Junglewise Threat Intelligence

kube-router: GoBGP gRPC Admin Port Exposed on Node Primary IP Without Authentication, Allowing Cluster-Wide BGP Route Injection

Severity: low · CVSS 3.1 · Published 2026-05-06

Technologies: github.com/cloudnativelabs/kube-router (Go). Vendors: Go.

Executive brief

kube-router: GoBGP gRPC Admin Port Exposed on Node Primary IP Without Authentication, Allowing Cluster-Wide BGP Route Injection

Affected products

  • Go github.com/cloudnativelabs/kube-router

Related threats