Junglewise Threat Intelligence

CVE-2025-13281: GO-2025-4240 - Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes

CVE-2025-13281 · Severity: low · CVSS 3.1 · Published 2025-12-16

Technologies: k8s.io/kubernetes (Go). Vendors: Go.

Executive brief

Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes

Affected products

  • Go k8s.io/kubernetes

Related threats