kubevirt/issues/9109 References Updated Nov 08, 2023 · Source: OSV.dev |
v0.59.0-alpha.2
pre
Dependencies (84)
+ 76 more |
|
v0.58.0-rc.0
pre
14 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64437
GO-2025-4102
GHSA-2r4r-5x78-mvqf
Nov 17, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801202148-3ce9f41c54d0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64434
GO-2025-4107
GHSA-ggp9-c99x-54gp
Nov 17, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64433
GO-2025-4109
GHSA-qw6q-3pgr-5cwq
Nov 17, 2025
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801195231-a81b27d4600c
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2023-26484
GHSA-cp96-jpmq-xrr2
Mar 16, 2023
On a compromised node, the virt-handler service account can be used to modify all node specs
8.2
/ 10
High
Network
High
Low
None
Changed
High
High
None
ImpactIf a malicious user has taken over a Kubernetes node where virt-handler (the KubeVirt node-daemon) is running, the virt-handler service account can be used to modify all node specs. This can be misused to lure-in system-level-privileged components (which can for instance read all secrets on the cluster, or can exec into pods on other nodes). This way a compromised node can be used to elevate privileges beyond the node until potentially having full privileged access to the whole cluster. The simplest way to exploit this, once a user could compromise a specific node, is to set with the virt-handler service account all other nodes to unschedulable and simply wait until system-critical components with high privileges appear on its node. Since this requires a node to be compromised first, the severity of this finding is considered Medium. PatchesNot yet available. WorkaroundsGatekeeper users can add a webhook which will block the An example policy, preventing virt-handler from changing the node spec may look like this:
and applying this template to node modifications. CreditsSpecial thanks to the discoverers of this issue: Nanzi Yang (nzyang@stu.xidian.edu.cn) Xin Guo (guox@stu.xidian.edu.cn) Jietao Xiao (jietaoXiao@stu.xidian.edu.cn) Wenbo Shen (shenwenbo@zju.edu.cn) Jinku Li (jkli@xidian.edu.cn) Referenceshttps://github.com/kubevirt/kubevirt/issues/9109 References Updated Nov 08, 2023 · Source: OSV.dev |
v0.58.0-rc.0
pre
Dependencies (84)
+ 76 more |
|
v0.58.0
minor
14 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64437
GO-2025-4102
GHSA-2r4r-5x78-mvqf
Nov 17, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801202148-3ce9f41c54d0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64434
GO-2025-4107
GHSA-ggp9-c99x-54gp
Nov 17, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64433
GO-2025-4109
GHSA-qw6q-3pgr-5cwq
Nov 17, 2025
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801195231-a81b27d4600c
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2023-26484
GHSA-cp96-jpmq-xrr2
Mar 16, 2023
On a compromised node, the virt-handler service account can be used to modify all node specs
8.2
/ 10
High
Network
High
Low
None
Changed
High
High
None
ImpactIf a malicious user has taken over a Kubernetes node where virt-handler (the KubeVirt node-daemon) is running, the virt-handler service account can be used to modify all node specs. This can be misused to lure-in system-level-privileged components (which can for instance read all secrets on the cluster, or can exec into pods on other nodes). This way a compromised node can be used to elevate privileges beyond the node until potentially having full privileged access to the whole cluster. The simplest way to exploit this, once a user could compromise a specific node, is to set with the virt-handler service account all other nodes to unschedulable and simply wait until system-critical components with high privileges appear on its node. Since this requires a node to be compromised first, the severity of this finding is considered Medium. PatchesNot yet available. WorkaroundsGatekeeper users can add a webhook which will block the An example policy, preventing virt-handler from changing the node spec may look like this:
and applying this template to node modifications. CreditsSpecial thanks to the discoverers of this issue: Nanzi Yang (nzyang@stu.xidian.edu.cn) Xin Guo (guox@stu.xidian.edu.cn) Jietao Xiao (jietaoXiao@stu.xidian.edu.cn) Wenbo Shen (shenwenbo@zju.edu.cn) Jinku Li (jkli@xidian.edu.cn) Referenceshttps://github.com/kubevirt/kubevirt/issues/9109 References Updated Nov 08, 2023 · Source: OSV.dev |
v0.58.0
minor
Dependencies (84)
+ 76 more |
|
v0.49.1
minor
15 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64437
GO-2025-4102
GHSA-2r4r-5x78-mvqf
Nov 17, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801202148-3ce9f41c54d0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64434
GO-2025-4107
GHSA-ggp9-c99x-54gp
Nov 17, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64433
GO-2025-4109
GHSA-qw6q-3pgr-5cwq
Nov 17, 2025
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801195231-a81b27d4600c
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
GO-2022-1000
GHSA-qv98-3369-g364
Aug 21, 2024
KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt Fixed in
0.55.1
References Updated Mar 13, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2023-26484
GHSA-cp96-jpmq-xrr2
Mar 16, 2023
On a compromised node, the virt-handler service account can be used to modify all node specs
8.2
/ 10
High
Network
High
Low
None
Changed
High
High
None
ImpactIf a malicious user has taken over a Kubernetes node where virt-handler (the KubeVirt node-daemon) is running, the virt-handler service account can be used to modify all node specs. This can be misused to lure-in system-level-privileged components (which can for instance read all secrets on the cluster, or can exec into pods on other nodes). This way a compromised node can be used to elevate privileges beyond the node until potentially having full privileged access to the whole cluster. The simplest way to exploit this, once a user could compromise a specific node, is to set with the virt-handler service account all other nodes to unschedulable and simply wait until system-critical components with high privileges appear on its node. Since this requires a node to be compromised first, the severity of this finding is considered Medium. PatchesNot yet available. WorkaroundsGatekeeper users can add a webhook which will block the An example policy, preventing virt-handler from changing the node spec may look like this:
and applying this template to node modifications. CreditsSpecial thanks to the discoverers of this issue: Nanzi Yang (nzyang@stu.xidian.edu.cn) Xin Guo (guox@stu.xidian.edu.cn) Jietao Xiao (jietaoXiao@stu.xidian.edu.cn) Wenbo Shen (shenwenbo@zju.edu.cn) Jinku Li (jkli@xidian.edu.cn) Referenceshttps://github.com/kubevirt/kubevirt/issues/9109 References Updated Nov 08, 2023 · Source: OSV.dev |
v0.49.1
minor
Dependencies (79)
+ 71 more |
|
v0.56.0-rc.0
pre
14 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64437
GO-2025-4102
GHSA-2r4r-5x78-mvqf
Nov 17, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801202148-3ce9f41c54d0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64434
GO-2025-4107
GHSA-ggp9-c99x-54gp
Nov 17, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64433
GO-2025-4109
GHSA-qw6q-3pgr-5cwq
Nov 17, 2025
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801195231-a81b27d4600c
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2023-26484
GHSA-cp96-jpmq-xrr2
Mar 16, 2023
On a compromised node, the virt-handler service account can be used to modify all node specs
8.2
/ 10
High
Network
High
Low
None
Changed
High
High
None
ImpactIf a malicious user has taken over a Kubernetes node where virt-handler (the KubeVirt node-daemon) is running, the virt-handler service account can be used to modify all node specs. This can be misused to lure-in system-level-privileged components (which can for instance read all secrets on the cluster, or can exec into pods on other nodes). This way a compromised node can be used to elevate privileges beyond the node until potentially having full privileged access to the whole cluster. The simplest way to exploit this, once a user could compromise a specific node, is to set with the virt-handler service account all other nodes to unschedulable and simply wait until system-critical components with high privileges appear on its node. Since this requires a node to be compromised first, the severity of this finding is considered Medium. PatchesNot yet available. WorkaroundsGatekeeper users can add a webhook which will block the An example policy, preventing virt-handler from changing the node spec may look like this:
and applying this template to node modifications. CreditsSpecial thanks to the discoverers of this issue: Nanzi Yang (nzyang@stu.xidian.edu.cn) Xin Guo (guox@stu.xidian.edu.cn) Jietao Xiao (jietaoXiao@stu.xidian.edu.cn) Wenbo Shen (shenwenbo@zju.edu.cn) Jinku Li (jkli@xidian.edu.cn) Referenceshttps://github.com/kubevirt/kubevirt/issues/9109 References Updated Nov 08, 2023 · Source: OSV.dev |
v0.56.0-rc.0
pre
Dependencies (81)
+ 73 more |
|
v0.53.1
minor
15 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64437
GO-2025-4102
GHSA-2r4r-5x78-mvqf
Nov 17, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801202148-3ce9f41c54d0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64434
GO-2025-4107
GHSA-ggp9-c99x-54gp
Nov 17, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64433
GO-2025-4109
GHSA-qw6q-3pgr-5cwq
Nov 17, 2025
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801195231-a81b27d4600c
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
GO-2022-1000
GHSA-qv98-3369-g364
Aug 21, 2024
KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt Fixed in
0.55.1
References Updated Mar 13, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2023-26484
GHSA-cp96-jpmq-xrr2
Mar 16, 2023
On a compromised node, the virt-handler service account can be used to modify all node specs
8.2
/ 10
High
Network
High
Low
None
Changed
High
High
None
ImpactIf a malicious user has taken over a Kubernetes node where virt-handler (the KubeVirt node-daemon) is running, the virt-handler service account can be used to modify all node specs. This can be misused to lure-in system-level-privileged components (which can for instance read all secrets on the cluster, or can exec into pods on other nodes). This way a compromised node can be used to elevate privileges beyond the node until potentially having full privileged access to the whole cluster. The simplest way to exploit this, once a user could compromise a specific node, is to set with the virt-handler service account all other nodes to unschedulable and simply wait until system-critical components with high privileges appear on its node. Since this requires a node to be compromised first, the severity of this finding is considered Medium. PatchesNot yet available. WorkaroundsGatekeeper users can add a webhook which will block the An example policy, preventing virt-handler from changing the node spec may look like this:
and applying this template to node modifications. CreditsSpecial thanks to the discoverers of this issue: Nanzi Yang (nzyang@stu.xidian.edu.cn) Xin Guo (guox@stu.xidian.edu.cn) Jietao Xiao (jietaoXiao@stu.xidian.edu.cn) Wenbo Shen (shenwenbo@zju.edu.cn) Jinku Li (jkli@xidian.edu.cn) Referenceshttps://github.com/kubevirt/kubevirt/issues/9109 References Updated Nov 08, 2023 · Source: OSV.dev |
v0.53.1
minor
Dependencies (79)
+ 71 more |
|
v0.49.0-rc.0
pre
15 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64437
GO-2025-4102
GHSA-2r4r-5x78-mvqf
Nov 17, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801202148-3ce9f41c54d0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64434
GO-2025-4107
GHSA-ggp9-c99x-54gp
Nov 17, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64433
GO-2025-4109
GHSA-qw6q-3pgr-5cwq
Nov 17, 2025
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801195231-a81b27d4600c
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
GO-2022-1000
GHSA-qv98-3369-g364
Aug 21, 2024
KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt Fixed in
0.55.1
References Updated Mar 13, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2023-26484
GHSA-cp96-jpmq-xrr2
Mar 16, 2023
On a compromised node, the virt-handler service account can be used to modify all node specs
8.2
/ 10
High
Network
High
Low
None
Changed
High
High
None
ImpactIf a malicious user has taken over a Kubernetes node where virt-handler (the KubeVirt node-daemon) is running, the virt-handler service account can be used to modify all node specs. This can be misused to lure-in system-level-privileged components (which can for instance read all secrets on the cluster, or can exec into pods on other nodes). This way a compromised node can be used to elevate privileges beyond the node until potentially having full privileged access to the whole cluster. The simplest way to exploit this, once a user could compromise a specific node, is to set with the virt-handler service account all other nodes to unschedulable and simply wait until system-critical components with high privileges appear on its node. Since this requires a node to be compromised first, the severity of this finding is considered Medium. PatchesNot yet available. WorkaroundsGatekeeper users can add a webhook which will block the An example policy, preventing virt-handler from changing the node spec may look like this:
and applying this template to node modifications. CreditsSpecial thanks to the discoverers of this issue: Nanzi Yang (nzyang@stu.xidian.edu.cn) Xin Guo (guox@stu.xidian.edu.cn) Jietao Xiao (jietaoXiao@stu.xidian.edu.cn) Wenbo Shen (shenwenbo@zju.edu.cn) Jinku Li (jkli@xidian.edu.cn) Referenceshttps://github.com/kubevirt/kubevirt/issues/9109 References Updated Nov 08, 2023 · Source: OSV.dev |
v0.49.0-rc.0
pre
Dependencies (79)
+ 71 more |
|
v0.48.0-rc.0
pre
15 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64437
GO-2025-4102
GHSA-2r4r-5x78-mvqf
Nov 17, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801202148-3ce9f41c54d0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64434
GO-2025-4107
GHSA-ggp9-c99x-54gp
Nov 17, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64433
GO-2025-4109
GHSA-qw6q-3pgr-5cwq
Nov 17, 2025
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801195231-a81b27d4600c
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
GO-2022-1000
GHSA-qv98-3369-g364
Aug 21, 2024
KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt Fixed in
0.55.1
References Updated Mar 13, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2023-26484
GHSA-cp96-jpmq-xrr2
Mar 16, 2023
On a compromised node, the virt-handler service account can be used to modify all node specs
8.2
/ 10
High
Network
High
Low
None
Changed
High
High
None
ImpactIf a malicious user has taken over a Kubernetes node where virt-handler (the KubeVirt node-daemon) is running, the virt-handler service account can be used to modify all node specs. This can be misused to lure-in system-level-privileged components (which can for instance read all secrets on the cluster, or can exec into pods on other nodes). This way a compromised node can be used to elevate privileges beyond the node until potentially having full privileged access to the whole cluster. The simplest way to exploit this, once a user could compromise a specific node, is to set with the virt-handler service account all other nodes to unschedulable and simply wait until system-critical components with high privileges appear on its node. Since this requires a node to be compromised first, the severity of this finding is considered Medium. PatchesNot yet available. WorkaroundsGatekeeper users can add a webhook which will block the An example policy, preventing virt-handler from changing the node spec may look like this:
and applying this template to node modifications. CreditsSpecial thanks to the discoverers of this issue: Nanzi Yang (nzyang@stu.xidian.edu.cn) Xin Guo (guox@stu.xidian.edu.cn) Jietao Xiao (jietaoXiao@stu.xidian.edu.cn) Wenbo Shen (shenwenbo@zju.edu.cn) Jinku Li (jkli@xidian.edu.cn) Referenceshttps://github.com/kubevirt/kubevirt/issues/9109 References Updated Nov 08, 2023 · Source: OSV.dev |
v0.48.0-rc.0
pre
Dependencies (78)
+ 70 more |
|
v0.46.1
patch
15 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64437
GO-2025-4102
GHSA-2r4r-5x78-mvqf
Nov 17, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801202148-3ce9f41c54d0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64434
GO-2025-4107
GHSA-ggp9-c99x-54gp
Nov 17, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64433
GO-2025-4109
GHSA-qw6q-3pgr-5cwq
Nov 17, 2025
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801195231-a81b27d4600c
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
GO-2022-1000
GHSA-qv98-3369-g364
Aug 21, 2024
KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt Fixed in
0.55.1
References Updated Mar 13, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2023-26484
GHSA-cp96-jpmq-xrr2
Mar 16, 2023
On a compromised node, the virt-handler service account can be used to modify all node specs
8.2
/ 10
High
Network
High
Low
None
Changed
High
High
None
ImpactIf a malicious user has taken over a Kubernetes node where virt-handler (the KubeVirt node-daemon) is running, the virt-handler service account can be used to modify all node specs. This can be misused to lure-in system-level-privileged components (which can for instance read all secrets on the cluster, or can exec into pods on other nodes). This way a compromised node can be used to elevate privileges beyond the node until potentially having full privileged access to the whole cluster. The simplest way to exploit this, once a user could compromise a specific node, is to set with the virt-handler service account all other nodes to unschedulable and simply wait until system-critical components with high privileges appear on its node. Since this requires a node to be compromised first, the severity of this finding is considered Medium. PatchesNot yet available. WorkaroundsGatekeeper users can add a webhook which will block the An example policy, preventing virt-handler from changing the node spec may look like this:
and applying this template to node modifications. CreditsSpecial thanks to the discoverers of this issue: Nanzi Yang (nzyang@stu.xidian.edu.cn) Xin Guo (guox@stu.xidian.edu.cn) Jietao Xiao (jietaoXiao@stu.xidian.edu.cn) Wenbo Shen (shenwenbo@zju.edu.cn) Jinku Li (jkli@xidian.edu.cn) Referenceshttps://github.com/kubevirt/kubevirt/issues/9109 References Updated Nov 08, 2023 · Source: OSV.dev |
v0.46.1
patch
Dependencies (76)
+ 68 more |
|
v0.46.0
minor
15 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64437
GO-2025-4102
GHSA-2r4r-5x78-mvqf
Nov 17, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801202148-3ce9f41c54d0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64434
GO-2025-4107
GHSA-ggp9-c99x-54gp
Nov 17, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64433
GO-2025-4109
GHSA-qw6q-3pgr-5cwq
Nov 17, 2025
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801195231-a81b27d4600c
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
GO-2022-1000
GHSA-qv98-3369-g364
Aug 21, 2024
KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt Fixed in
0.55.1
References Updated Mar 13, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2023-26484
GHSA-cp96-jpmq-xrr2
Mar 16, 2023
On a compromised node, the virt-handler service account can be used to modify all node specs
8.2
/ 10
High
Network
High
Low
None
Changed
High
High
None
ImpactIf a malicious user has taken over a Kubernetes node where virt-handler (the KubeVirt node-daemon) is running, the virt-handler service account can be used to modify all node specs. This can be misused to lure-in system-level-privileged components (which can for instance read all secrets on the cluster, or can exec into pods on other nodes). This way a compromised node can be used to elevate privileges beyond the node until potentially having full privileged access to the whole cluster. The simplest way to exploit this, once a user could compromise a specific node, is to set with the virt-handler service account all other nodes to unschedulable and simply wait until system-critical components with high privileges appear on its node. Since this requires a node to be compromised first, the severity of this finding is considered Medium. PatchesNot yet available. WorkaroundsGatekeeper users can add a webhook which will block the An example policy, preventing virt-handler from changing the node spec may look like this:
and applying this template to node modifications. CreditsSpecial thanks to the discoverers of this issue: Nanzi Yang (nzyang@stu.xidian.edu.cn) Xin Guo (guox@stu.xidian.edu.cn) Jietao Xiao (jietaoXiao@stu.xidian.edu.cn) Wenbo Shen (shenwenbo@zju.edu.cn) Jinku Li (jkli@xidian.edu.cn) Referenceshttps://github.com/kubevirt/kubevirt/issues/9109 References Updated Nov 08, 2023 · Source: OSV.dev |
v0.46.0
minor
Dependencies (76)
+ 68 more |
|
v0.43.1-rc.1
pre
15 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64437
GO-2025-4102
GHSA-2r4r-5x78-mvqf
Nov 17, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801202148-3ce9f41c54d0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64434
GO-2025-4107
GHSA-ggp9-c99x-54gp
Nov 17, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64433
GO-2025-4109
GHSA-qw6q-3pgr-5cwq
Nov 17, 2025
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801195231-a81b27d4600c
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
GO-2022-1000
GHSA-qv98-3369-g364
Aug 21, 2024
KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt Fixed in
0.55.1
References Updated Mar 13, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2023-26484
GHSA-cp96-jpmq-xrr2
Mar 16, 2023
On a compromised node, the virt-handler service account can be used to modify all node specs
8.2
/ 10
High
Network
High
Low
None
Changed
High
High
None
ImpactIf a malicious user has taken over a Kubernetes node where virt-handler (the KubeVirt node-daemon) is running, the virt-handler service account can be used to modify all node specs. This can be misused to lure-in system-level-privileged components (which can for instance read all secrets on the cluster, or can exec into pods on other nodes). This way a compromised node can be used to elevate privileges beyond the node until potentially having full privileged access to the whole cluster. The simplest way to exploit this, once a user could compromise a specific node, is to set with the virt-handler service account all other nodes to unschedulable and simply wait until system-critical components with high privileges appear on its node. Since this requires a node to be compromised first, the severity of this finding is considered Medium. PatchesNot yet available. WorkaroundsGatekeeper users can add a webhook which will block the An example policy, preventing virt-handler from changing the node spec may look like this:
and applying this template to node modifications. CreditsSpecial thanks to the discoverers of this issue: Nanzi Yang (nzyang@stu.xidian.edu.cn) Xin Guo (guox@stu.xidian.edu.cn) Jietao Xiao (jietaoXiao@stu.xidian.edu.cn) Wenbo Shen (shenwenbo@zju.edu.cn) Jinku Li (jkli@xidian.edu.cn) Referenceshttps://github.com/kubevirt/kubevirt/issues/9109 References Updated Nov 08, 2023 · Source: OSV.dev |
v0.43.1-rc.1
pre
Dependencies (74)
+ 66 more |
|
v0.41.0-rc.0
pre
15 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64437
GO-2025-4102
GHSA-2r4r-5x78-mvqf
Nov 17, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801202148-3ce9f41c54d0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64434
GO-2025-4107
GHSA-ggp9-c99x-54gp
Nov 17, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64433
GO-2025-4109
GHSA-qw6q-3pgr-5cwq
Nov 17, 2025
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801195231-a81b27d4600c
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
GO-2022-1000
GHSA-qv98-3369-g364
Aug 21, 2024
KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt Fixed in
0.55.1
References Updated Mar 13, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2023-26484
GHSA-cp96-jpmq-xrr2
Mar 16, 2023
On a compromised node, the virt-handler service account can be used to modify all node specs
8.2
/ 10
High
Network
High
Low
None
Changed
High
High
None
ImpactIf a malicious user has taken over a Kubernetes node where virt-handler (the KubeVirt node-daemon) is running, the virt-handler service account can be used to modify all node specs. This can be misused to lure-in system-level-privileged components (which can for instance read all secrets on the cluster, or can exec into pods on other nodes). This way a compromised node can be used to elevate privileges beyond the node until potentially having full privileged access to the whole cluster. The simplest way to exploit this, once a user could compromise a specific node, is to set with the virt-handler service account all other nodes to unschedulable and simply wait until system-critical components with high privileges appear on its node. Since this requires a node to be compromised first, the severity of this finding is considered Medium. PatchesNot yet available. WorkaroundsGatekeeper users can add a webhook which will block the An example policy, preventing virt-handler from changing the node spec may look like this:
and applying this template to node modifications. CreditsSpecial thanks to the discoverers of this issue: Nanzi Yang (nzyang@stu.xidian.edu.cn) Xin Guo (guox@stu.xidian.edu.cn) Jietao Xiao (jietaoXiao@stu.xidian.edu.cn) Wenbo Shen (shenwenbo@zju.edu.cn) Jinku Li (jkli@xidian.edu.cn) Referenceshttps://github.com/kubevirt/kubevirt/issues/9109 References Updated Nov 08, 2023 · Source: OSV.dev |
v0.41.0-rc.0
pre
Dependencies (71)
+ 63 more |
|
v0.39.0
minor
15 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64437
GO-2025-4102
GHSA-2r4r-5x78-mvqf
Nov 17, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801202148-3ce9f41c54d0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64434
GO-2025-4107
GHSA-ggp9-c99x-54gp
Nov 17, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64433
GO-2025-4109
GHSA-qw6q-3pgr-5cwq
Nov 17, 2025
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801195231-a81b27d4600c
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
GO-2022-1000
GHSA-qv98-3369-g364
Aug 21, 2024
KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt Fixed in
0.55.1
References Updated Mar 13, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2023-26484
GHSA-cp96-jpmq-xrr2
Mar 16, 2023
On a compromised node, the virt-handler service account can be used to modify all node specs
8.2
/ 10
High
Network
High
Low
None
Changed
High
High
None
ImpactIf a malicious user has taken over a Kubernetes node where virt-handler (the KubeVirt node-daemon) is running, the virt-handler service account can be used to modify all node specs. This can be misused to lure-in system-level-privileged components (which can for instance read all secrets on the cluster, or can exec into pods on other nodes). This way a compromised node can be used to elevate privileges beyond the node until potentially having full privileged access to the whole cluster. The simplest way to exploit this, once a user could compromise a specific node, is to set with the virt-handler service account all other nodes to unschedulable and simply wait until system-critical components with high privileges appear on its node. Since this requires a node to be compromised first, the severity of this finding is considered Medium. PatchesNot yet available. WorkaroundsGatekeeper users can add a webhook which will block the An example policy, preventing virt-handler from changing the node spec may look like this:
and applying this template to node modifications. CreditsSpecial thanks to the discoverers of this issue: Nanzi Yang (nzyang@stu.xidian.edu.cn) Xin Guo (guox@stu.xidian.edu.cn) Jietao Xiao (jietaoXiao@stu.xidian.edu.cn) Wenbo Shen (shenwenbo@zju.edu.cn) Jinku Li (jkli@xidian.edu.cn) Referenceshttps://github.com/kubevirt/kubevirt/issues/9109 References Updated Nov 08, 2023 · Source: OSV.dev |
v0.39.0
minor
Dependencies (67)
+ 59 more |
|
v0.39.0-rc.0
pre
15 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64437
GO-2025-4102
GHSA-2r4r-5x78-mvqf
Nov 17, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801202148-3ce9f41c54d0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64434
GO-2025-4107
GHSA-ggp9-c99x-54gp
Nov 17, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64433
GO-2025-4109
GHSA-qw6q-3pgr-5cwq
Nov 17, 2025
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801195231-a81b27d4600c
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
GO-2022-1000
GHSA-qv98-3369-g364
Aug 21, 2024
KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt Fixed in
0.55.1
References Updated Mar 13, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2023-26484
GHSA-cp96-jpmq-xrr2
Mar 16, 2023
On a compromised node, the virt-handler service account can be used to modify all node specs
8.2
/ 10
High
Network
High
Low
None
Changed
High
High
None
ImpactIf a malicious user has taken over a Kubernetes node where virt-handler (the KubeVirt node-daemon) is running, the virt-handler service account can be used to modify all node specs. This can be misused to lure-in system-level-privileged components (which can for instance read all secrets on the cluster, or can exec into pods on other nodes). This way a compromised node can be used to elevate privileges beyond the node until potentially having full privileged access to the whole cluster. The simplest way to exploit this, once a user could compromise a specific node, is to set with the virt-handler service account all other nodes to unschedulable and simply wait until system-critical components with high privileges appear on its node. Since this requires a node to be compromised first, the severity of this finding is considered Medium. PatchesNot yet available. WorkaroundsGatekeeper users can add a webhook which will block the An example policy, preventing virt-handler from changing the node spec may look like this:
and applying this template to node modifications. CreditsSpecial thanks to the discoverers of this issue: Nanzi Yang (nzyang@stu.xidian.edu.cn) Xin Guo (guox@stu.xidian.edu.cn) Jietao Xiao (jietaoXiao@stu.xidian.edu.cn) Wenbo Shen (shenwenbo@zju.edu.cn) Jinku Li (jkli@xidian.edu.cn) Referenceshttps://github.com/kubevirt/kubevirt/issues/9109 References Updated Nov 08, 2023 · Source: OSV.dev |
v0.39.0-rc.0
pre
Dependencies (67)
+ 59 more |
|
v0.38.0
minor
15 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64437
GO-2025-4102
GHSA-2r4r-5x78-mvqf
Nov 17, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801202148-3ce9f41c54d0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64434
GO-2025-4107
GHSA-ggp9-c99x-54gp
Nov 17, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64433
GO-2025-4109
GHSA-qw6q-3pgr-5cwq
Nov 17, 2025
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801195231-a81b27d4600c
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
GO-2022-1000
GHSA-qv98-3369-g364
Aug 21, 2024
KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt Fixed in
0.55.1
References Updated Mar 13, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2023-26484
GHSA-cp96-jpmq-xrr2
Mar 16, 2023
On a compromised node, the virt-handler service account can be used to modify all node specs
8.2
/ 10
High
Network
High
Low
None
Changed
High
High
None
ImpactIf a malicious user has taken over a Kubernetes node where virt-handler (the KubeVirt node-daemon) is running, the virt-handler service account can be used to modify all node specs. This can be misused to lure-in system-level-privileged components (which can for instance read all secrets on the cluster, or can exec into pods on other nodes). This way a compromised node can be used to elevate privileges beyond the node until potentially having full privileged access to the whole cluster. The simplest way to exploit this, once a user could compromise a specific node, is to set with the virt-handler service account all other nodes to unschedulable and simply wait until system-critical components with high privileges appear on its node. Since this requires a node to be compromised first, the severity of this finding is considered Medium. PatchesNot yet available. WorkaroundsGatekeeper users can add a webhook which will block the An example policy, preventing virt-handler from changing the node spec may look like this:
and applying this template to node modifications. CreditsSpecial thanks to the discoverers of this issue: Nanzi Yang (nzyang@stu.xidian.edu.cn) Xin Guo (guox@stu.xidian.edu.cn) Jietao Xiao (jietaoXiao@stu.xidian.edu.cn) Wenbo Shen (shenwenbo@zju.edu.cn) Jinku Li (jkli@xidian.edu.cn) Referenceshttps://github.com/kubevirt/kubevirt/issues/9109 References Updated Nov 08, 2023 · Source: OSV.dev |
v0.38.0
minor
Dependencies (69)
+ 61 more |
|
v0.34.1
minor
15 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64437
GO-2025-4102
GHSA-2r4r-5x78-mvqf
Nov 17, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801202148-3ce9f41c54d0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64434
GO-2025-4107
GHSA-ggp9-c99x-54gp
Nov 17, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64433
GO-2025-4109
GHSA-qw6q-3pgr-5cwq
Nov 17, 2025
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801195231-a81b27d4600c
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
GO-2022-1000
GHSA-qv98-3369-g364
Aug 21, 2024
KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt Fixed in
0.55.1
References Updated Mar 13, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2023-26484
GHSA-cp96-jpmq-xrr2
Mar 16, 2023
On a compromised node, the virt-handler service account can be used to modify all node specs
8.2
/ 10
High
Network
High
Low
None
Changed
High
High
None
ImpactIf a malicious user has taken over a Kubernetes node where virt-handler (the KubeVirt node-daemon) is running, the virt-handler service account can be used to modify all node specs. This can be misused to lure-in system-level-privileged components (which can for instance read all secrets on the cluster, or can exec into pods on other nodes). This way a compromised node can be used to elevate privileges beyond the node until potentially having full privileged access to the whole cluster. The simplest way to exploit this, once a user could compromise a specific node, is to set with the virt-handler service account all other nodes to unschedulable and simply wait until system-critical components with high privileges appear on its node. Since this requires a node to be compromised first, the severity of this finding is considered Medium. PatchesNot yet available. WorkaroundsGatekeeper users can add a webhook which will block the An example policy, preventing virt-handler from changing the node spec may look like this:
and applying this template to node modifications. CreditsSpecial thanks to the discoverers of this issue: Nanzi Yang (nzyang@stu.xidian.edu.cn) Xin Guo (guox@stu.xidian.edu.cn) Jietao Xiao (jietaoXiao@stu.xidian.edu.cn) Wenbo Shen (shenwenbo@zju.edu.cn) Jinku Li (jkli@xidian.edu.cn) Referenceshttps://github.com/kubevirt/kubevirt/issues/9109 References Updated Nov 08, 2023 · Source: OSV.dev |
v0.34.1
minor
Dependencies (63)
+ 55 more |
|
v0.33.0-rc.1
pre
15 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64437
GO-2025-4102
GHSA-2r4r-5x78-mvqf
Nov 17, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801202148-3ce9f41c54d0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64434
GO-2025-4107
GHSA-ggp9-c99x-54gp
Nov 17, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64433
GO-2025-4109
GHSA-qw6q-3pgr-5cwq
Nov 17, 2025
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801195231-a81b27d4600c
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
GO-2022-1000
GHSA-qv98-3369-g364
Aug 21, 2024
KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt Fixed in
0.55.1
References Updated Mar 13, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2023-26484
GHSA-cp96-jpmq-xrr2
Mar 16, 2023
On a compromised node, the virt-handler service account can be used to modify all node specs
8.2
/ 10
High
Network
High
Low
None
Changed
High
High
None
ImpactIf a malicious user has taken over a Kubernetes node where virt-handler (the KubeVirt node-daemon) is running, the virt-handler service account can be used to modify all node specs. This can be misused to lure-in system-level-privileged components (which can for instance read all secrets on the cluster, or can exec into pods on other nodes). This way a compromised node can be used to elevate privileges beyond the node until potentially having full privileged access to the whole cluster. The simplest way to exploit this, once a user could compromise a specific node, is to set with the virt-handler service account all other nodes to unschedulable and simply wait until system-critical components with high privileges appear on its node. Since this requires a node to be compromised first, the severity of this finding is considered Medium. PatchesNot yet available. WorkaroundsGatekeeper users can add a webhook which will block the An example policy, preventing virt-handler from changing the node spec may look like this:
and applying this template to node modifications. CreditsSpecial thanks to the discoverers of this issue: Nanzi Yang (nzyang@stu.xidian.edu.cn) Xin Guo (guox@stu.xidian.edu.cn) Jietao Xiao (jietaoXiao@stu.xidian.edu.cn) Wenbo Shen (shenwenbo@zju.edu.cn) Jinku Li (jkli@xidian.edu.cn) Referenceshttps://github.com/kubevirt/kubevirt/issues/9109 References Updated Nov 08, 2023 · Source: OSV.dev |
v0.33.0-rc.1
pre
Dependencies (62)
+ 54 more |
|
v0.30.4
patch
15 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64437
GO-2025-4102
GHSA-2r4r-5x78-mvqf
Nov 17, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801202148-3ce9f41c54d0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64434
GO-2025-4107
GHSA-ggp9-c99x-54gp
Nov 17, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64433
GO-2025-4109
GHSA-qw6q-3pgr-5cwq
Nov 17, 2025
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801195231-a81b27d4600c
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
GO-2022-1000
GHSA-qv98-3369-g364
Aug 21, 2024
KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt Fixed in
0.55.1
References Updated Mar 13, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2023-26484
GHSA-cp96-jpmq-xrr2
Mar 16, 2023
On a compromised node, the virt-handler service account can be used to modify all node specs
8.2
/ 10
High
Network
High
Low
None
Changed
High
High
None
ImpactIf a malicious user has taken over a Kubernetes node where virt-handler (the KubeVirt node-daemon) is running, the virt-handler service account can be used to modify all node specs. This can be misused to lure-in system-level-privileged components (which can for instance read all secrets on the cluster, or can exec into pods on other nodes). This way a compromised node can be used to elevate privileges beyond the node until potentially having full privileged access to the whole cluster. The simplest way to exploit this, once a user could compromise a specific node, is to set with the virt-handler service account all other nodes to unschedulable and simply wait until system-critical components with high privileges appear on its node. Since this requires a node to be compromised first, the severity of this finding is considered Medium. PatchesNot yet available. WorkaroundsGatekeeper users can add a webhook which will block the An example policy, preventing virt-handler from changing the node spec may look like this:
and applying this template to node modifications. CreditsSpecial thanks to the discoverers of this issue: Nanzi Yang (nzyang@stu.xidian.edu.cn) Xin Guo (guox@stu.xidian.edu.cn) Jietao Xiao (jietaoXiao@stu.xidian.edu.cn) Wenbo Shen (shenwenbo@zju.edu.cn) Jinku Li (jkli@xidian.edu.cn) Referenceshttps://github.com/kubevirt/kubevirt/issues/9109 References Updated Nov 08, 2023 · Source: OSV.dev |
v0.30.4
patch
Dependencies (57)
+ 49 more |
|
v0.30.2
patch
15 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64437
GO-2025-4102
GHSA-2r4r-5x78-mvqf
Nov 17, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801202148-3ce9f41c54d0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64434
GO-2025-4107
GHSA-ggp9-c99x-54gp
Nov 17, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64433
GO-2025-4109
GHSA-qw6q-3pgr-5cwq
Nov 17, 2025
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801195231-a81b27d4600c
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
GO-2022-1000
GHSA-qv98-3369-g364
Aug 21, 2024
KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt Fixed in
0.55.1
References Updated Mar 13, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2023-26484
GHSA-cp96-jpmq-xrr2
Mar 16, 2023
On a compromised node, the virt-handler service account can be used to modify all node specs
8.2
/ 10
High
Network
High
Low
None
Changed
High
High
None
ImpactIf a malicious user has taken over a Kubernetes node where virt-handler (the KubeVirt node-daemon) is running, the virt-handler service account can be used to modify all node specs. This can be misused to lure-in system-level-privileged components (which can for instance read all secrets on the cluster, or can exec into pods on other nodes). This way a compromised node can be used to elevate privileges beyond the node until potentially having full privileged access to the whole cluster. The simplest way to exploit this, once a user could compromise a specific node, is to set with the virt-handler service account all other nodes to unschedulable and simply wait until system-critical components with high privileges appear on its node. Since this requires a node to be compromised first, the severity of this finding is considered Medium. PatchesNot yet available. WorkaroundsGatekeeper users can add a webhook which will block the An example policy, preventing virt-handler from changing the node spec may look like this:
and applying this template to node modifications. CreditsSpecial thanks to the discoverers of this issue: Nanzi Yang (nzyang@stu.xidian.edu.cn) Xin Guo (guox@stu.xidian.edu.cn) Jietao Xiao (jietaoXiao@stu.xidian.edu.cn) Wenbo Shen (shenwenbo@zju.edu.cn) Jinku Li (jkli@xidian.edu.cn) Referenceshttps://github.com/kubevirt/kubevirt/issues/9109 References Updated Nov 08, 2023 · Source: OSV.dev |
v0.30.2
patch
Dependencies (57)
+ 49 more |
|
v0.30.1
patch
15 CVEs
CVE-2026-9804
GO-2026-5883
GHSA-mpmf-3w4r-qfpf
Jul 07, 2026
KubeVirt has a Link Following issue in kubevirt.io/kubevirt KubeVirt has a Link Following issue in kubevirt.io/kubevirt References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-7374
GO-2026-5848
GHSA-7jcp-v9w4-wjmg
Jul 07, 2026
KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt Fixed in
1.6.6
1.7.4
1.8.3
References Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-6383
GO-2026-5450
GHSA-j6cv-3w8p-vrg8
Jun 25, 2026
KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt References Updated Jun 26, 2026 · Source: OSV.dev
CVE-2025-14525
GO-2026-4384
GHSA-25mh-hp8x-cgrv
Feb 02, 2026
KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64437
GO-2025-4102
GHSA-2r4r-5x78-mvqf
Nov 17, 2025
KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801202148-3ce9f41c54d0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64434
GO-2025-4107
GHSA-ggp9-c99x-54gp
Nov 17, 2025
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64432
GO-2025-4103
GHSA-38jw-g2qx-4286
Nov 17, 2025
KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250730135146-231dc69723f3
1.6.1
1.7.0-rc.0
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64433
GO-2025-4109
GHSA-qw6q-3pgr-5cwq
Nov 17, 2025
KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt Fixed in
1.5.3
1.6.0-beta.0.0.20250801195231-a81b27d4600c
1.6.1
References
Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64435
GO-2025-4105
GHSA-9m94-w2vq-hcf9
Nov 17, 2025
KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt Fixed in
1.7.0-beta.0
References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2025-64324
GO-2025-4110
GHSA-46xp-26xh-hpqh
Nov 17, 2025
KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt Fixed in
1.6.1
1.7.0-rc.0
References Updated Mar 25, 2026 · Source: OSV.dev
CVE-2025-64436
GHSA-7xgm-5prm-v5gc
GO-2025-4104
Nov 06, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Medium
Network
Low
None
None
SummaryThe permissions granted to the DetailsFollowing the GitHub security advisory published on March 23 2023, a However, if a Another finding describes how a compromised Additionally, by default, the PoCBy injecting incorrect data into a running VMI, for example, by altering the
The VMI is then created on a minikube node identified with
Assume that a First, we retrieve the
The attacker updates the VMI object labels in a way that makes it terminate:
Now, the attacker can use the excessive permissions of the
Note: This request could require multiple invocations as the Finally, an admin user decides to restart the VMI:
Identifying the origin node of a request is not a straightforward task. One potential solution is to embed additional authentication data, such as the An alternative approach would be to create a dedicated ImpactThis vulnerability could otherwise allow an attacker to mark all nodes as unschedulable, potentially forcing the migration or creation of privileged pods onto a compromised node. Fixed in
1.7.0
References Updated Sep 10, 2026 · Source: OSV.dev
GO-2022-1000
GHSA-qv98-3369-g364
Aug 21, 2024
KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt Fixed in
0.55.1
References Updated Mar 13, 2026 · Source: OSV.dev
CVE-2024-31420
GO-2024-2688
GHSA-vjhf-6xfr-5p9g
Jun 05, 2024
KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2024-33394
GO-2024-2816
GHSA-4q63-mr2m-57hf
Jun 05, 2024
kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt References Updated Jun 20, 2026 · Source: OSV.dev
CVE-2023-26484
GHSA-cp96-jpmq-xrr2
Mar 16, 2023
On a compromised node, the virt-handler service account can be used to modify all node specs
8.2
/ 10
High
Network
High
Low
None
Changed
High
High
None
ImpactIf a malicious user has taken over a Kubernetes node where virt-handler (the KubeVirt node-daemon) is running, the virt-handler service account can be used to modify all node specs. This can be misused to lure-in system-level-privileged components (which can for instance read all secrets on the cluster, or can exec into pods on other nodes). This way a compromised node can be used to elevate privileges beyond the node until potentially having full privileged access to the whole cluster. The simplest way to exploit this, once a user could compromise a specific node, is to set with the virt-handler service account all other nodes to unschedulable and simply wait until system-critical components with high privileges appear on its node. Since this requires a node to be compromised first, the severity of this finding is considered Medium. PatchesNot yet available. WorkaroundsGatekeeper users can add a webhook which will block the An example policy, preventing virt-handler from changing the node spec may look like this:
and applying this template to node modifications. CreditsSpecial thanks to the discoverers of this issue: Nanzi Yang (nzyang@stu.xidian.edu.cn) Xin Guo (guox@stu.xidian.edu.cn) Jietao Xiao (jietaoXiao@stu.xidian.edu.cn) Wenbo Shen (shenwenbo@zju.edu.cn) Jinku Li (jkli@xidian.edu.cn) Referenceshttps://github.com/kubevirt/kubevirt/issues/9109 References Updated Nov 08, 2023 · Source: OSV.dev |
v0.30.1
patch
Dependencies (57)
+ 49 more |