CVE-2024-7598Low· 3.1▾ SunlitKubernetes kube-apiserver Vulnerable to Race Condition
▾ Sunlit zone — Low / medium · no exploitation signal
impact 17.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
0.3% → 0.3%
A security issue was discovered in Kubernetes where a malicious or compromised pod could bypass network restrictions enforced by network policies during namespace deletion. The order in which objects are deleted during namespace termination is not defined, and it is possible for network policies to be deleted before the pods that they protect. This can lead to a brief period in which the pods are running, but network policies that should apply to connections to and from the pods are not enforced.
k8s.io/kubernetes/cmd/kube-apiserver >= 1.3.0, <= 1.32.3Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2024-5321Medium· 6.1Kubernetes sets incorrect permissions on Windows containers logs
CVE-2023-3676High· 8.8Kubernetes privilege escalation vulnerability
CVE-2020-8561Medium· 4.1Confused Deputy in Kubernetes
CVE-2025-1767Medium· 6.5Kubernetes GitRepo Volume Inadvertent Local Repository Access
CVE-2021-25736Medium· 5.8Kube-proxy may unintentionally forward traffic
CVE-2015-7561Low· 3.1Kubernetes in OpenShift3 Access Control Misconfiguration