go

k8s.io/kubernetes

View on go registry
88 Total advisories
88 Vulnerabilities
0 Malware

Dependency scanning

Check whether k8s.io/kubernetes is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 5.8
Go

CVE-2025-13281

kube-controller-manager is vulnerable to half-blind Server Side Request Forgery through in-tree Portworx StorageClass

MEDIUM 6.5
Go

CVE-2025-1767

Kubernetes GitRepo Volume Inadvertent Local Repository Access

MEDIUM 6.7
Go

CVE-2025-5187

Kubernetes Nodes can delete themselves by adding an OwnerReference

LOW 2.7
Go

CVE-2025-4563

kubernetes allows nodes to bypass dynamic resource allocation authorization checks

MEDIUM 5.9
Go

CVE-2024-9042

Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API

MEDIUM 6.2
Go

CVE-2025-0426

Node Denial of Service via kubelet Checkpoint API

HIGH 7.7
Go

CVE-2024-0793

Kubernetes Nil pointer dereference in KCM after v1 HPA patch request

HIGH 8.1
Go

CVE-2024-10220

Kubernetes kubelet arbitrary command execution

MEDIUM 6.1
Go

CVE-2024-5321

Kubernetes sets incorrect permissions on Windows containers logs

LOW 2.7
Go

CVE-2024-3177

Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin

MEDIUM 6.8
Go

CVE-2020-8559

Privilege Escalation in Kubernetes

HIGH 8.8
Go

CVE-2023-3955

Kubernetes privilege escalation vulnerability

MEDIUM 5.8
Go

CVE-2021-25736

Kube-proxy may unintentionally forward traffic

MEDIUM 6.5
Go

CVE-2023-2727

kube-apiserver vulnerable to policy bypass

HIGH 8.8
Go

CVE-2023-5528

Kubernetes Improper Input Validation vulnerability

HIGH 8.8
Go

CVE-2023-3676

Kubernetes privilege escalation vulnerability

MEDIUM 6.5
Go

CVE-2023-2728

Kubernetes mountable secrets policy bypass

MEDIUM 4.4
Go

CVE-2023-2431

Kubelet vulnerable to bypass of seccomp profile enforcement

MEDIUM 4.7
Go

CVE-2020-8564

Kubernetes Sensitive Information leak via Log File

MEDIUM 4.7
Go

CVE-2020-8565

Kubernetes client-go vulnerable to Sensitive Information Leak via Log File

LOW 3.1
Go

CVE-2015-7561

Kubernetes in OpenShift3 Access Control Misconfiguration

MEDIUM 6.5
Go

CVE-2019-11250

Kubernetes client-go library logs may disclose credentials to unauthorized users

MEDIUM 6.5
Go

CVE-2019-1002100

Kubernetes DoS Vulnerability

MEDIUM 5.0
Go

CVE-2020-8554

Unverified Ownership in Kubernetes

MEDIUM 6.5
Go

CVE-2021-25735

Access Restriction Bypass in kube-apiserver

LOW 3.1
Go

CVE-2020-8562

Potential proxy IP restriction bypass in Kubernetes

MEDIUM 5.5
Go

CVE-2019-1002101

Symlink Attack in kubectl cp

MEDIUM 5.9
Go

CVE-2018-1002101

Kubernetes Arbitrary Command Injection

MEDIUM 6.3
Go

CVE-2020-8555

Server Side Request Forgery (SSRF) in Kubernetes

HIGH 8.8
Go

CVE-2020-8558

Improper Authentication in Kubernetes

LOW 3.0
Go

CVE-2021-25743

kubectl ANSI escape characters not filtered

HIGH 8.1
Go

CVE-2021-25741

Files or Directories Accessible to External Parties in kubernetes

LOW 3.1
Go

CVE-2021-25740

Confused Deputy in Kubernetes

MEDIUM 4.1
Go

CVE-2020-8561

Confused Deputy in Kubernetes

HIGH 7.5
Go

CVE-2019-11253

XML Entity Expansion and Improper Input Validation in Kubernetes API server

UNKNOWN
Go

CVE-2020-8551

Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes in k8s.io/kubernetes

MEDIUM 4.3
Go

CVE-2020-8551

Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes

UNKNOWN
Go

CVE-2024-7598

Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes

UNKNOWN
Go

CVE-2019-11243

Kubernetes did not effectively clear service account credentials in k8s.io/kubernetes

UNKNOWN
Go

CVE-2020-8563

Sensitive Information leak for VSphere users via Log File in k8s.io/kubernetes

UNKNOWN
Go

CVE-2020-8566

Sensitive Information leak for users of Ceph RBD via Log File in k8s.io/kubernetes

UNKNOWN
Go

CVE-2019-11245

Kubelet Incorrect Privilege Assignment in k8s.io/kubernetes

UNKNOWN
Go

CVE-2017-1002102

Kubernetes can trigger deletion of arbitrary files from the nodes where containers are running in k8s.io/kubernetes

UNKNOWN
Go

CVE-2018-1002100

Kubernetes arbitrary file overwrite in k8s.io/kubernetes

UNKNOWN
Go

CVE-2022-3162

Kubernetes vulnerable to path traversal in k8s.io/kubernetes

UNKNOWN
Go

CVE-2017-1000056

Kubernetes Privilege Escalation in k8s.io/kubernetes

UNKNOWN
Go

CVE-2021-25737

Incomplete List of Disallowed Inputs in Kubernetes in k8s.io/kubernetes

UNKNOWN
Go

CVE-2020-8557

Denial of service in Kubernetes in k8s.io/kubernetes

UNKNOWN
Go

CVE-2022-3294

Kubernetes vulnerable to validation bypass in k8s.io/kubernetes

UNKNOWN
Go

CVE-2019-11251

Kubernetes kubectl cp Vulnerable to Symlink Attack in k8s.io/kubernetes

UNKNOWN
Go

CVE-2019-1002101

Symlink Attack in kubectl cp in k8s.io/kubernetes

UNKNOWN
Go

CVE-2021-25743

ANSI escape characters not filtered in kubectl in k8s.io/kubernetes

UNKNOWN
Go

CVE-2023-3676

Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes

UNKNOWN
Go

CVE-2025-0426

Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes

UNKNOWN
Go

CVE-2021-25735

Access Restriction Bypass in kube-apiserver in k8s.io/kubernetes

UNKNOWN
Go

CVE-2020-8559

Privilege Escalation in Kubernetes in k8s.io/apimachinery

UNKNOWN
Go

CVE-2020-8562

WITHDRAWN: Potential proxy IP restriction bypass in Kubernetes in k8s.io/kubernetes

UNKNOWN
Go

CVE-2025-5187

Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes

UNKNOWN
Go

CVE-2020-8555

Server Side Request Forgery (SSRF) in Kubernetes in k8s.io/kubernetes

UNKNOWN
Go

CVE-2024-3177

Kubernetes allows bypassing mountable secrets policy imposed by the ServiceAccount admission plugin in k8s.io/kubernetes

UNKNOWN
Go

CVE-2020-8564

Sensitive information leak via log file in k8s.io/kubernetes

UNKNOWN
Go

CVE-2023-2727

Vulnerable to policy bypass in kube-apiserver in k8s.io/kubernetes

UNKNOWN
Go

CVE-2021-25736

Kube-proxy may unintentionally forward traffic in k8s.io/kubernetes

UNKNOWN
Go

CVE-2024-0793

Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes

UNKNOWN
Go

CVE-2023-3955

Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes and k8s.io/mount-utils

UNKNOWN
Go

CVE-2018-1002101

Kubernetes Arbitrary Command Injection in k8s.io/kubernetes

UNKNOWN
Go

CVE-2021-25741

Files or Directories Accessible to External Parties in kubernetes in k8s.io/kubernetes

UNKNOWN
Go

CVE-2025-13281

Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes

UNKNOWN
Go

CVE-2023-2431

Kubelet vulnerable to bypass of seccomp profile enforcement in k8s.io/kubernetes

UNKNOWN
Go

CVE-2020-8558

Improper Authentication in Kubernetes in k8s.io/kubernetes

UNKNOWN
Go

CVE-2024-9042

Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes

UNKNOWN
Go

CVE-2025-1767

Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes

UNKNOWN
Go

CVE-2019-1002100

Kubernetes DoS Vulnerability in k8s.io/kubernetes

UNKNOWN
Go

CVE-2025-4563

Kubernetes allows nodes to bypass dynamic resource allocation authorization checks in k8s.io/kubernetes

UNKNOWN
Go

CVE-2023-5528

Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes

UNKNOWN
Go

CVE-2019-11253

XML Entity Expansion and Improper Input Validation in Kubernetes API server in k8s.io/kubernetes

UNKNOWN
Go

CVE-2023-2728

Kubernetes mountable secrets policy bypass in k8s.io/kubernetes

UNKNOWN
Go

CVE-2024-10220

Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes

UNKNOWN
Go

CVE-2024-5321

Kubernetes sets incorrect permissions on Windows containers logs in k8s.io/kubernetes

UNKNOWN
Go

CVE-2015-7561

Kubernetes in OpenShift3 Access Control Misconfiguration in k8s.io/kubernetes

MEDIUM 5.5
Go

CVE-2018-1002100

Kubernetes arbitrary file overwrite

HIGH 8.1
Go

CVE-2019-11243

Kubernetes did not effectively clear service account credentials

MEDIUM 5.7
Go

CVE-2019-11251

Kubernetes kubectl cp Vulnerable to Symlink Attack

MEDIUM 4.8
Go

CVE-2021-25737

Incomplete List of Disallowed Inputs in Kubernetes

CRITICAL 9.8
Go

CVE-2017-1000056

Kubernetes Privilege Escalation

MEDIUM 5.6
Go

CVE-2017-1002102

Kubernetes arbitrary file overwrite

UNKNOWN
Go

CVE-2015-5305

Directory traversal in k8s.io/kubernetes

MEDIUM 6.5
Go

CVE-2015-5305

Directory Traversal in Kubernetes

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes