VulnSea

Kubernetes has 12 CVEs on record between 2021 and 2026. 1 was published in the last 90 days. The median CVSS is 5.9 (medium), with 1 rated critical. None have a confirmed exploitation report. Most affected products: k8s.io/kubernetes (9), Kubernetes (1), github.com/kubernetes/kubernetes (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.9
Publish → KEV
—
Last 90 days
1 prev 0

Weakness classes

Products

  • k8s.io/kubernetes 9
  • Kubernetes 1
  • github.com/kubernetes/kubernetes 1
  • k8s.io/kubernetes/cmd/kube-apiserver 1
12
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

Kubernetes vulnerabilities

CVEs affecting Kubernetes, newest first. Open any entry for full detail, references, and exploit status.

12 CVEsRSS

CVE-2026-19444Medium· 6.5
today

A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows

A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows. When copying files from a container, kubectl runs tar inside the container to build a tar archive, transfers it over the netw…

▾ SunlitKubernetes · Kubernetesvia NVD
CVE-2024-7598Low· 3.1
1y ago

Kubernetes kube-apiserver Vulnerable to Race Condition

Kubernetes kube-apiserver Vulnerable to Race Condition

▾ Sunlitkubernetes · k8s.io/kubernetes/cmd/kube-apiserverEPSS 0.31%via OSV
CVE-2025-1767Medium· 6.5
1y ago

Kubernetes GitRepo Volume Inadvertent Local Repository Access

Kubernetes GitRepo Volume Inadvertent Local Repository Access

▾ Sunlitkubernetes · k8s.io/kubernetesEPSS 0.55%via OSV
CVE-2024-10220High· 8.1PoC
1y ago

Kubernetes kubelet arbitrary command execution

Kubernetes kubelet arbitrary command execution

▾ Midnightkubernetes · k8s.io/kubernetesEPSS 3.0%via OSV
CVE-2024-5321Medium· 6.1
2y ago

Kubernetes sets incorrect permissions on Windows containers logs

Kubernetes sets incorrect permissions on Windows containers logs

▾ Sunlitkubernetes · k8s.io/kubernetesEPSS 0.31%via OSV
CVE-2023-3676High· 8.8
2y ago

Kubernetes privilege escalation vulnerability

Kubernetes privilege escalation vulnerability

▾ Twilightkubernetes · k8s.io/kubernetesEPSS 13%via OSV
CVE-2021-25736Medium· 5.8
2y ago

Kube-proxy may unintentionally forward traffic

Kube-proxy may unintentionally forward traffic

▾ Sunlitkubernetes · k8s.io/kubernetesEPSS 0.92%via OSV
CVE-2015-7561Low· 3.1
4y ago

Kubernetes in OpenShift3 Access Control Misconfiguration

Kubernetes in OpenShift3 Access Control Misconfiguration

▾ Sunlitkubernetes · k8s.io/kubernetesEPSS 1.4%via OSV
CVE-2018-1002105Critical· 9.8PoC
4y ago

Privilege Escalation in Kubernetes

Privilege Escalation in Kubernetes

▾ Abyssalkubernetes · github.com/kubernetes/kubernetesEPSS 87%via OSV
CVE-2019-1002101Medium· 5.5PoC
4y ago

Symlink Attack in kubectl cp

Symlink Attack in kubectl cp

▾ Twilightkubernetes · k8s.io/kubernetesEPSS 13%via OSV
CVE-2020-8551Medium· 4.3
4y ago

Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes

Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes

▾ Sunlitkubernetes · k8s.io/kubernetesEPSS 1.2%via OSV
CVE-2020-8561Medium· 4.1
5y ago

Confused Deputy in Kubernetes

Confused Deputy in Kubernetes

▾ Sunlitkubernetes · k8s.io/kubernetesEPSS 2.1%via OSV
Kubernetes vulnerabilities (CVEs) · VulnSea