Technology · Go
k8s.io/kubernetes (Go) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 49 vulnerabilities in k8s.io/kubernetes (Go): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2025-13281, was published on 16 December 2025.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
About k8s.io/kubernetes (Go)
An open-source system for automating deployment, scaling, and management of containerized applications.
Latest k8s.io/kubernetes (Go) vulnerabilities
- CVE-2025-13281: GO-2025-4240 - Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in…lowCVSS 3.1EPSS 0.4%
- CVE-2025-5187: GO-2025-3915 - Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kuberneteslowCVSS 3.1EPSS 0.5%
- CVE-2025-4563: GO-2025-3774 - Kubernetes allows nodes to bypass dynamic resource allocation authorization checks in k8s.io/kuberneteslowCVSS 3.1EPSS 0.7%
- CVE-2019-11243: GO-2025-3645 - Kubernetes did not effectively clear service account credentials in k8s.io/kuberneteslowCVSS 3.1EPSS 1.5%
- CVE-2024-9042: GO-2025-3522 - Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kuberneteslowCVSS 3.1EPSS 1.4%
- CVE-2024-7598: GO-2025-3547 - Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kuberneteslowCVSS 3.1EPSS 0.3%
- CVE-2025-1767: GO-2025-3521 - Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kuberneteslowCVSS 3.1EPSS 0.5%
- CVE-2025-0426: GO-2025-3465 - Node Denial of Service via kubelet Checkpoint API in k8s.io/kuberneteslowCVSS 3.1EPSS 0.4%
- CVE-2024-10220: GO-2024-3286 - Kubernetes kubelet arbitrary command execution in k8s.io/kuberneteslowCVSS 3.1EPSS 3.0%
- CVE-2024-0793: GO-2024-3277 - Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kuberneteslowCVSS 3.1EPSS 0.6%
- CVE-2021-25743: GO-2022-0983 - ANSI escape characters not filtered in kubectl in k8s.io/kuberneteslowCVSS 3.1EPSS 0.8%
- CVE-2021-25735: GO-2022-0907 - Access Restriction Bypass in kube-apiserver in k8s.io/kuberneteslowCVSS 3.1EPSS 5.5%
- CVE-2021-25741: GO-2022-0910 - Files or Directories Accessible to External Parties in kubernetes in k8s.io/kuberneteslowCVSS 3.1EPSS 8.0%
- CVE-2020-8555: GO-2022-0890 - Server Side Request Forgery (SSRF) in Kubernetes in k8s.io/kuberneteslowCVSS 3.1EPSS 3.7%
- CVE-2021-25737: GO-2022-0908 - Incomplete List of Disallowed Inputs in Kubernetes in k8s.io/kuberneteslowCVSS 3.1EPSS 1.3%
- CVE-2018-1002101: GO-2022-0886 - Kubernetes Arbitrary Command Injection in k8s.io/kuberneteslowCVSS 3EPSS 4.0%
- CVE-2020-8551: GO-2022-0867 - Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes in…lowCVSS 3.1EPSS 1.2%
- CVE-2020-8558: GO-2022-0885 - Improper Authentication in Kubernetes in k8s.io/kuberneteslowCVSS 3.1EPSS 3.6%
- CVE-2019-11251: GO-2022-0802 - Kubernetes kubectl cp Vulnerable to Symlink Attack in k8s.io/kuberneteslowCVSS 3.1EPSS 2.6%
- CVE-2019-1002101: GO-2022-0782 - Symlink Attack in kubectl cp in k8s.io/kuberneteslowCVSS 3EPSS 12.8%
- CVE-2019-11253: GO-2022-0703 - XML Entity Expansion and Improper Input Validation in Kubernetes API server in k8s.io/kuberneteslowCVSS 3.1EPSS 25.9%
- CVE-2023-5528: GO-2023-2341 - Kubernetes Improper Input Validation vulnerability in k8s.io/kuberneteslowCVSS 3.1EPSS 4.3%
- CVE-2023-3955: GO-2023-2170 - Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes and…lowCVSS 3.1EPSS 3.1%
- CVE-2023-3676: GO-2023-2330 - Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kuberneteslowCVSS 3.1EPSS 13.2%
- CVE-2017-1002102: GO-2023-1977 - Kubernetes can trigger deletion of arbitrary files from the nodes where containers are running in…lowCVSS 3EPSS 1.1%
Most severe k8s.io/kubernetes (Go) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2021-25736: Kubernetes kube-proxy traffic forwarding error on WindowsmediumCVSS 5.8EPSS 0.9%
- CVE-2020-8554: Kubernetes traffic interception via unverified ExternalIPs ownershipmediumCVSS 5EPSS 9.3%
- CVE-2020-8561: Kubernetes kube-apiserver confused deputy in webhook configurationsmediumCVSS 4.1EPSS 2.1%
- CVE-2019-11253: GO-2022-0703 - XML Entity Expansion and Improper Input Validation in Kubernetes API server in k8s.io/kuberneteslowCVSS 3.1EPSS 25.9%
- CVE-2023-3676: GO-2023-2330 - Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kuberneteslowCVSS 3.1EPSS 13.2%
- CVE-2021-25741: GO-2022-0910 - Files or Directories Accessible to External Parties in kubernetes in k8s.io/kuberneteslowCVSS 3.1EPSS 8.0%
- CVE-2020-8559: GO-2024-2748 - Privilege Escalation in Kubernetes in k8s.io/apimachinerylowCVSS 3.1EPSS 6.1%
- CVE-2021-25735: GO-2022-0907 - Access Restriction Bypass in kube-apiserver in k8s.io/kuberneteslowCVSS 3.1EPSS 5.5%
- CVE-2023-5528: GO-2023-2341 - Kubernetes Improper Input Validation vulnerability in k8s.io/kuberneteslowCVSS 3.1EPSS 4.3%
- CVE-2020-8555: GO-2022-0890 - Server Side Request Forgery (SSRF) in Kubernetes in k8s.io/kuberneteslowCVSS 3.1EPSS 3.7%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/k8s-io-kubernetes.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "k8s.io/kubernetes (Go) vulnerabilities", https://junglewise.ai/threats/technologies/k8s-io-kubernetes, 26 September 2026.