VulnSea

kubevirt has 8 CVEs on record between 2022 and 2026. The busiest recent month was November 2025 with 4. The median CVSS is 5.9 (medium). None have a confirmed exploitation report. Most affected products: kubevirt.io/kubevirt (5), kubevirt (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.9
Publish → KEV
Last 90 days
0 prev 2

Products

  • kubevirt.io/kubevirt 5
  • kubevirt 3
8
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

kubevirt vulnerabilities

CVEs affecting kubevirt, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2026-13208Medium· 6.5
3mo ago

A flaw was found in KubeVirt's virt-handler domain notify server

A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SEvent derive the VMI identity (namespace/name) solely from the request body without validating it against the connecti…

Sunlitkubevirt · kubevirtEPSS 0.13%via NVD
CVE-2026-13201High· 7.3
3mo ago

A flaw was found in KubeVirt's safepath package used by virt-handler

A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but downstream operations resolve the path via /proc/self/fd/N using lin…

Twilightkubevirt · kubevirtEPSS 0.22%via NVD
CVE-2025-64432Medium· 4.7PoC
10mo ago

KubeVirt is a virtual machine management add-on for Kubernetes

KubeVirt is a virtual machine management add-on for Kubernetes. Versions 1.5.3 and below, and 1.6.0 contained a flawed implementation of the Kubernetes aggregation layer's authentication flow which could enable bypass of RBAC controls. I…

Twilightkubevirt · kubevirtEPSS 0.14%via NVD
CVE-2025-64324High· 7.7
10mo ago

KubeVirt Vulnerable to Arbitrary Host File Read and Write

KubeVirt Vulnerable to Arbitrary Host File Read and Write

Twilightkubevirt · kubevirt.io/kubevirtEPSS 0.22%via OSV
CVE-2025-64436Medium· 5.3
10mo ago

KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes

KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes

Sunlitkubevirt · kubevirt.io/kubevirtEPSS 0.26%via OSV
CVE-2025-64437Medium· 5.0
10mo ago

KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes

KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes

Sunlitkubevirt · kubevirt.io/kubevirtEPSS 0.21%via OSV
CVE-2024-33394Medium· 5.9
2y ago

kubevirt allows a local attacker to execute arbitrary code via a crafted command

kubevirt allows a local attacker to execute arbitrary code via a crafted command

Sunlitkubevirt · kubevirt.io/kubevirtEPSS 0.33%via OSV
GHSA-qv98-3369-g364High
4y ago

KubeVirt vulnerable to arbitrary file read on host

KubeVirt vulnerable to arbitrary file read on host

Twilightkubevirt · kubevirt.io/kubevirtvia OSV
kubevirt vulnerabilities (CVEs) · VulnSea