MEDIUM 6.7 Go
Kubernetes Nodes can delete themselves by adding an OwnerReference
GHSA-4x4m-3c2p-qppc · CVE-2025-5187 · GO-2025-3915
Published · Modified
Description
A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2025-5187
- WEB https://github.com/kubernetes/kubernetes/issues/133471
- WEB https://github.com/kubernetes/kubernetes/commit/a2d98cac56a0c5cb2d8abc4d087fc00846b3bc0f
- PACKAGE https://github.com/kubernetes/kubernetes
- WEB https://groups.google.com/g/kubernetes-security-announce/c/znSNY7XCztE
Ready to move
Start Securing
Free, no credit card | First findings in minutes