CVE-2020-8551Medium· 4.3▾ SunlitAllocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.1%
1.1% → 1.2%
The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via the kubelet API, including the unauthenticated HTTP read-only API typically served on port 10255, and the authenticated HTTPS API typically served on port 10250.
k8s.io/kubernetes >= 1.15.0, < 1.15.10k8s.io/kubernetes >= 1.16.0, < 1.16.6k8s.io/kubernetes >= 1.17.0, < 1.17.2Upgrade to a patched release:
k8s.io/kubernetes 1.15.10k8s.io/kubernetes 1.16.6k8s.io/kubernetes 1.17.2Connected by shared product, vendor, weakness, or advisory.
CVE-2024-5321Medium· 6.1Kubernetes sets incorrect permissions on Windows containers logs
CVE-2023-3676High· 8.8Kubernetes privilege escalation vulnerability
CVE-2020-8561Medium· 4.1Confused Deputy in Kubernetes
CVE-2025-1767Medium· 6.5Kubernetes GitRepo Volume Inadvertent Local Repository Access
CVE-2019-1002101Medium· 5.5Symlink Attack in kubectl cp
CVE-2021-25736Medium· 5.8Kube-proxy may unintentionally forward traffic