Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Kubernetes — Vulnerabilities & Security Advisories 102

Browse all 102 CVE security advisories affecting Kubernetes. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Kubernetes serves as an open-source container orchestration platform, automating the deployment, scaling, and management of containerized applications across distributed clusters. Its complex architecture, involving numerous interacting components like the API server and kubelet, historically exposes it to diverse vulnerability classes. Common issues include remote code execution (RCE) via unauthenticated API endpoints, privilege escalation through misconfigured role-based access controls, and cross-site scripting (XSS) in the web dashboard. With over 100 recorded CVEs, the platform has faced significant security challenges, including incidents where attackers exploited weak authentication mechanisms to gain cluster-wide control. These vulnerabilities often stem from default configurations or delayed patching of underlying dependencies. Consequently, securing Kubernetes requires rigorous network segmentation, strict identity management, and continuous monitoring to mitigate risks associated with its intricate service mesh and dynamic workload scheduling capabilities.

Found 17 results / 102Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2026-4342 ingress-nginx comment-based nginx configuration injection — ingress-nginxCWE-20 8.8 High2026-03-19
CVE-2026-3288 ingress-nginx rewrite-target nginx configuration injection — ingress-nginxCWE-20 8.8 High2026-03-09
CVE-2025-15566 ingress-nginx auth-proxy-set-headers nginx configuration injection — ingress-nginxCWE-20 8.8 High2026-02-06
CVE-2026-24514 ingress-nginx Admission Controller denial of service — ingress-nginxCWE-770 6.5 Medium2026-02-03
CVE-2026-24513 ingress-nginx auth-url protection bypass — ingress-nginxCWE-754 3.1 Low2026-02-03
CVE-2026-24512 ingress-nginx auth-method nginx configuration injection — ingress-nginxCWE-20 8.8 High2026-02-03
CVE-2026-1580 ingress-nginx auth-method nginx configuration injection — ingress-nginxCWE-20 8.8 High2026-02-03
CVE-2025-24514 ingress-nginx controller - configuration injection via unsanitized auth-url annotation — ingress-nginxCWE-20 8.8 High2025-03-24
CVE-2025-24513 ingress-nginx controller - auth secret file path traversal vulnerability — ingress-nginxCWE-20 4.8 Medium2025-03-24
CVE-2025-1098 ingress-nginx controller - configuration injection via unsanitized mirror annotations — ingress-nginxCWE-20 8.8 High2025-03-24
CVE-2025-1097 ingress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation — ingress-nginxCWE-20 8.8 High2025-03-24
CVE-2025-1974 ingress-nginx admission controller RCE escalation — ingress-nginxCWE-653 9.8 Critical2025-03-24
CVE-2024-7646 Ingress NGINX Controller 安全漏洞 — ingress-nginxCWE-20 8.8 High2024-08-16
CVE-2023-5044 Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation — ingress-nginxCWE-20 7.6 High2023-10-25
CVE-2023-5043 Ingress nginx annotation injection causes arbitrary command execution — ingress-nginxCWE-20 7.6 High2023-10-25
CVE-2022-4886 Ingress-nginx `path` sanitization can be bypassed with `log_format` directive — ingress-nginxCWE-20 8.8 High2023-10-25
CVE-2020-8553 Kubernetes ingress-nginx Compromise of auth via subset/superset namespace names — ingress-nginxCWE-73 5.9 Medium2020-07-29

This page lists every published CVE security advisory associated with Kubernetes. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.