Github.com/kubernetes/kubernetes
9 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Github.com/kubernetes/kubernetes, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Github.com/kubernetes/kubernetes CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 9 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High1
- Medium7
Latest CVEs
The 9 most recently published vulnerabilities affecting Github.com/kubernetes/kubernetes.
- CVE-2022-3294Node address isn't always verified when proxying6.6
- CVE-2022-3162Unauthorized read of Custom Resources6.5
- CVE-2020-8563Secret leaks in logs for vSphere Provider kube-controller-manager4.7
- CVE-2020-8564Docker config secrets leaked when file is malformed and loglevel >= 44.7
- CVE-2020-8566Ceph RBD adminSecrets exposed in logs when loglevel >= 44.7
- CVE-2018-1002105In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to est...9.8
- CVE-2015-7528Kubernetes before 1.2.0-alpha.5 allows remote attackers to read arbitrary pod logs via a container name.5.3
- CVE-2016-1905The API server in Kubernetes does not properly check admission control, which allows remote authenticated users to access additional resources via a crafted patched object.7.7
- CVE-2015-5305Directory traversal vulnerability in Kubernetes, as used in Red Hat OpenShift Enterprise 3.0, allows attackers to write to arbitrary files via a crafted object type name, which is not properly hand...6.4
Product grouping is registry-driven, with AI assist and human review. How it works