Kubernetes has 12 CVEs on record between 2021 and 2026. 1 was published in the last 90 days. The median CVSS is 5.9 (medium), with 1 rated critical. None have a confirmed exploitation report. Most affected products: k8s.io/kubernetes (9), Kubernetes (1), github.com/kubernetes/kubernetes (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.9
- Publish → KEV
- —
- Last 90 days
- 1 prev 0
Weakness classes
Products
- k8s.io/kubernetes 9
- Kubernetes 1
- github.com/kubernetes/kubernetes 1
- k8s.io/kubernetes/cmd/kube-apiserver 1
Worst active — by depth score
CVE-2018-1002105Critical· 9.8Privilege Escalation in Kubernetes83CVE-2024-10220High· 8.1 Kubernetes kubelet arbitrary command execution57CVE-2023-3676High· 8.8Kubernetes privilege escalation vulnerability51CVE-2019-1002101Medium· 5.5Symlink Attack in kubectl cp45CVE-2026-19444Medium· 6.5A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows36
Kubernetes vulnerabilities
CVEs affecting Kubernetes, newest first. Open any entry for full detail, references, and exploit status.
12 CVEsRSS
CVE-2026-19444Medium· 6.5A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows
A path traversal vulnerability was discovered in the Kubernetes kubectl client's kubectl cp command on Windows. When copying files from a container, kubectl runs tar inside the container to build a tar archive, transfers it over the netw…
CVE-2024-7598Low· 3.1Kubernetes kube-apiserver Vulnerable to Race Condition
Kubernetes kube-apiserver Vulnerable to Race Condition
CVE-2025-1767Medium· 6.5Kubernetes GitRepo Volume Inadvertent Local Repository Access
Kubernetes GitRepo Volume Inadvertent Local Repository Access
CVE-2024-10220High· 8.1PoCKubernetes kubelet arbitrary command execution
Kubernetes kubelet arbitrary command execution
CVE-2024-5321Medium· 6.1Kubernetes sets incorrect permissions on Windows containers logs
Kubernetes sets incorrect permissions on Windows containers logs
CVE-2023-3676High· 8.8Kubernetes privilege escalation vulnerability
Kubernetes privilege escalation vulnerability
CVE-2021-25736Medium· 5.8Kube-proxy may unintentionally forward traffic
Kube-proxy may unintentionally forward traffic
CVE-2015-7561Low· 3.1Kubernetes in OpenShift3 Access Control Misconfiguration
Kubernetes in OpenShift3 Access Control Misconfiguration
CVE-2018-1002105Critical· 9.8PoCPrivilege Escalation in Kubernetes
Privilege Escalation in Kubernetes
CVE-2019-1002101Medium· 5.5PoCSymlink Attack in kubectl cp
Symlink Attack in kubectl cp
CVE-2020-8551Medium· 4.3Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes
Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes
CVE-2020-8561Medium· 4.1Confused Deputy in Kubernetes
Confused Deputy in Kubernetes