CVE-2021-25736Medium· 5.8▾ SunlitKube-proxy may unintentionally forward traffic
▾ Sunlit zone — Low / medium · no exploitation signal
impact 31.9 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.9%
Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (spec.ports[*].port) as a LoadBalancer Service when the LoadBalancer controller does not set the status.loadBalancer.ingress[].ip field. Clusters
where the LoadBalancer controller sets the status.loadBalancer.ingress[].ip field are unaffected.
k8s.io/kubernetes < 1.21.0Upgrade to a patched release:
k8s.io/kubernetes 1.21.0Connected by shared product, vendor, weakness, or advisory.
CVE-2024-5321Medium· 6.1Kubernetes sets incorrect permissions on Windows containers logs
CVE-2023-3676High· 8.8Kubernetes privilege escalation vulnerability
CVE-2020-8561Medium· 4.1Confused Deputy in Kubernetes
CVE-2025-1767Medium· 6.5Kubernetes GitRepo Volume Inadvertent Local Repository Access
CVE-2015-7561Low· 3.1Kubernetes in OpenShift3 Access Control Misconfiguration
CVE-2024-10220High· 8.1Kubernetes kubelet arbitrary command execution