{"schema_version":1,"title":"KubeVirt vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 10 vulnerabilities in KubeVirt: 0 in the last 7 days and 0 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-13434, was published on 26 June 2026.","url":"https://junglewise.ai/threats/technologies/kubevirt","json_url":"https://junglewise.ai/threats/technologies/kubevirt.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/kubevirt","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":2,"all_time":10,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":10},"latest":[{"cve":"CVE-2026-13434","cvss":4.9,"slug":"cve-2026-13434-kubevirt-improper-input-validation-in-network-annotation","title":"KubeVirt improper input validation in network annotation generator","severity":"medium","exploited":false,"published_at":"2026-06-26T17:16:32.313+00:00","url":"https://junglewise.ai/threats/cve-2026-13434-kubevirt-improper-input-validation-in-network-annotation"},{"cve":"CVE-2026-13325","cvss":8.5,"slug":"cve-2026-13325-kubevirt-authentication-bypass-in-migration-proxy-when-tls-is","title":"KubeVirt authentication bypass in migration proxy when TLS is disabled","severity":"high","exploited":false,"published_at":"2026-06-26T11:16:30.83+00:00","url":"https://junglewise.ai/threats/cve-2026-13325-kubevirt-authentication-bypass-in-migration-proxy-when-tls-is"},{"cve":"CVE-2026-13322","cvss":3.8,"slug":"cve-2026-13322-kubevirt-unbounded-memory-allocation-in-virt-handler-virtio","title":"KubeVirt unbounded memory allocation in virt-handler virtio-serial server","severity":"low","exploited":false,"published_at":"2026-06-26T00:16:51.397+00:00","url":"https://junglewise.ai/threats/cve-2026-13322-kubevirt-unbounded-memory-allocation-in-virt-handler-virtio"},{"cve":"CVE-2026-13318","cvss":6.4,"slug":"cve-2026-13318-kubevirt-ssrf-in-virt-api-port-forward-handler","title":"KubeVirt SSRF in virt-api port-forward handler","severity":"medium","exploited":false,"published_at":"2026-06-26T00:16:51.277+00:00","url":"https://junglewise.ai/threats/cve-2026-13318-kubevirt-ssrf-in-virt-api-port-forward-handler"},{"cve":"CVE-2026-13218","cvss":4.2,"slug":"cve-2026-13218-kubevirt-virt-handler-symlink-following-in-writetocachedfile","title":"KubeVirt virt-handler symlink following in WriteToCachedFile","severity":"medium","exploited":false,"published_at":"2026-06-26T00:16:51.147+00:00","url":"https://junglewise.ai/threats/cve-2026-13218-kubevirt-virt-handler-symlink-following-in-writetocachedfile"},{"cve":"CVE-2026-13208","cvss":6.5,"slug":"cve-2026-13208-kubevirt-virt-handler-improper-authentication-in-domain-notify","title":"KubeVirt virt-handler improper authentication in domain notify server","severity":"medium","exploited":false,"published_at":"2026-06-24T21:16:52.547+00:00","url":"https://junglewise.ai/threats/cve-2026-13208-kubevirt-virt-handler-improper-authentication-in-domain-notify"},{"cve":"CVE-2026-13201","cvss":5.2,"slug":"cve-2026-13201-kubevirt-safepath-symlink-following-in-openatnofollow","title":"KubeVirt safepath symlink following in OpenAtNoFollow","severity":"medium","exploited":false,"published_at":"2026-06-24T21:16:52.42+00:00","url":"https://junglewise.ai/threats/cve-2026-13201-kubevirt-safepath-symlink-following-in-openatnofollow"},{"cve":"CVE-2026-9804","cvss":7.7,"epss":0.0072,"slug":"cve-2026-9804-kubevirt-path-traversal-in-virt-exportserver-via-symlink-escape","title":"KubeVirt path traversal in virt-exportserver via symlink escape","severity":"high","exploited":false,"published_at":"2026-05-28T09:16:49.5+00:00","url":"https://junglewise.ai/threats/cve-2026-9804-kubevirt-path-traversal-in-virt-exportserver-via-symlink-escape"},{"cve":"CVE-2026-7374","cvss":9.9,"epss":0.0083,"slug":"cve-2026-7374-kubevirt-virt-handler-privilege-escalation-via-symlink-following","title":"KubeVirt virt-handler privilege escalation via symlink following","severity":"critical","exploited":false,"published_at":"2026-05-26T14:16:40.717+00:00","url":"https://junglewise.ai/threats/cve-2026-7374-kubevirt-virt-handler-privilege-escalation-via-symlink-following"},{"cve":"CVE-2026-6383","cvss":5.4,"epss":0.0025,"slug":"cve-2026-6383-kubevirt-incorrect-rbac-evaluation-via-subresource-name-truncation","title":"KubeVirt incorrect RBAC evaluation via subresource name truncation","severity":"medium","exploited":false,"published_at":"2026-04-15T21:30:18+00:00","url":"https://junglewise.ai/threats/cve-2026-6383-kubevirt-incorrect-rbac-evaluation-via-subresource-name-truncation"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"KubeVirt Migration-Planner","slug":"migration-planner","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/migration-planner"}],"technology":{"hub":true,"name":"KubeVirt","slug":"kubevirt","vendor":{"name":"KubeVirt","slug":"kubevirt","url":"https://junglewise.ai/threats/vendors/kubevirt"},"aliases":[],"category":"virtualization-software","homepage":"https://kubevirt.io/","repo_url":"https://github.com/kubevirt/kubevirt","description":"KubeVirt is an open-source virtualization add-on for Kubernetes that allows running virtual machines alongside containers.","url":"https://junglewise.ai/threats/technologies/kubevirt"},"most_severe":[{"cve":"CVE-2026-7374","cvss":9.9,"epss":0.0083,"slug":"cve-2026-7374-kubevirt-virt-handler-privilege-escalation-via-symlink-following","title":"KubeVirt virt-handler privilege escalation via symlink following","severity":"critical","exploited":false,"published_at":"2026-05-26T14:16:40.717+00:00","url":"https://junglewise.ai/threats/cve-2026-7374-kubevirt-virt-handler-privilege-escalation-via-symlink-following"},{"cve":"CVE-2026-13325","cvss":8.5,"slug":"cve-2026-13325-kubevirt-authentication-bypass-in-migration-proxy-when-tls-is","title":"KubeVirt authentication bypass in migration proxy when TLS is disabled","severity":"high","exploited":false,"published_at":"2026-06-26T11:16:30.83+00:00","url":"https://junglewise.ai/threats/cve-2026-13325-kubevirt-authentication-bypass-in-migration-proxy-when-tls-is"},{"cve":"CVE-2026-9804","cvss":7.7,"epss":0.0072,"slug":"cve-2026-9804-kubevirt-path-traversal-in-virt-exportserver-via-symlink-escape","title":"KubeVirt path traversal in virt-exportserver via symlink escape","severity":"high","exploited":false,"published_at":"2026-05-28T09:16:49.5+00:00","url":"https://junglewise.ai/threats/cve-2026-9804-kubevirt-path-traversal-in-virt-exportserver-via-symlink-escape"},{"cve":"CVE-2026-13208","cvss":6.5,"slug":"cve-2026-13208-kubevirt-virt-handler-improper-authentication-in-domain-notify","title":"KubeVirt virt-handler improper authentication in domain notify server","severity":"medium","exploited":false,"published_at":"2026-06-24T21:16:52.547+00:00","url":"https://junglewise.ai/threats/cve-2026-13208-kubevirt-virt-handler-improper-authentication-in-domain-notify"},{"cve":"CVE-2026-13318","cvss":6.4,"slug":"cve-2026-13318-kubevirt-ssrf-in-virt-api-port-forward-handler","title":"KubeVirt SSRF in virt-api port-forward handler","severity":"medium","exploited":false,"published_at":"2026-06-26T00:16:51.277+00:00","url":"https://junglewise.ai/threats/cve-2026-13318-kubevirt-ssrf-in-virt-api-port-forward-handler"},{"cve":"CVE-2026-6383","cvss":5.4,"epss":0.0025,"slug":"cve-2026-6383-kubevirt-incorrect-rbac-evaluation-via-subresource-name-truncation","title":"KubeVirt incorrect RBAC evaluation via subresource name truncation","severity":"medium","exploited":false,"published_at":"2026-04-15T21:30:18+00:00","url":"https://junglewise.ai/threats/cve-2026-6383-kubevirt-incorrect-rbac-evaluation-via-subresource-name-truncation"},{"cve":"CVE-2026-13201","cvss":5.2,"slug":"cve-2026-13201-kubevirt-safepath-symlink-following-in-openatnofollow","title":"KubeVirt safepath symlink following in OpenAtNoFollow","severity":"medium","exploited":false,"published_at":"2026-06-24T21:16:52.42+00:00","url":"https://junglewise.ai/threats/cve-2026-13201-kubevirt-safepath-symlink-following-in-openatnofollow"},{"cve":"CVE-2026-13434","cvss":4.9,"slug":"cve-2026-13434-kubevirt-improper-input-validation-in-network-annotation","title":"KubeVirt improper input validation in network annotation generator","severity":"medium","exploited":false,"published_at":"2026-06-26T17:16:32.313+00:00","url":"https://junglewise.ai/threats/cve-2026-13434-kubevirt-improper-input-validation-in-network-annotation"},{"cve":"CVE-2026-13218","cvss":4.2,"slug":"cve-2026-13218-kubevirt-virt-handler-symlink-following-in-writetocachedfile","title":"KubeVirt virt-handler symlink following in WriteToCachedFile","severity":"medium","exploited":false,"published_at":"2026-06-26T00:16:51.147+00:00","url":"https://junglewise.ai/threats/cve-2026-13218-kubevirt-virt-handler-symlink-following-in-writetocachedfile"},{"cve":"CVE-2026-13322","cvss":3.8,"slug":"cve-2026-13322-kubevirt-unbounded-memory-allocation-in-virt-handler-virtio","title":"KubeVirt unbounded memory allocation in virt-handler virtio-serial server","severity":"low","exploited":false,"published_at":"2026-06-26T00:16:51.397+00:00","url":"https://junglewise.ai/threats/cve-2026-13322-kubevirt-unbounded-memory-allocation-in-virt-handler-virtio"}],"generated_at":"2026-09-26T15:07:00.181821+00:00"}