VulnSea

kubevirt vulnerabilities

CVEs whose affected-version data names the kubevirt package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

5 CVEsRSS

CVE-2026-13208Medium· 6.5
3mo ago

A flaw was found in KubeVirt's virt-handler domain notify server

A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SEvent derive the VMI identity (namespace/name) solely from the request body without validating it against the connecti…

Sunlitkubevirt · kubevirtEPSS 0.13%via NVD
CVE-2026-13201High· 7.3
3mo ago

A flaw was found in KubeVirt's safepath package used by virt-handler

A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but downstream operations resolve the path via /proc/self/fd/N using lin…

Twilightkubevirt · kubevirtEPSS 0.22%via NVD
CVE-2026-7374Critical· 9.9
3mo ago

A flaw was found in KubeVirt's virt-handler component

A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation when connecting to virtual machine consol…

MidnightRed Hat · kubevirtEPSS 0.74%via NVD
CVE-2025-14525Medium· 6.4
7mo ago

A flaw was found in kubevirt

A flaw was found in kubevirt. A user within a virtual machine (VM), if the guest agent is active, can exploit this by causing the agent to report an excessive number of network interfaces. This action can overwhelm the system's ability t…

SunlitRed Hat · kubevirtEPSS 0.27%via NVD
CVE-2025-64432Medium· 4.7PoC
10mo ago

KubeVirt is a virtual machine management add-on for Kubernetes

KubeVirt is a virtual machine management add-on for Kubernetes. Versions 1.5.3 and below, and 1.6.0 contained a flawed implementation of the Kubernetes aggregation layer's authentication flow which could enable bypass of RBAC controls. I…

Twilightkubevirt · kubevirtEPSS 0.14%via NVD
kubevirt vulnerabilities (CVEs) · VulnSea