Catalog / Kubernetes

Kubernetes security advisories

All 91 advisories Kubernetes has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.

Advisories
9191 carry a CVE
critical
1
high
9
medium
11
low
3
Fix in the archive
0of 91 matched to a release
Oldest
21 Mar 20179.5 years ago

91 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.

Newest first

Every product
CVE-2026-3865medium

CSI Driver for SMB path traversal via subDir may delete unintended directories on the SMB server

CVE-2026-4342

ingress-nginx comment-based nginx configuration injection

CVE-2026-3864medium

CSI Driver for NFS path traversal via subDir may delete unintended directories on the NFS server

CVE-2026-3288

ingress-nginx rewrite-target nginx configuration injection

CVE-2025-15566

ingress-nginx auth-proxy-set-headers nginx configuration injection

CVE-2026-1580

ingress-nginx auth-method nginx configuration injection

CVE-2026-24512

ingress-nginx rules.http.paths.path nginx configuration injection

CVE-2026-24514

ingress-nginx Admission Controller denial of service

CVE-2025-14269high

Credential caching in Headlamp with Helm enabled

CVE-2025-13281medium

Portworx Half-Blind SSRF in kube-controller-manager

CVE-2025-9708medium

Kubernetes C# Client: improper certificate validation in custom CA mode may lead to man-in-the-middle attacks

CVE-2025-7445

secrets-store-sync-controller discloses service account tokens in logs

CVE-2025-5187medium

Nodes can delete themselves by adding an OwnerReference

CVE-2025-7342high

VM images built with Kubernetes Image Builder Nutanix or OVA providers use default credentials for Windows images if user did not override

CVE-2025-4563low

Nodes can bypass dynamic resource allocation authorization checks

CVE-2025-24513medium

ingress-nginx controller auth secret file path traversal vulnerability

CVE-2025-24514high

ingress-nginx controller configuration injection via unsanitized auth-url annotation

CVE-2025-1097high

ingress-nginx controller configuration injection via unsanitized auth-tls-match-cn annotation

CVE-2025-1098high

ingress-nginx controller configuration injection via unsanitized mirror annotations

CVE-2025-1974critical

ingress-nginx admission controller RCE escalation

CVE-2025-1767

GitRepo Volume Inadvertent Local Repository Access

CVE-2025-0426

Node Denial of Service via kubelet Checkpoint API

CVE-2024-9042

Command Injection affecting Windows nodes via nodes/*/logs/query API

CVE-2024-10220

Arbitrary command execution through gitRepo volume

CVE-2024-9486

VM images built with Image Builder and Proxmox provider use default credentials

CVE-2024-9594

VM images built with Image Builder with some providers use default credentials during builds

CVE-2024-7646

Ingress-nginx Annotation Validation Bypass

CVE-2024-7598low

Network restriction bypass via race condition during namespace termination

CVE-2024-5321medium

Incorrect permissions on Windows containers logs

CVE-2024-3744medium

azure-file-csi-driver discloses service account tokens in logs

CVE-2024-3177low

Bypassing mountable secrets policy imposed by the ServiceAccount admission plugin

CVE-2023-5528high

Insufficient input sanitization in in-tree storage plugin leads to privilege escalation on Windows nodes

CVE-2022-4886

ingress-nginx path sanitization can be bypassed

CVE-2023-5043

Ingress nginx annotation injection causes arbitrary command execution

CVE-2023-5044

Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation

CVE-2023-3893high

Insufficient input sanitization on kubernetes-csi-proxy leads to privilege escalation

CVE-2023-3955high

Insufficient input sanitization on Windows nodes leads to privilege escalation

CVE-2023-3676high

Insufficient input sanitization on Windows nodes leads to privilege escalation

CVE-2023-2727

Bypassing policies imposed by the ImagePolicyWebhook and bypassing mountable secrets policy imposed by the ServiceAccount admission plugin

CVE-2023-2728

Bypassing policies imposed by the ImagePolicyWebhook and bypassing mountable secrets policy imposed by the ServiceAccount admission plugin

CVE-2023-2878

secrets-store-csi-driver discloses service account tokens in logs

CVE-2022-3294

Node address isn't always verified when proxying

CVE-2022-3172

Aggregated API server can cause clients to be redirected (SSRF)

CVE-2021-25749

`runAsNonRoot` logic bypass for Windows containers

CVE-2021-25748

Ingress-nginx `path` sanitization can be bypassed with newline character

CVE-2021-25745

Ingress-nginx `path` can be pointed to service account token file

CVE-2021-25746

Ingress-nginx directive injection via annotations

CVE-2021-25742

Ingress-nginx custom snippets allows retrieval of ingress-nginx serviceaccount token and secrets across all namespaces

CVE-2021-25741

Symlink Exchange Can Allow Host Filesystem Access

CVE-2021-25740

Endpoint & EndpointSlice permissions allow cross-Namespace forwarding

CVE-2021-25737

Holes in EndpointSlice Validation Enable Host Network Hijack

CVE-2020-8562

Bypass of Kubernetes API Server proxy TOCTOU

CVE-2021-3121

Processes may panic upon receipt of malicious protobuf messages

CVE-2021-25735

Validating Admission Webhook does not observe some previous fields

CVE-2020-8554

Man in the middle using LoadBalancer or ExternalIPs

CVE-2020-8563

Secret leaks in kube-controller-manager when using vSphere provider

CVE-2020-8564

Docker config secrets leaked when file is malformed and log level >= 4

CVE-2020-8565

Incomplete fix for CVE-2019-11250 allows for token leak in logs when logLevel >= 9

CVE-2020-8566

Ceph RBD adminSecrets exposed in logs when loglevel >= 4

CVE-2020-8557medium

Node disk DOS by writing to container /etc/hosts

CVE-2020-8559medium

Privilege escalation from compromised node to cluster

CVE-2020-8558medium

Node setting allows for neighboring hosts to bypass localhost boundary

CVE-2020-8555

Half-Blind SSRF in kube-controller-manager

CVE-2020-10749

IPv4 only clusters susceptible to MitM attacks via IPv6 rogue router advertisements

CVE-2019-11254

kube-apiserver Denial of Service vulnerability from malicious YAML payloads

CVE-2020-8553

ingress-nginx auth-type basic annotation vulnerability

CVE-2019-11255

CSI volume snapshot, cloning and resizing features can result in unauthorized volume data access or mutation

CVE-2019-11253

Kubernetes API Server JSON/YAML parsing vulnerable to resource exhaustion attack

CVE-2019-11250

Bearer tokens are revealed in logs (audit finding TOB-K8S-001)

CVE-2019-11248

/debug/pprof exposed on kubelet's healthz port

CVE-2019-11247

API server allows access to custom resources via wrong scope

CVE-2019-11249

Incomplete fixes for CVE-2019-1002101 and CVE-2019-11246, kubectl cp potential directory traversal

CVE-2019-11245

container uid changes to root after first restart or if image is already pulled to the node

CVE-2019-11243

rest.AnonymousClientConfig() does not remove the serviceaccount credentials from config created by rest.InClusterConfig()

CVE-2019-11244

`kubectl --http-cache=<world-accessible dir>` creates world-writeable cached schema files

CVE-2018-1002105

proxy request handling in kube-apiserver can leave vulnerable TCP connections

CVE-2018-1002100

Kubectl copy doesn't check for paths outside of it's destination directory.

CVE-2017-1002101

subpath volume mount handling allows arbitrary file access in host filesystem

CVE-2017-1002102

atomic writer volume handling allows arbitrary file deletion in host filesystem

CVE-2017-1000056

PodSecurityPolicy admission plugin authorizes incorrectly