Dependency scanning
Check whether k8s.io/kubernetes is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2025-13281
kube-controller-manager is vulnerable to half-blind Server Side Request Forgery through in-tree Portworx StorageClass
CVE-2025-1767
Kubernetes GitRepo Volume Inadvertent Local Repository Access
CVE-2025-5187
Kubernetes Nodes can delete themselves by adding an OwnerReference
CVE-2025-4563
kubernetes allows nodes to bypass dynamic resource allocation authorization checks
CVE-2024-9042
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API
CVE-2025-0426
Node Denial of Service via kubelet Checkpoint API
CVE-2024-0793
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request
CVE-2024-10220
Kubernetes kubelet arbitrary command execution
CVE-2024-5321
Kubernetes sets incorrect permissions on Windows containers logs
CVE-2024-3177
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin
CVE-2020-8559
Privilege Escalation in Kubernetes
CVE-2023-3955
Kubernetes privilege escalation vulnerability
CVE-2021-25736
Kube-proxy may unintentionally forward traffic
CVE-2023-2727
kube-apiserver vulnerable to policy bypass
CVE-2023-5528
Kubernetes Improper Input Validation vulnerability
CVE-2023-3676
Kubernetes privilege escalation vulnerability
CVE-2023-2728
Kubernetes mountable secrets policy bypass
CVE-2023-2431
Kubelet vulnerable to bypass of seccomp profile enforcement
CVE-2020-8564
Kubernetes Sensitive Information leak via Log File
CVE-2020-8565
Kubernetes client-go vulnerable to Sensitive Information Leak via Log File
CVE-2015-7561
Kubernetes in OpenShift3 Access Control Misconfiguration
CVE-2019-11250
Kubernetes client-go library logs may disclose credentials to unauthorized users
CVE-2019-1002100
Kubernetes DoS Vulnerability
CVE-2020-8554
Unverified Ownership in Kubernetes
CVE-2021-25735
Access Restriction Bypass in kube-apiserver
CVE-2020-8562
Potential proxy IP restriction bypass in Kubernetes
CVE-2019-1002101
Symlink Attack in kubectl cp
CVE-2018-1002101
Kubernetes Arbitrary Command Injection
CVE-2020-8555
Server Side Request Forgery (SSRF) in Kubernetes
CVE-2020-8558
Improper Authentication in Kubernetes
CVE-2021-25743
kubectl ANSI escape characters not filtered
CVE-2021-25741
Files or Directories Accessible to External Parties in kubernetes
CVE-2021-25740
Confused Deputy in Kubernetes
CVE-2020-8561
Confused Deputy in Kubernetes
CVE-2019-11253
XML Entity Expansion and Improper Input Validation in Kubernetes API server
CVE-2020-8551
Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes in k8s.io/kubernetes
CVE-2020-8551
Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes
CVE-2024-7598
Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes
CVE-2019-11243
Kubernetes did not effectively clear service account credentials in k8s.io/kubernetes
CVE-2020-8563
Sensitive Information leak for VSphere users via Log File in k8s.io/kubernetes
CVE-2020-8566
Sensitive Information leak for users of Ceph RBD via Log File in k8s.io/kubernetes
CVE-2019-11245
Kubelet Incorrect Privilege Assignment in k8s.io/kubernetes
CVE-2017-1002102
Kubernetes can trigger deletion of arbitrary files from the nodes where containers are running in k8s.io/kubernetes
CVE-2018-1002100
Kubernetes arbitrary file overwrite in k8s.io/kubernetes
CVE-2022-3162
Kubernetes vulnerable to path traversal in k8s.io/kubernetes
CVE-2017-1000056
Kubernetes Privilege Escalation in k8s.io/kubernetes
CVE-2021-25737
Incomplete List of Disallowed Inputs in Kubernetes in k8s.io/kubernetes
CVE-2020-8557
Denial of service in Kubernetes in k8s.io/kubernetes
CVE-2022-3294
Kubernetes vulnerable to validation bypass in k8s.io/kubernetes
CVE-2019-11251
Kubernetes kubectl cp Vulnerable to Symlink Attack in k8s.io/kubernetes
CVE-2019-1002101
Symlink Attack in kubectl cp in k8s.io/kubernetes
CVE-2021-25743
ANSI escape characters not filtered in kubectl in k8s.io/kubernetes
CVE-2023-3676
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes
CVE-2025-0426
Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes
CVE-2021-25735
Access Restriction Bypass in kube-apiserver in k8s.io/kubernetes
CVE-2020-8559
Privilege Escalation in Kubernetes in k8s.io/apimachinery
CVE-2020-8562
WITHDRAWN: Potential proxy IP restriction bypass in Kubernetes in k8s.io/kubernetes
CVE-2025-5187
Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes
CVE-2020-8555
Server Side Request Forgery (SSRF) in Kubernetes in k8s.io/kubernetes
CVE-2024-3177
Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes
CVE-2020-8564
Sensitive information leak via log file in k8s.io/kubernetes
CVE-2023-2727
Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes
CVE-2021-25736
Kube-proxy may unintentionally forward traffic in k8s.io/kubernetes
CVE-2024-0793
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes
CVE-2023-3955
Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes and k8s.io/mount-utils
CVE-2018-1002101
Kubernetes Arbitrary Command Injection in k8s.io/kubernetes
CVE-2021-25741
Files or Directories Accessible to External Parties in kubernetes in k8s.io/kubernetes
CVE-2025-13281
Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes
CVE-2023-2431
Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes
CVE-2020-8558
Improper Authentication in Kubernetes in k8s.io/kubernetes
CVE-2024-9042
Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes
CVE-2025-1767
Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes
CVE-2019-1002100
Kubernetes DoS Vulnerability in k8s.io/kubernetes
CVE-2025-4563
Kubernetes allows nodes to bypass dynamic resource allocation authorization checks in k8s.io/kubernetes
CVE-2023-5528
Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes
CVE-2019-11253
XML Entity Expansion and Improper Input Validation in Kubernetes API server in k8s.io/kubernetes
CVE-2023-2728
Kubernetes mountable secrets policy bypass in k8s.io/kubernetes
CVE-2024-10220
Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes
CVE-2024-5321
Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes
CVE-2015-7561
Kubernetes in OpenShift3 Access Control Misconfiguration in k8s.io/kubernetes
CVE-2018-1002100
Kubernetes arbitrary file overwrite
CVE-2019-11243
Kubernetes did not effectively clear service account credentials
CVE-2019-11251
Kubernetes kubectl cp Vulnerable to Symlink Attack
CVE-2021-25737
Incomplete List of Disallowed Inputs in Kubernetes
CVE-2017-1000056
Kubernetes Privilege Escalation
CVE-2017-1002102
Kubernetes arbitrary file overwrite
CVE-2015-5305
Directory traversal in k8s.io/kubernetes
CVE-2015-5305
Directory Traversal in Kubernetes
Browse more Go advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes