{"schema_version":1,"title":"k8s.io/kubernetes (Go) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 49 vulnerabilities in k8s.io/kubernetes (Go): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2025-13281, was published on 16 December 2025.","url":"https://junglewise.ai/threats/technologies/k8s-io-kubernetes","json_url":"https://junglewise.ai/threats/technologies/k8s-io-kubernetes.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/k8s-io-kubernetes","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":49,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":1},"latest":[{"cve":"CVE-2025-13281","cvss":3.1,"epss":0.0039,"slug":"cve-2025-13281-kube-controller-manager-is-vulnerable-to-half-blind-server-side","title":"GO-2025-4240 - Half-blind Server Side Request Forgery in kube-controller-manager through in-tree Portworx StorageClass in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2025-12-16T19:39:14+00:00","url":"https://junglewise.ai/threats/cve-2025-13281-kube-controller-manager-is-vulnerable-to-half-blind-server-side"},{"cve":"CVE-2025-5187","cvss":3.1,"epss":0.0055,"slug":"cve-2025-5187-kubernetes-nodes-can-delete-themselves-by-adding-an-ownerreference","title":"GO-2025-3915 - Kubernetes Nodes can delete themselves by adding an OwnerReference in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2025-09-18T17:26:15+00:00","url":"https://junglewise.ai/threats/cve-2025-5187-kubernetes-nodes-can-delete-themselves-by-adding-an-ownerreference"},{"cve":"CVE-2025-4563","cvss":3.1,"epss":0.0069,"slug":"cve-2025-4563-kubernetes-allows-nodes-to-bypass-dynamic-resource-allocation","title":"GO-2025-3774 - Kubernetes allows nodes to bypass dynamic resource allocation authorization checks in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2025-07-28T19:57:13+00:00","url":"https://junglewise.ai/threats/cve-2025-4563-kubernetes-allows-nodes-to-bypass-dynamic-resource-allocation"},{"cve":"CVE-2019-11243","cvss":3.1,"epss":0.0149,"slug":"cve-2019-11243-kubernetes-did-not-effectively-clear-service-account-credentials","title":"GO-2025-3645 - Kubernetes did not effectively clear service account credentials in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2025-05-05T16:13:00+00:00","url":"https://junglewise.ai/threats/cve-2019-11243-kubernetes-did-not-effectively-clear-service-account-credentials"},{"cve":"CVE-2024-9042","cvss":3.1,"epss":0.0137,"slug":"cve-2024-9042-kubernetes-allows-command-injection-affecting-windows-nodes-via","title":"GO-2025-3522 - Kubernetes allows Command Injection affecting Windows nodes via nodes/*/logs/query API in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2025-03-25T19:38:11+00:00","url":"https://junglewise.ai/threats/cve-2024-9042-kubernetes-allows-command-injection-affecting-windows-nodes-via"},{"cve":"CVE-2024-7598","cvss":3.1,"epss":0.0031,"slug":"cve-2024-7598-kubernetes-kube-apiserver-vulnerable-to-race-condition","title":"GO-2025-3547 - Kubernetes kube-apiserver Vulnerable to Race Condition in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2025-03-25T19:38:11+00:00","url":"https://junglewise.ai/threats/cve-2024-7598-kubernetes-kube-apiserver-vulnerable-to-race-condition"},{"cve":"CVE-2025-1767","cvss":3.1,"epss":0.0055,"slug":"cve-2025-1767-kubernetes-gitrepo-volume-inadvertent-local-repository-access","title":"GO-2025-3521 - Kubernetes GitRepo Volume Inadvertent Local Repository Access in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2025-03-25T19:38:11+00:00","url":"https://junglewise.ai/threats/cve-2025-1767-kubernetes-gitrepo-volume-inadvertent-local-repository-access"},{"cve":"CVE-2025-0426","cvss":3.1,"epss":0.0037,"slug":"cve-2025-0426-node-denial-of-service-via-kubelet-checkpoint-api","title":"GO-2025-3465 - Node Denial of Service via kubelet Checkpoint API in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2025-03-03T19:22:09+00:00","url":"https://junglewise.ai/threats/cve-2025-0426-node-denial-of-service-via-kubelet-checkpoint-api"},{"cve":"CVE-2024-10220","cvss":3.1,"epss":0.0303,"slug":"cve-2024-10220-kubernetes-kubelet-arbitrary-command-execution","title":"GO-2024-3286 - Kubernetes kubelet arbitrary command execution in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2024-11-27T19:16:39+00:00","url":"https://junglewise.ai/threats/cve-2024-10220-kubernetes-kubelet-arbitrary-command-execution"},{"cve":"CVE-2024-0793","cvss":3.1,"epss":0.0059,"slug":"cve-2024-0793-kubernetes-nil-pointer-dereference-in-kcm-after-v1-hpa-patch","title":"GO-2024-3277 - Kubernetes Nil pointer dereference in KCM after v1 HPA patch request in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2024-11-19T17:20:31+00:00","url":"https://junglewise.ai/threats/cve-2024-0793-kubernetes-nil-pointer-dereference-in-kcm-after-v1-hpa-patch"},{"cve":"CVE-2021-25743","cvss":3.1,"epss":0.0079,"slug":"cve-2021-25743-kubectl-ansi-escape-characters-not-filtered","title":"GO-2022-0983 - ANSI escape characters not filtered in kubectl in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2024-08-21T16:03:21+00:00","url":"https://junglewise.ai/threats/cve-2021-25743-kubectl-ansi-escape-characters-not-filtered"},{"cve":"CVE-2021-25735","cvss":3.1,"epss":0.0552,"slug":"cve-2021-25735-access-restriction-bypass-in-kube-apiserver","title":"GO-2022-0907 - Access Restriction Bypass in kube-apiserver in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:08+00:00","url":"https://junglewise.ai/threats/cve-2021-25735-access-restriction-bypass-in-kube-apiserver"},{"cve":"CVE-2021-25741","cvss":3.1,"epss":0.0796,"slug":"cve-2021-25741-files-or-directories-accessible-to-external-parties-in-kubernetes","title":"GO-2022-0910 - Files or Directories Accessible to External Parties in kubernetes in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:08+00:00","url":"https://junglewise.ai/threats/cve-2021-25741-files-or-directories-accessible-to-external-parties-in-kubernetes"},{"cve":"CVE-2020-8555","cvss":3.1,"epss":0.0368,"slug":"cve-2020-8555-server-side-request-forgery-ssrf-in-kubernetes","title":"GO-2022-0890 - Server Side Request Forgery (SSRF) in Kubernetes in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:08+00:00","url":"https://junglewise.ai/threats/cve-2020-8555-server-side-request-forgery-ssrf-in-kubernetes"},{"cve":"CVE-2021-25737","cvss":3.1,"epss":0.0133,"slug":"cve-2021-25737-incomplete-list-of-disallowed-inputs-in-kubernetes","title":"GO-2022-0908 - Incomplete List of Disallowed Inputs in Kubernetes in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:08+00:00","url":"https://junglewise.ai/threats/cve-2021-25737-incomplete-list-of-disallowed-inputs-in-kubernetes"},{"cve":"CVE-2018-1002101","cvss":3,"epss":0.04,"slug":"cve-2018-1002101-kubernetes-arbitrary-command-injection","title":"GO-2022-0886 - Kubernetes Arbitrary Command Injection in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:06+00:00","url":"https://junglewise.ai/threats/cve-2018-1002101-kubernetes-arbitrary-command-injection"},{"cve":"CVE-2020-8551","cvss":3.1,"epss":0.0124,"slug":"cve-2020-8551-allocation-of-resources-without-limits-or-throttling-and","title":"GO-2022-0867 - Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:06+00:00","url":"https://junglewise.ai/threats/cve-2020-8551-allocation-of-resources-without-limits-or-throttling-and"},{"cve":"CVE-2020-8558","cvss":3.1,"epss":0.036,"slug":"cve-2020-8558-improper-authentication-in-kubernetes","title":"GO-2022-0885 - Improper Authentication in Kubernetes in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:06+00:00","url":"https://junglewise.ai/threats/cve-2020-8558-improper-authentication-in-kubernetes"},{"cve":"CVE-2019-11251","cvss":3.1,"epss":0.0261,"slug":"cve-2019-11251-kubernetes-kubectl-cp-vulnerable-to-symlink-attack","title":"GO-2022-0802 - Kubernetes kubectl cp Vulnerable to Symlink Attack in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:02+00:00","url":"https://junglewise.ai/threats/cve-2019-11251-kubernetes-kubectl-cp-vulnerable-to-symlink-attack"},{"cve":"CVE-2019-1002101","cvss":3,"epss":0.1275,"slug":"cve-2019-1002101-symlink-attack-in-kubectl-cp","title":"GO-2022-0782 - Symlink Attack in kubectl cp in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2024-08-21T15:28:59+00:00","url":"https://junglewise.ai/threats/cve-2019-1002101-symlink-attack-in-kubectl-cp"},{"cve":"CVE-2019-11253","cvss":3.1,"epss":0.2594,"slug":"cve-2019-11253-xml-entity-expansion-and-improper-input-validation-in-kubernetes","title":"GO-2022-0703 - XML Entity Expansion and Improper Input Validation in Kubernetes API server in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2024-08-21T15:21:45+00:00","url":"https://junglewise.ai/threats/cve-2019-11253-xml-entity-expansion-and-improper-input-validation-in-kubernetes"},{"cve":"CVE-2023-5528","cvss":3.1,"epss":0.0425,"slug":"cve-2023-5528-kubernetes-improper-input-validation-vulnerability","title":"GO-2023-2341 - Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2024-08-21T14:30:24+00:00","url":"https://junglewise.ai/threats/cve-2023-5528-kubernetes-improper-input-validation-vulnerability"},{"cve":"CVE-2023-3955","cvss":3.1,"epss":0.0311,"slug":"cve-2023-3955-kubernetes-privilege-escalation-vulnerability","title":"GO-2023-2170 - Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes and k8s.io/mount-utils","severity":"low","exploited":false,"published_at":"2024-08-21T14:30:22+00:00","url":"https://junglewise.ai/threats/cve-2023-3955-kubernetes-privilege-escalation-vulnerability"},{"cve":"CVE-2023-3676","cvss":3.1,"epss":0.1316,"slug":"cve-2023-3676-kubernetes-privilege-escalation-vulnerability","title":"GO-2023-2330 - Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2024-08-21T14:30:22+00:00","url":"https://junglewise.ai/threats/cve-2023-3676-kubernetes-privilege-escalation-vulnerability"},{"cve":"CVE-2017-1002102","cvss":3,"epss":0.0106,"slug":"cve-2017-1002102-kubernetes-arbitrary-file-overwrite","title":"GO-2023-1977 - Kubernetes can trigger deletion of arbitrary files from the nodes where containers are running in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2024-08-20T20:32:20+00:00","url":"https://junglewise.ai/threats/cve-2017-1002102-kubernetes-arbitrary-file-overwrite"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"github.com/siyuan-note/siyuan/kernel (Go)","slug":"github-com-siyuan-note-siyuan-kernel","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel"},{"name":"code.gitea.io/gitea (Go)","slug":"code-gitea-io-gitea","vulnerabilities":76,"url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea"},{"name":"github.com/rclone/rclone (Go)","slug":"github-com-rclone-rclone","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/github-com-rclone-rclone"},{"name":"gogs.io/gogs (Go)","slug":"gogs-io-gogs","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/gogs-io-gogs"},{"name":"github.com/filebrowser/filebrowser/v2 (Go)","slug":"github-com-filebrowser-filebrowser-v2","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-filebrowser-filebrowser-v2"},{"name":"github.com/fission/fission (Go)","slug":"github-com-fission-fission","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-fission-fission"},{"name":"github.com/klever-io/klever-go (Go)","slug":"github-com-klever-io-klever-go","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-klever-io-klever-go"},{"name":"code.vikunja.io/api (Go)","slug":"code-vikunja-io-api","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/code-vikunja-io-api"},{"name":"github.com/cloudreve/Cloudreve/v4 (Go)","slug":"github-com-cloudreve-cloudreve-v4","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/github-com-cloudreve-cloudreve-v4"},{"name":"github.com/gotenberg/gotenberg/v8 (Go)","slug":"github-com-gotenberg-gotenberg-v8","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-gotenberg-gotenberg-v8"},{"name":"github.com/nezhahq/nezha (Go)","slug":"github-com-nezhahq-nezha","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-nezhahq-nezha"},{"name":"github.com/fleetdm/fleet/v4 (Go)","slug":"github-com-fleetdm-fleet-v4","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/github-com-fleetdm-fleet-v4"}],"technology":{"hub":true,"name":"k8s.io/kubernetes (Go)","slug":"k8s-io-kubernetes","vendor":{"name":"Go","slug":"go","url":"https://junglewise.ai/threats/vendors/go"},"aliases":[],"homepage":"https://kubernetes.io/","repo_url":"https://github.com/kubernetes/kubernetes","description":"An open-source system for automating deployment, scaling, and management of containerized applications.","url":"https://junglewise.ai/threats/technologies/k8s-io-kubernetes"},"most_severe":[{"cve":"CVE-2021-25736","cvss":5.8,"epss":0.0092,"slug":"cve-2021-25736-kubernetes-kube-proxy-traffic-forwarding-error-on-windows","title":"Kubernetes kube-proxy traffic forwarding error on Windows","severity":"medium","exploited":false,"published_at":"2023-10-30T03:30:15+00:00","url":"https://junglewise.ai/threats/cve-2021-25736-kubernetes-kube-proxy-traffic-forwarding-error-on-windows"},{"cve":"CVE-2020-8554","cvss":5,"epss":0.0927,"slug":"cve-2020-8554-kubernetes-traffic-interception-via-unverified-externalips","title":"Kubernetes traffic interception via unverified ExternalIPs ownership","severity":"medium","exploited":false,"published_at":"2022-02-08T21:50:34+00:00","url":"https://junglewise.ai/threats/cve-2020-8554-kubernetes-traffic-interception-via-unverified-externalips"},{"cve":"CVE-2020-8561","cvss":4.1,"epss":0.021,"slug":"cve-2020-8561-kubernetes-kube-apiserver-confused-deputy-in-webhook","title":"Kubernetes kube-apiserver confused deputy in webhook configurations","severity":"medium","exploited":false,"published_at":"2021-09-21T18:28:21+00:00","url":"https://junglewise.ai/threats/cve-2020-8561-kubernetes-kube-apiserver-confused-deputy-in-webhook"},{"cve":"CVE-2019-11253","cvss":3.1,"epss":0.2594,"slug":"cve-2019-11253-xml-entity-expansion-and-improper-input-validation-in-kubernetes","title":"GO-2022-0703 - XML Entity Expansion and Improper Input Validation in Kubernetes API server in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2024-08-21T15:21:45+00:00","url":"https://junglewise.ai/threats/cve-2019-11253-xml-entity-expansion-and-improper-input-validation-in-kubernetes"},{"cve":"CVE-2023-3676","cvss":3.1,"epss":0.1316,"slug":"cve-2023-3676-kubernetes-privilege-escalation-vulnerability","title":"GO-2023-2330 - Insufficient input sanitization on Windows nodes leads to privilege escalation in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2024-08-21T14:30:22+00:00","url":"https://junglewise.ai/threats/cve-2023-3676-kubernetes-privilege-escalation-vulnerability"},{"cve":"CVE-2021-25741","cvss":3.1,"epss":0.0796,"slug":"cve-2021-25741-files-or-directories-accessible-to-external-parties-in-kubernetes","title":"GO-2022-0910 - Files or Directories Accessible to External Parties in kubernetes in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:08+00:00","url":"https://junglewise.ai/threats/cve-2021-25741-files-or-directories-accessible-to-external-parties-in-kubernetes"},{"cve":"CVE-2020-8559","cvss":3.1,"epss":0.061,"slug":"cve-2020-8559-privilege-escalation-in-kubernetes","title":"GO-2024-2748 - Privilege Escalation in Kubernetes in k8s.io/apimachinery","severity":"low","exploited":false,"published_at":"2024-05-20T19:46:32+00:00","url":"https://junglewise.ai/threats/cve-2020-8559-privilege-escalation-in-kubernetes"},{"cve":"CVE-2021-25735","cvss":3.1,"epss":0.0552,"slug":"cve-2021-25735-access-restriction-bypass-in-kube-apiserver","title":"GO-2022-0907 - Access Restriction Bypass in kube-apiserver in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:08+00:00","url":"https://junglewise.ai/threats/cve-2021-25735-access-restriction-bypass-in-kube-apiserver"},{"cve":"CVE-2023-5528","cvss":3.1,"epss":0.0425,"slug":"cve-2023-5528-kubernetes-improper-input-validation-vulnerability","title":"GO-2023-2341 - Kubernetes Improper Input Validation vulnerability in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2024-08-21T14:30:24+00:00","url":"https://junglewise.ai/threats/cve-2023-5528-kubernetes-improper-input-validation-vulnerability"},{"cve":"CVE-2020-8555","cvss":3.1,"epss":0.0368,"slug":"cve-2020-8555-server-side-request-forgery-ssrf-in-kubernetes","title":"GO-2022-0890 - Server Side Request Forgery (SSRF) in Kubernetes in k8s.io/kubernetes","severity":"low","exploited":false,"published_at":"2024-08-21T15:29:08+00:00","url":"https://junglewise.ai/threats/cve-2020-8555-server-side-request-forgery-ssrf-in-kubernetes"}],"generated_at":"2026-09-26T16:07:00.132667+00:00"}