VulnSea

kubeedge has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 8.4 (high).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.4
Publish → KEV
Last 90 days
4 prev 0

Products

  • kubeedge 4
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

kubeedge vulnerabilities

CVEs affecting kubeedge, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-62369High· 8.1
today

KubeEdge: keadm DecompressTarGz path traversal enables arbitrary file write on Windows during edge node join

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.16.0 until 1.21.2, 1.22.2, and 1.23.1, the DecompressTarGz function in keadm/cmd/keadm/app/cmd/util/comm…

Twilightkubeedge · kubeedgevia CVEORG
CVE-2026-62182High· 8.8
today

KubeEdge: ConfigUpdateJob updateFields enables remote shell injection and code execution on edge nodes

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.21.0 until 1.21.2, 1.22.2, and 1.23.1, ConfigUpdateJob processing in edge/pkg/taskmanager/actions/config…

Twilightkubeedge · kubeedgevia CVEORG
CVE-2026-62371High· 8.8
today

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.12.0 until 1.21.2, 1.22.2, and 1.23.1, the v1alpha2 NodeUpgradeJob handler in edge/pkg/taskmanager/actio…

Twilightkubeedge · kubeedgevia NVD
CVE-2026-62370Medium· 6.5
today

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge

KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.0.0 until 1.21.2, 1.22.2, and 1.23.1, Reader.Read in pkg/viaduct/pkg/packer trusts the 32-bit PackageHea…

Sunlitkubeedge · kubeedgevia NVD
kubeedge vulnerabilities (CVEs) · VulnSea