Launch Week Day 1: Announcing Security Design Review
go

k8s.io/kubernetes

View on go registry
88 Total advisories
88 Vulnerabilities
0 Malware

Vulnerabilities

LOW 3.1
Go

CVE-2020-8562

Potential proxy IP restriction bypass in Kubernetes

MEDIUM 5.0
Go

CVE-2020-8554

Unverified Ownership in Kubernetes

LOW 3.1
Go

CVE-2021-25740

Confused Deputy in Kubernetes

MEDIUM 4.1
Go

CVE-2020-8561

Confused Deputy in Kubernetes

UNKNOWN
Go

CVE-2019-11243

Kubernetes did not effectively clear service account credentials in k8s.io/kubernetes

UNKNOWN
Go

CVE-2024-7598

Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes

UNKNOWN
Go

CVE-2020-8563

Sensitive Information leak for VSphere users via Log File in k8s.io/kubernetes

UNKNOWN
Go

CVE-2020-8566

Sensitive Information leak for users of Ceph RBD via Log File in k8s.io/kubernetes

UNKNOWN
Go

CVE-2019-11245

Kubelet Incorrect Privilege Assignment in k8s.io/kubernetes

UNKNOWN
Go

CVE-2017-1002102

Kubernetes can trigger deletion of arbitrary files from the nodes where containers are running in k8s.io/kubernetes

UNKNOWN
Go

CVE-2018-1002100

Kubernetes arbitrary file overwrite in k8s.io/kubernetes

UNKNOWN
Go

CVE-2022-3162

Kubernetes vulnerable to path traversal in k8s.io/kubernetes

UNKNOWN
Go

CVE-2017-1000056

Kubernetes Privilege Escalation in k8s.io/kubernetes

UNKNOWN
Go

CVE-2021-25737

Incomplete List of Disallowed Inputs in Kubernetes in k8s.io/kubernetes

UNKNOWN
Go

CVE-2020-8557

Denial of service in Kubernetes in k8s.io/kubernetes

UNKNOWN
Go

CVE-2022-3294

Kubernetes vulnerable to validation bypass in k8s.io/kubernetes

UNKNOWN
Go

CVE-2019-11251

Kubernetes kubectl cp Vulnerable to Symlink Attack in k8s.io/kubernetes

HIGH 7.5
Go

CVE-2019-11253

XML Entity Expansion and Improper Input Validation in Kubernetes API server

UNKNOWN
Go

CVE-2020-8551

Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes in k8s.io/kubernetes

UNKNOWN
Go

CVE-2019-1002101

Symlink Attack in kubectl cp in k8s.io/kubernetes

MEDIUM 5.8
Go

CVE-2025-13281

kube-controller-manager is vulnerable to half-blind Server Side Request Forgery through in-tree Portworx StorageClass

HIGH 8.8
Go

CVE-2023-3955

Kubernetes privilege escalation vulnerability

UNKNOWN
Go

CVE-2021-25743

ANSI escape characters not filtered in kubectl in k8s.io/kubernetes

MEDIUM 6.5
Go

CVE-2019-1002100

Kubernetes DoS Vulnerability

MEDIUM 6.3
Go

CVE-2020-8555

Server Side Request Forgery (SSRF) in Kubernetes

MEDIUM 4.3
Go

CVE-2020-8551

Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes

UNKNOWN
Go

CVE-2023-3676

Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes

UNKNOWN
Go

CVE-2025-0426

Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes

MEDIUM 6.5
Go

CVE-2021-25735

Access Restriction Bypass in kube-apiserver

UNKNOWN
Go

CVE-2021-25735

Access Restriction Bypass in kube-apiserver in k8s.io/kubernetes

UNKNOWN
Go

CVE-2020-8559

Privilege Escalation in Kubernetes in k8s.io/apimachinery

MEDIUM 4.4
Go

CVE-2023-2431

Kubelet vulnerable to bypass of seccomp profile enforcement

UNKNOWN
Go

CVE-2020-8562

WITHDRAWN: Potential proxy IP restriction bypass in Kubernetes in k8s.io/kubernetes

UNKNOWN
Go

CVE-2025-5187

Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes

UNKNOWN
Go

CVE-2020-8555

Server Side Request Forgery (SSRF) in Kubernetes in k8s.io/kubernetes

UNKNOWN
Go

CVE-2024-3177

Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes

UNKNOWN
Go

CVE-2020-8564

Sensitive information leak via log file in k8s.io/kubernetes

MEDIUM 6.5
Go

CVE-2025-1767

Kubernetes GitRepo Volume Inadvertent Local Repository Access

HIGH 8.8
Go

CVE-2023-5528

Kubernetes Improper Input Validation vulnerability

MEDIUM 6.5
Go

CVE-2019-11250

Kubernetes client-go library logs may disclose credentials to unauthorized users

UNKNOWN
Go

CVE-2023-2727

Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes

UNKNOWN
Go

CVE-2021-25736

Kube-proxy may unintentionally forward traffic in k8s.io/kubernetes

MEDIUM 5.8
Go

CVE-2021-25736

Kube-proxy may unintentionally forward traffic

UNKNOWN
Go

CVE-2024-0793

Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes

MEDIUM 4.7
Go

CVE-2020-8565

Kubernetes client-go vulnerable to Sensitive Information Leak via Log File

MEDIUM 6.5
Go

CVE-2023-2728

Kubernetes mountable secrets policy bypass

UNKNOWN
Go

CVE-2023-3955

Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes and k8s.io/mount-utils

MEDIUM 5.5
Go

CVE-2019-1002101

Symlink Attack in kubectl cp

UNKNOWN
Go

CVE-2018-1002101

Kubernetes Arbitrary Command Injection in k8s.io/kubernetes

MEDIUM 6.8
Go

CVE-2020-8559

Privilege Escalation in Kubernetes

LOW 3.1
Go

CVE-2015-7561

Kubernetes in OpenShift3 Access Control Misconfiguration

MEDIUM 6.7
Go

CVE-2025-5187

Kubernetes Nodes can delete themselves by adding an OwnerReference

MEDIUM 6.2
Go

CVE-2025-0426

Node Denial of Service via kubelet Checkpoint API

UNKNOWN
Go

CVE-2021-25741

Files or Directories Accessible to External Parties in kubernetes in k8s.io/kubernetes

UNKNOWN
Go

CVE-2025-13281

Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes

UNKNOWN
Go

CVE-2023-2431

Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes

MEDIUM 5.9
Go

CVE-2024-9042

Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API

UNKNOWN
Go

CVE-2020-8558

Improper Authentication in Kubernetes in k8s.io/kubernetes

UNKNOWN
Go

CVE-2024-9042

Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes

LOW 2.7
Go

CVE-2025-4563

kubernetes allows nodes to bypass dynamic resource allocation authorization checks

LOW 2.7
Go

CVE-2024-3177

Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin

UNKNOWN
Go

CVE-2025-1767

Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes

MEDIUM 6.1
Go

CVE-2024-5321

Kubernetes sets incorrect permissions on Windows containers logs

HIGH 7.7
Go

CVE-2024-0793

Kubernetes Nil pointer dereference in KCM after v1 HPA patch request

MEDIUM 4.7
Go

CVE-2020-8564

Kubernetes Sensitive Information leak via Log File

UNKNOWN
Go

CVE-2019-1002100

Kubernetes DoS Vulnerability in k8s.io/kubernetes

UNKNOWN
Go

CVE-2025-4563

Kubernetes allows nodes to bypass dynamic resource allocation authorization checks in k8s.io/kubernetes

MEDIUM 6.5
Go

CVE-2023-2727

kube-apiserver vulnerable to policy bypass

HIGH 8.1
Go

CVE-2024-10220

Kubernetes kubelet arbitrary command execution

HIGH 8.8
Go

CVE-2023-3676

Kubernetes privilege escalation vulnerability

MEDIUM 5.9
Go

CVE-2018-1002101

Kubernetes Arbitrary Command Injection

UNKNOWN
Go

CVE-2023-5528

Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes

LOW 3.0
Go

CVE-2021-25743

kubectl ANSI escape characters not filtered

UNKNOWN
Go

CVE-2019-11253

XML Entity Expansion and Improper Input Validation in Kubernetes API server in k8s.io/kubernetes

UNKNOWN
Go

CVE-2023-2728

Kubernetes mountable secrets policy bypass in k8s.io/kubernetes

UNKNOWN
Go

CVE-2024-10220

Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes

HIGH 8.1
Go

CVE-2021-25741

Files or Directories Accessible to External Parties in kubernetes

UNKNOWN
Go

CVE-2024-5321

Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes

UNKNOWN
Go

CVE-2015-7561

Kubernetes in OpenShift3 Access Control Misconfiguration in k8s.io/kubernetes

HIGH 8.8
Go

CVE-2020-8558

Improper Authentication in Kubernetes

MEDIUM 5.5
Go

CVE-2018-1002100

Kubernetes arbitrary file overwrite

HIGH 8.1
Go

CVE-2019-11243

Kubernetes did not effectively clear service account credentials

MEDIUM 5.7
Go

CVE-2019-11251

Kubernetes kubectl cp Vulnerable to Symlink Attack

MEDIUM 4.8
Go

CVE-2021-25737

Incomplete List of Disallowed Inputs in Kubernetes

CRITICAL 9.8
Go

CVE-2017-1000056

Kubernetes Privilege Escalation

MEDIUM 5.6
Go

CVE-2017-1002102

Kubernetes arbitrary file overwrite

UNKNOWN
Go

CVE-2015-5305

Directory traversal in k8s.io/kubernetes

MEDIUM 6.5
Go

CVE-2015-5305

Directory Traversal in Kubernetes

Ready to move

Start Securing

Free, no credit card | First findings in minutes