Skip to main content

Vendor archive

kubernetes CVEs

Beta · best-effort

98 CVEs tagged to vendor kubernetes8 Critical, 37 High, 46 Medium, 7 Low, 0 Unrated.

CVE-2026-4342

Published Mar 19, 2026

A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can lead to arbitrary code executi…

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-3288

Published Mar 9, 2026

A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject configuration into nginx. This can…

CVSS 8.8 · High
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2022-3172

Published Nov 3, 2023

A security issue was discovered in kube-apiserver that allows an aggregated API server to redirect client traffic to any URL. This could lead to the client performing unexpecte…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-3893

Published Nov 3, 2023

A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes running kubernetes-csi-proxy may be able to escalate to admin privileges on thos…

CVSS 8.8 · High
evidence mentions
5
Buzz score
27.4
Vendor/product tagsBeta · best-effort

CVE-2023-3955

Published Oct 31, 2023

A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters…

CVSS 8.8 · High
evidence mentions
5
Buzz score
27.4
Vendor/product tagsBeta · best-effort

CVE-2023-3676

Published Oct 31, 2023

A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters…

CVSS 8.8 · High
evidence mentions
6
Buzz score
29.0
Vendor/product tagsBeta · best-effort

CVE-2021-25736

Published Oct 30, 2023

Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (“spec.ports[*].port”) as a LoadBalancer Service when the LoadBalancer c…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-4318

Published Sep 25, 2023

A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.

CVSS 7.8 · High

CVE-2023-2728

Published Jul 3, 2023

Users may be able to launch containers that bypass the mountable secrets policy enforced by the ServiceAccount admission plugin when using ephemeral containers. The policy ensures…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2727

Published Jul 3, 2023

Users may be able to launch containers using images that are restricted by ImagePolicyWebhook when using ephemeral containers. Kubernetes clusters are only affected if the ImagePo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 98 CVEsPage 1 of 4