CVE Tools

Kubevirt

7 CVEs tracked since 2025. Since Nov 2025, none of them reached CISA KEV.

Kubevirt CVEs per month

Nov 2025 to Nov 2025. Point at a month, or focus the strip and use the arrow keys.
Kubevirt CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2025-1170

Products

The products that kept showing up in Kubevirt's monthly top three, with their CVEs summed over those months.

  1. Kubevirt71 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Kubevirt.

  1. CVE-2026-13434Virt-controller-rhel9: kubevirt: kubevirt: multus default-network annotation injection via unvalidated tenant networkname when externalnetresourceinjection is enabled4.9
  2. CVE-2026-13322Kubevirt: virt-handler-rhel9: kubevirt: unbounded virtio-serial readline in virt-handler causes oom denial of service3.8
  3. CVE-2026-13318Virt-api-rhel9: kubevirt: kubevirt: ssrf in virt-api port-forward via unvalidated guest-agent-reported ip6.4
  4. CVE-2026-13218Kubevirt: kubevirt: symlink following in writetocachedfile allows host file overwrite from virt-launcher4.2
  5. CVE-2026-13208Kubevirt: virt-handler-rhel9: kubevirt: virt-handler notify server trusts vmi identity from unauthenticated grpc request body6.5
  6. CVE-2026-13201Kubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enables notify socket hijacking and node-level vm disruption7.3
  7. CVE-2025-64324KubeVirt Vulnerable to Arbitrary Host File Read and Write7.7
  8. CVE-2025-64433KubeVirt Arbitrary Container File Read6.5
  9. CVE-2025-64437KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes5.0
  10. CVE-2025-64436KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes5.3
  11. CVE-2025-64435KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation5.3
  12. CVE-2025-64434KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing4.7
  13. CVE-2025-64432KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer4.7
  14. CVE-2024-33394An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.5.9
  15. CVE-2023-26484On a compromised KubeVirt node, the virt-handler service account can be used to modify all node specs8.2

The record

Peak rank
#109 in Nov 2025
Busiest month shown
Nov 2025, 7 CVEs
Months with a KEV entry
0 since Nov 2025
Monthly snapshots
1 since 2025
Kubevirt's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store