CVE-2026-102623Medium· 6.5▾ SunlitA flaw was found in KubeVirt. An authenticated user with permission to create Virtual Machine Instances (VMIs) can cause a Denial of Service (DoS) by submitting a virtual machine definition with an empty ephemeral volume. The virt-contro…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A flaw was found in KubeVirt. An authenticated user with permission to create Virtual Machine Instances (VMIs) can cause a Denial of Service (DoS) by submitting a virtual machine definition with an empty ephemeral volume. The virt-controller component fails to properly validate the volume configuration, leading to an unhandled exception and application crash during processing. Because the malformed definition persists in the cluster, the controller enters a continuous crash loop, disrupting virtual machine lifecycle operations across the entire environment.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-88384Medium· 5.5OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribute parsing path
CVE-2022-23526High· 7.5helm: Denial of service through schema file (CVE-2022-23526)
CVE-2022-23525High· 7.5helm: Denial of service through through repository index file (CVE-2022-23525)
CVE-2023-54354Medium· 5.9Rejected reason: This CVE ID has been rejected as a duplicate.
CVE-2026-102558High· 8.6Libsoup: libsoup: heap buffer overflow during websocket receive-buffer growth
CVE-2026-102555High· 8.2Libsoup: libsoup: heap buffer overflow via uninitialized length in data-uri base64 decoding