go

kubevirt.io/kubevirt

View on go registry
33 Total advisories
33 Vulnerabilities
0 Malware

Dependency scanning

Check whether kubevirt.io/kubevirt is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 7.7
Go

CVE-2026-9804

KubeVirt has a Link Following issue

MEDIUM 5.4
Go

CVE-2026-6383

KubeVirt's authorization mechanism improperly truncates subresource names

MEDIUM 6.5
Go

CVE-2025-64433

KubeVirt Arbitrary Container File Read

CRITICAL 9.9
Go

CVE-2026-7374

KubeVirt has a Link Following vulnerability

MEDIUM 4.7
Go

CVE-2025-64434

KubeVirt's Improper TLS Certificate Management Handling Allows API Identity Spoofing

MEDIUM 5.3
Go

CVE-2025-64435

KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation

MEDIUM 5.3
Go

CVE-2025-64436

KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes

HIGH 7.7
Go

CVE-2025-64324

KubeVirt Vulnerable to Arbitrary Host File Read and Write

MEDIUM 5.0
Go

CVE-2025-64437

KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes

MEDIUM 4.7
Go

CVE-2025-64432

KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer

MEDIUM 5.9
Go

CVE-2024-33394

kubevirt allows a local attacker to execute arbitrary code via a crafted command

MEDIUM 6.5
Go

CVE-2024-31420

KubeVirt NULL pointer dereference flaw

UNKNOWN
Go

CVE-2022-1798

KubeVirt vulnerable to arbitrary file read on host

MEDIUM 6.5
Go

CVE-2022-1798

Duplicate Advisory: KubeVirt arbitrary host file read from the VM

MEDIUM 6.4
Go

CVE-2025-14525

KubeVirt Guest Agent DoS via Excessive Network Interface Reports

UNKNOWN
Go

CVE-2026-7374

KubeVirt has a Link Following vulnerability in kubevirt.io/kubevirt

UNKNOWN
Go

CVE-2026-9804

KubeVirt has a Link Following issue in kubevirt.io/kubevirt

UNKNOWN
Go

CVE-2026-6383

KubeVirt's authorization mechanism improperly truncates subresource names in kubevirt.io/kubevirt

UNKNOWN
Go

CVE-2024-31420

KubeVirt NULL pointer dereference flaw in kubevirt.io/kubevirt

UNKNOWN
Go

CVE-2025-64435

KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation in kubevirt.io/kubevirt

UNKNOWN
Go

CVE-2025-14525

KubeVirt Guest Agent DoS via Excessive Network Interface Reports in kubevirt.io/kubevirt

UNKNOWN
Go

CVE-2024-33394

kubevirt allows a local attacker to execute arbitrary code via a crafted command in kubevirt.io/kubevirt

UNKNOWN
Go

CVE-2025-64437

KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes in kubevirt.io/kubevirt

UNKNOWN
Go

CVE-2025-64324

KubeVirt Vulnerable to Arbitrary Host File Read and Write in kubevirt.io/kubevirt

UNKNOWN
Go

CVE-2025-64433

KubeVirt Arbitrary Container File Read in kubevirt.io/kubevirt

UNKNOWN
Go

CVE-2025-64432

KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer in kubevirt.io/kubevirt

UNKNOWN
Go

CVE-2025-64434

KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing in kubevirt.io/kubevirt

UNKNOWN
Go

GHSA-qv98-3369-g364

KubeVirt vulnerable to arbitrary file read on host in kubevirt.io/kubevirt

UNKNOWN
Go

CVE-2020-14316

Privilege Escalation in kubevirt in kubevirt.io/kubevirt

UNKNOWN
Go

CVE-2020-1701

Permissions bypass in KubeVirt in kubevirt.io/kubevirt

CRITICAL 9.9
Go

CVE-2020-14316

Privilege Escalation in kubevirt

MEDIUM 6.5
Go

CVE-2020-1701

Permissions bypass in KubeVirt

HIGH 8.2
Go

CVE-2023-26484

On a compromised node, the virt-handler service account can be used to modify all node specs

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes