Database/Container, Kubernetes & orchestration
Container and Kubernetes vulnerabilities for GPU clusters
Container escapes, Kubernetes privilege escalation, and scheduler and service mesh flaws: Docker, containerd, runc, kubelet, Argo, Istio, and the isolation boundary every multi-tenant GPU cluster depends on.
408 entries41 critical1 known exploitedFilter and search this layer
2026
Kata Containers: kata-runtime host code execution via an untrusted input pathCriticalAug 7, 2026
Kata Containers: runtime-rs standalone virtio-fs path is vulnerable to a guest-to-host escapeCriticalAug 7, 2026
Calico: Application Layer Policy (Dikastes) does not normalise URL paths, so path-traversal and encodedHighJul 30, 2026
Calico: DeleteCollection skips AuthorizeTierOperation, so a tenant can delete tiered NetworkPolicies theyMediumJul 30, 2026
Calico: kube-controllers and Goldmane bind an unauthenticated pprof listener to 0.0.0.0MediumJul 30, 2026
Kata Containers: Default configuration allows pod creators more than intendedMediumJul 23, 2026- Traefik: Authentication bypass via path traversal in ReplacePathRegexHighJul 22, 2026
- BuildKit: git.checkoutbundle=true on a malicious git source yields crafted command invocation on the build hostHighJul 21, 2026
- BuildKit: Crafted upload request lets files escape the BuildKit state directory onto the hostMediumJul 21, 2026
- BuildKit: Malicious client or frontend panics the BuildKit daemonMediumJul 21, 2026
- BuildKit: Crafted low-level API message deletes the contents of the host /tmpLowJul 21, 2026
- BuildKit: NTFS junctions inside the cache root escape the cache mount on Windows container workersMediumJul 20, 2026
cert-manager: Challenge resource handling flaw in cert-manager 1.18.0-1.19.5 and 1.20.xHighJul 16, 2026- Cilium: With L7 enabled, the embedded Envoy exposes a world-accessible admin.sock on the clusterCriticalJul 15, 2026
- Cilium: A namespaced HTTPRoute can mirror another tenant's HTTP trafficMediumJul 15, 2026
- Cilium: CIDR ipBlock rules without selectors generate a wildcard, over-permitting trafficMediumJul 15, 2026
- containerd: CRI plugin propagates unvalidated image LABEL values into container configCriticalJul 1, 2026
- containerd: CRI trusts CDI annotations inside untrusted checkpoint image metadataHighJul 1, 2026
- containerd: CRI restores container.log from a checkpoint image without validating symlinksHighJul 1, 2026
- containerd: Numeric User directive that fails 32-bit parsing is treated as a username, changing the effective UIDHighJul 1, 2026
- containerd: CRI checkpoint import does not validate image references in checkpoint metadataMediumJul 1, 2026
- containerd: Crafted image causes DoS during container creationMediumJul 1, 2026
- runc: setupPtmx/setupDev rootfs setup flaw during container rootfs constructionLowJul 1, 2026
- Rancher: SAML assertion replay: the ACS handler does not enforce one-time use, so a captured assertion logsCriticalJun 30, 2026
- Podman: Image env var with a key and no value causes Podman to pass the host's value of that variableHighJun 26, 2026
KubeVirt: SSRF in the virt-api port-forward handler via attacker-influenced VMI status IPMediumJun 26, 2026- Podman: Malicious image WORKDIR symlink creates directories or changes ownership on the host filesystemMediumJun 26, 2026
KubeVirt: safepath OpenAtNoFollow resolves via /proc/self/fd, defeating the symlink protectionHighJun 24, 2026
KubeVirt: virt-handler notify server derives VMI identity from the request body without validating the connectionMediumJun 24, 2026- Traefik: StripPrefix middleware allows route-level authentication bypassHighJun 23, 2026
- Traefik: HTTP/3 QUIC TLS configuration selection lets clients bypass router-specific mTLS enforcementHighJun 23, 2026
- Docker / moby: Race condition during `docker cp` mount setup allows escape/host accessHighJun 12, 2026
- Docker / moby: Companion `docker cp` mount-setup raceMediumJun 12, 2026
KubeVirt: Symlink path traversal in the virt-exportserver VMExport directory endpointHighMay 28, 2026
Calico: install-cni logs the rendered CNI config including the substituted service-account tokenMediumMay 28, 2026
Calico: Azure IPAM helper logs the mutated CNI config including credentialsMediumMay 28, 2026
KubeVirt: Improper symlink validation in virt-handler lets a user with edit rights in one namespace escape to the hostCriticalMay 26, 2026- Traefik: A tenant with HTTPRoute creation rights exposes the REST provider handler, bypassing provider isolationMediumMay 15, 2026
- Cilium: cilium-bugtool leaks sensitive data (recurrence of the 2024 issue)HighMay 8, 2026
- Istio: A RequestAuthentication jwksUri pointed at an internal service makes istiod issue an unauthenticated requestMediumMay 7, 2026
- Traefik: Authentication bypass in ForwardAuth when trustForwardHeader=falseHighApr 30, 2026
- Traefik: Authentication bypass in ForwardAuth and snippet-based auth middlewareHighApr 30, 2026
- Traefik: Authentication bypass via StripPrefixRegex middlewareHighApr 30, 2026
- Traefik: Cross-namespace isolation not enforced in the Kubernetes CRD providerMediumApr 30, 2026
Kata Containers: Oversight in the CopyFile policy from v3.4.0 to v3.28.0HighApr 24, 2026- Istio: serviceAccounts and notServiceAccounts in AuthorizationPolicy are evaluated incorrectlyMediumApr 15, 2026
- Helm: Crafted plugin writes its contents to an arbitrary filesystem location on install or updateHighApr 9, 2026
- Helm: Helm installs plugins with no provenance file even when signature verification is requiredHighApr 9, 2026
Firecracker: Out-of-bounds write in the virtio PCI transportHighApr 8, 2026
cosign / sigstore: verify-blob-attestation reports "Verified OK" for malformed or mismatched payloadsMediumApr 7, 2026- BuildKit: Custom frontend can craft an API message causing daemon compromiseHighMar 27, 2026
- BuildKit: Insufficient validation of git URL fragment subdir allows access to files outside the intended checkoutHighMar 27, 2026
- Cilium: Ingress NetworkPolicies not enforced for pod traffic to L7 servicesMediumMar 27, 2026
- Harbor: Hard-coded default credentials give web UI access to the whole registryCriticalMar 23, 2026
- Traefik: mTLS bypass via SNI pre-sniffing on fragmented ClientHello packetsHighMar 20, 2026
- CSI Driver NFS: Path traversal via `subDir` lets a tenant delete unintended directories on the shared NFS serverMediumMar 20, 2026
- ingress-nginx: Comment-based nginx configuration injectionHighMar 19, 2026
- Traefik: A tenant with HTTPRoute write access injects backtick-delimited rule tokens into Traefik's routerMediumMar 11, 2026
- Istio: When JWKS resolution fails, istiod falls back to hardcoded defaults, weakening JWT validationHighMar 10, 2026
- Istio: Envoy RBAC header matching flaw bypasses header-based authorization policyMediumMar 10, 2026
- ingress-nginx: rewrite-target annotation injects nginx configHighMar 9, 2026
- Cilium: With native routing plus WireGuard node encryption, traffic from pods on other nodes is wrongly permittedMediumFeb 20, 2026
Kata Containers: Kata with Cloud Hypervisor allows a user to break the VM isolation boundaryCriticalFeb 19, 2026
cosign / sigstore: Expired issuing certificate treated as valid during verificationLowFeb 19, 2026- ingress-nginx: Config injection via the auth-method annotationHighFeb 3, 2026
- ingress-nginx: Config injection via rules.http.paths.pathHighFeb 3, 2026
- ingress-nginx: Admission controller denial of serviceMediumFeb 3, 2026
- ingress-nginx: auth-url protection bypassLowFeb 3, 2026
Kata Containers: Malformed or layer-less container image breaks Kata's handlingHighJan 29, 2026
Firecracker: Symlink following in the jailer lets a local host user with write access to pre-created jailerMediumJan 23, 2026
cosign / sigstore: A crafted bundle verifies successfully even though the embedded Rekor entry does not referenceMediumJan 10, 2026- Argo Workflows (controller, podSpecPatch in Strict/Secure template reference mode): MULTI-TENANT ISOLATION: AHigh2026
- Argo Workflows (controller, ArtifactGC.PodSpecPatch / template reference allow-list): MULTI-TENANT ISOLATION: TheHigh2026
- BentoML (Dockerfile template, docker.base_image interpolation): A multi-line docker.base_image value in bento.yamlHigh2026
- Argo Workflows (workflow executor, artifact driver logging): MULTI-TENANT ISOLATION: The executor logs the wholeHigh2026
- Argo Workflows (Argo Server, ConfigMap-backed sync limit provider): MULTI-TENANT ISOLATION: The Sync Service'sHigh2026
- Argo Workflows (controller, hostNetwork / securityContext / serviceAccountName merge path): MULTI-TENANT ISOLATION: TheHigh2026
- Argo Workflows (controller pod informer, pod-gc-strategy annotation parsing): MULTI-TENANT ISOLATION: A malformedHigh2026
- Kubeflow Pipelines (Data Science Pipelines V1 API Argo Workflow spec path): MULTI-TENANT ISOLATION: The V1 API pathHigh2026
- Argo Workflows (Argo Server, WorkflowTemplate / ClusterWorkflowTemplate endpoints): MULTI-TENANT ISOLATION: TheHigh2026
- Argo Workflows (Argo Server, webhook interceptor /api/v1/events/): The webhook interceptor buffers the entire requestHigh2026
- BentoML (bentofile.yaml path fields: description, docker.setup_script, docker.dockerfile_templateHigh2026
- Argo Workflows (Argo Server, artifact directory listing renderer): MULTI-TENANT ISOLATION: Object names are printedHigh2026
- CSI Driver SMB: Same `subDir` path traversal against a shared SMB serverMedium2026
- Argo Workflows (Argo Server, SSO RBAC delegation gatekeeper): With SSO_DELEGATE_RBAC_TO_NAMESPACE enabled, an SSO userLow2026
2025
- Rancher: CLI login with -skip-verify and no --cacert silently accepts any certificateHighFeb 25, 2026
- ingress-nginx: Config injection via the auth-proxy-set-headers annotationHighFeb 6, 2026
KubeVirt CDI: PVCs can be cloned from unauthorized namespaces via DataImportCronHighJan 26, 2026- Kubernetes (kube-controller-manager): Half-blind SSRF via the Portworx in-tree volume plugin in kube-controller-managerMediumDec 14, 2025
- Cilium: Egress policies referencing AWS security group IDs are misappliedMediumNov 29, 2025
KubeVirt: hostDisk feature mounts host files into a VM with insufficient restrictionHighNov 18, 2025- containerd: CRI Attach implementation bug lets a user attach to a container they should not reachMediumNov 7, 2025
KubeVirt: virt-handler service-account permissions (update VMI, patch nodes) can be abused to force VMI migrationMediumNov 7, 2025
KubeVirt: A VM reads arbitrary files from the virt-launcher pod filesystemMediumNov 7, 2025
KubeVirt: Flawed aggregation-layer authentication flow enables RBAC bypassMediumNov 7, 2025- runc: Insufficient checks when bind-mounting /dev/console allow writes to arbitrary host procfs pathsHighNov 6, 2025
- runc: Insufficient verification of masked-path bind mounts (/dev/null replaced by symlink) enables containerHighNov 6, 2025
- runc: Attacker misdirects runc writes to /proc via racing symlinksHighNov 6, 2025
- Argo CD: Azure DevOps webhook credentials mishandled, allowing unauthorised webhook useHighOct 1, 2025
Kata Containers: A malicious host can circumvent guest protectionsMediumSep 23, 2025- Kubernetes C# client: Improper certificate validation in custom-CA mode enables MITM on the Kubernetes API connectionMediumSep 16, 2025
- secrets-store-sync-controller: Service account tokens disclosed in controller logsMediumSep 5, 2025
- Kubernetes (kube-apiserver): A node can delete itself, and cascade-delete other objects, by adding an OwnerReferenceMediumAug 27, 2025
- Kubernetes Image Builder: Nutanix/OVA Windows images use default credentials unless overriddenHighAug 17, 2025
- Helm: Crafted JSON Schema causes OOM termination of the rendererMediumAug 14, 2025
- Traefik: Path traversal in the WASM plugin installation mechanismHighAug 2, 2025
- Docker / moby: On firewalld reload, published container ports become reachable from outside despite the intendedMediumJul 30, 2025
- Docker / moby: Related firewalld handling defect affecting Moby port exposureLowJul 30, 2025
- Helm: Crafted Chart.yaml plus a symlinked Chart.lock gives local code execution when dependencies are updatedHighJul 8, 2025
- Kubernetes (kube-apiserver): Nodes can bypass DRA authorization checksLowJun 23, 2025
- containerd: User-namespaced containers not placed under the Kubernetes cgroup, defeating resource limitsMediumMay 21, 2025
- containerd: TOCTOU during image unpack: a crafted image can arbitrarily modify the host filesystemHighMay 20, 2025
- Traefik: Path matcher flaw in PathPrefix/Path/PathRegex routing enables route and authorization bypassHighApr 21, 2025
- Cilium: WireGuard encryption gap in a specific Cilium configurationMediumApr 21, 2025
- Helm: Decompression bomb chart exhausts memory on the rendering hostMediumApr 9, 2025
- Helm: Deeply nested JSON Schema references cause stack overflowMediumApr 9, 2025
gVisor: runsc mishandles file access permissions, letting unprivileged users read restricted filesMediumMar 28, 2025- ingress-nginx: "IngressNightmare": unauthenticated RCE in the admission controller, reachable from any podCriticalMar 25, 2025
- ingress-nginx: Config injection via unsanitized auth-tls-match-cn annotationHighMar 25, 2025
- ingress-nginx: Config injection via unsanitized mirror annotationsHighMar 25, 2025
- ingress-nginx: Config injection via unsanitized auth-url annotation (part of the IngressNightmare set)HighMar 25, 2025
- ingress-nginx: auth-secret file path traversal in the controllerMediumMar 25, 2025
- Kubernetes (kubelet): gitRepo volume grants inadvertent access to local repositories on the nodeMediumMar 13, 2025
- Kubernetes (kubelet): Unauthenticated node DoS through the kubelet checkpoint API filling node diskMediumFeb 13, 2025
- Cilium: Insecure default Access-Control-Allow-Origin in Hubble UI exposes sensitive observability dataMediumJan 22, 2025
- Cilium: Denial of service in the Cilium dataplaneMediumJan 22, 2025
- Argo Events (EventSource / Sensor controller, spec.template.container merge): MULTI-TENANT ISOLATION: The controllerCritical2025
- Argo Workflows (workflow-controller, artifact repository credential logging): MULTI-TENANT ISOLATIONHigh2025
- Argo Workflows (workflow executor, artifact unpack path handling): MULTI-TENANT ISOLATION: Archive entries withHigh2025
- Argo Workflows (workflow executor, tar extraction symlink handling): MULTI-TENANT ISOLATION: The patch forHigh2025
Headlamp: Credential caching in Headlamp when Helm is enabledMedium2025- Intel Device Plugins for Kubernetes (GPU/accelerator device plugin, access control): Improper access control in Intel'sMedium2025
2024
- containerd: Overly broad default permissions on containerd-managed directoriesHighNov 6, 2025
- Kubernetes (kube-apiserver): NetworkPolicy is not applied during a race in namespace termination, so pods briefly runLowMar 20, 2025
- containerd: UID:GID larger than 32-bit signed max wraps to 0, silently running the container as rootMediumMar 17, 2025
- Kubernetes (kubelet): Command injection on Windows nodes via the nodes/*/logs/query APIMediumMar 13, 2025
gVisor: Weak hashing and small seeds let a remote attacker derive a local IP and per-boot identifierMediumJan 30, 2025
gVisor: Predictable TCP/UDP source ports and header values enable off-path attacksMediumJan 30, 2025- Envoy: Load-shed path assumes an active request existsHighDec 18, 2024
- Docker / moby: Race condition in the streamformatter package causing data corruption or daemon crashHighNov 29, 2024
- Docker / moby: NULL pointer dereference in image_history crashes the daemonMediumNov 29, 2024
- Docker / moby: Race in the buildkit snapshot adapterMediumNov 29, 2024
- Cilium: L3 port-range plus L7 allow combination results in over-permissive policyMediumNov 25, 2024
- Kubernetes (kubelet): Arbitrary command execution on the node via a gitRepo volumeHighNov 22, 2024
Slurm: Authentication-handling mistake in stepmgr lets an attacker execute processes under other users' jobsMediumOct 28, 2024- Cilium: Deny rules for prefixes broader than /32 can be ignoredMediumOct 21, 2024
- Kubernetes Image Builder: VM images built with the Proxmox provider ship default credentialsCriticalOct 15, 2024
- Kubernetes Image Builder: Default credentials present during the build window for several providersMediumOct 15, 2024
- Envoy: Stream-management bugs in the default oghttp HTTP/2 codecHighSep 20, 2024
- Envoy: External clients manipulate Envoy internal headers, reaching unauthorized behaviourMediumSep 20, 2024
- Traefik: Traefik-added X-Forwarded-* headers can be spoofed by the client and are trusted by the backendCriticalSep 19, 2024
- runc: runc can be tricked into creating empty files/directories at arbitrary host locationsLowSep 3, 2024
- ingress-nginx: Annotation validation bypass reaching config injection and cluster-wide secret accessHighAug 16, 2024
- Cilium: Agent race condition drops pod labels, so the wrong (often more permissive) policy appliesMediumAug 15, 2024
- Podman: Crafted container sharing IPC creates unbounded IPC resources in /dev/shmHighAug 2, 2024
- Harbor: Incorrect permission validation lets authenticated users modify Harbor configurationMediumAug 2, 2024
- Argo CD: Large JSON payload to /api/webhook DoSes the API server from an unauthenticated positionHighJul 22, 2024
- Kubernetes (kubelet): Incorrect permissions on Windows container log directories allow privilege escalationMediumJul 18, 2024
- Traefik: IP allow-lists bypassed via HTTP/3 early data in QUIC 0-RTT with spoofed addressesHighJul 5, 2024
- Cilium: cilium-bugtool output contains sensitive dataHighJun 13, 2024
- CRI-O: Malicious container creates a symlink via directory traversal and gets arbitrary host read/writeHighJun 12, 2024
- Argo CD: /api/v1/settings exposes sensitive settings without authenticationMediumJun 6, 2024
- Argo CD: An unprivileged pod in any namespace can reach the unauthenticated Argo CD Redis on 6379 and poisonCriticalMay 21, 2024
- azure-file-csi-driver: Service account tokens disclosed in driver logsMediumMay 15, 2024
- Kubernetes (kube-apiserver): Init/ephemeral container envFrom bypasses the ServiceAccount mountable-secrets policyLowApr 22, 2024
- Docker / moby: IPv6 not disabled on interfaces where it should beMediumApr 18, 2024
- Traefik: GET with a Content-Length header hangs the endpoint indefinitelyHighApr 12, 2024
cosign / sigstore: Remote image with a malicious attachment DoSes the machine running cosignMediumApr 10, 2024
cosign / sigstore: Crafted software artifacts DoS the cosign host, affecting all colocated servicesMediumApr 10, 2024- Argo CD: Repo-server DoS, halting all GitOps reconciliationMediumMar 29, 2024
- Cilium: IPsec transparent encryption is cryptographically ineffectiveHighMar 27, 2024
- Docker / moby: DNS requests from an internal network can be forwarded to external resolvers, leaking data outMediumMar 20, 2024
- Argo CD: Chained DoS plus in-memory data manipulation lets an attacker bypass authenticationCriticalMar 18, 2024
- Cilium: HTTP policies not consistently applied to all trafficHighMar 18, 2024
- Cilium: IPsec-eligible traffic matching L7 policy is sent unencryptedMediumMar 18, 2024
- Cilium: WireGuard-eligible traffic matching L7 policy is sent unencrypted between nodesMediumMar 18, 2024
- Argo CD: Improper URL protocol filtering in link annotations enables client-side attacks against adminsCriticalMar 13, 2024
KubeVirt: kubevirt-csi in OpenShift Virtualization HCP grants access to the root HCP worker node's volumeMediumMar 7, 2024- Helm: Uninitialized variable panic parsing index and plugin YAMLHighFeb 21, 2024
- Cilium: WireGuard transparent encryption not applied to some pod trafficMediumFeb 20, 2024
- Cilium: With an external kvstore and WireGuard, pod-to-pod traffic is unencryptedMediumFeb 20, 2024
- Helm: Relative path in a chart name writes the chart outside the intended directoryMediumFeb 15, 2024
- Envoy proxy (ext_authz filter): When Envoy's ext_authz filter is configured with failure_mode_allow set to trueHighFeb 9, 2024
- Docker / moby: Classic builder cache poisoning for images built FROM scratchMediumFeb 1, 2024
- BuildKit: "Leaky Vessels": RUN --mount empty-file removal can delete arbitrary host filesCriticalJan 31, 2024
- BuildKit: Interactive-container API lacks entitlement checks, so a build can run a privileged container and escapeCriticalJan 31, 2024
- BuildKit: Race between parallel build steps sharing cache mounts with subpathsHighJan 31, 2024
- runc: "Leaky Vessels": internal file descriptor leak lets a container process start with cwd in the host filesystemHighJan 31, 2024
- BuildKit: Malicious client or frontend crashes the BuildKit daemonMediumJan 31, 2024
- Argo CD: CSRF against the Argo CD API allows deploying arbitrary workloads with Argo's cluster-admin rightsHighJan 19, 2024
- Argo Workflows Helm chart (argo-helm, workflow-role RBAC): MULTI-TENANT ISOLATION: The chart's workflow-role grantsHigh2024
- Kubeflow (AWS ALB Route Directive Adapter for Istio, OIDC JWT validation): MULTI-TENANT ISOLATION: The OIDC adapterHigh2024
- Argo Workflows (Argo Server, archived workflow retrieval under client/sso auth mode): MULTI-TENANT ISOLATION: WithMedium2024
- Argo Workflows (controller, daemon workflow SPDY client race): MULTI-TENANT ISOLATION: A data race in a global variableMedium2024
- Argo Workflows Helm chart (argo-helm, workflow-role privileges on workflowtasksets / workflowartifactgctasks): TheLow2024
2022
- Harbor: Missing permission validation on Webhook policiesHighNov 14, 2024
- Harbor: Missing permission validation on tag retention policies across projectsHighNov 14, 2024
- Harbor: Robot accounts in other projects can be updatedMediumNov 14, 2024
- Kubernetes (kube-apiserver): Aggregated API server can redirect apiserver clientsMediumNov 3, 2023
- ingress-nginx: `log_format` directive bypasses path sanitizationHighOct 25, 2023
- CRI-O: Crafted environment variable injects arbitrary lines into /etc/passwdHighSep 25, 2023
- CRI-O: Shipped OpenShift CRI-O builds regressed the CVE-2022-2995 fixMediumSep 15, 2023
- Argo CD: Unauthenticated attackers can enumerate existing applicationsMediumMar 27, 2023
- Kubernetes (kube-apiserver): Node address not verified when proxyingMediumMar 1, 2023
- Kubernetes (kube-apiserver): Users authorized to list/watch one namespaced CR type can read other CR types in the sameMediumMar 1, 2023
- Rancher: Cleartext credential storage lets managed-cluster users read credentialsCriticalFeb 7, 2023
- Rancher: OS command injection through an untrusted Helm catalog URLHighFeb 7, 2023
- Rancher: Missing authorization allows an authenticated user to create a shell pod with kubectl accessHighFeb 7, 2023
- Rancher: Insufficient entropy means a leaked cattle-token stays usable after rotationHighFeb 7, 2023
- Harbor: Public and private image repositories accessible without authenticationHighJan 13, 2023
- Buildah: Symlink following when reading .containerignore/.dockerignore discloses host filesMediumDec 8, 2022
- containerd: Goroutine leak in the CRI stream server terminal-resize path exhausts host memoryMediumDec 7, 2022
- Istio: Localhost access to the istiod pod lets a user impersonate any workload identity in the meshHighNov 10, 2022
- Istio: Crafted message DoSes istiodHighOct 13, 2022
- CRI-O: Incorrect supplementary group handling leads to information disclosure between workloadsHighSep 19, 2022
KubeVirt: Path traversal lets a user who can configure KubeVirt read arbitrary host filesHighSep 15, 2022
cosign / sigstore: Multiple verify-blob flaws cause successful verification of unsigned or wrongly-signed artifactsMediumSep 14, 2022- Podman: Incorrect supplementary group handlingHighSep 13, 2022
- Docker / moby: Supplementary groups not set up properlyMediumSep 9, 2022
- Rancher: Anyone who can create role template bindings escalates privileges cluster-wideCriticalSep 7, 2022
- Helm: OOM panic in the strvals package from crafted `--set` inputMediumSep 1, 2022
cosign / sigstore: `cosign verify-attestation --type` returns a false positive if any attestation existsHighAug 4, 2022- Argo CD: Improper access control lets any user escalate to admin-levelHighJul 12, 2022
- Argo CD: Improper certificate validation lets Argo CD be tricked into trusting a hostile endpointHighJul 12, 2022
- Argo CD: Stored XSS via a `javascript:` link executes in an admin's browserCriticalJun 27, 2022
- Argo CD: Predictable SSO state values allow authentication bypass during loginHighJun 27, 2022
- Envoy: OAuth filter does not validate access tokens, so authentication can be skipped entirelyCriticalJun 9, 2022
- Envoy: Decompressor accumulates unbounded dataHighJun 9, 2022
- containerd: Unbounded memory consumption in containerd daemon via repeated ExecSyncMediumJun 9, 2022
- CRI-O: Unbounded ExecSync output exhausts node memory or diskHighJun 7, 2022
Calico: Route hijacking via the floating IP featureMediumJun 6, 2022- Argo CD: Unauthenticated attacker forges JWTs and gains full Argo CD admin, which in a GitOps clusterCriticalMay 20, 2022
- Cilium: Incorrect default permissions on Cilium-managed host paths allow privilege escalationHighMay 20, 2022
- Cilium: After a container escape, an attacker can install eBPF programs and take over the node dataplaneHighMay 20, 2022
- runc: `runc exec --cap` created processes with non-empty inheritable capabilitiesMediumMay 17, 2022
Slurm: Incorrect access control leading to privilege escalationCriticalMay 5, 2022
Slurm: Incorrect access control leading to information disclosure across users' jobsHighMay 5, 2022
Slurm: Incorrect access control leading to privilege escalation and code executionHighMay 5, 2022- Podman: Malicious image causes privilege escalation when a user runs `podman top`HighApr 29, 2022
- CRI-O: Containers started with non-empty default inheritable capabilitiesMediumApr 18, 2022
- Podman: Containers started with non-empty default inheritable capabilitiesHighApr 4, 2022
- Docker / moby: Containers started with non-empty inheritable capabilitiesMediumMar 24, 2022
- Argo CD: Improper access control allows a low-privileged user to escalate to Argo CD adminCriticalMar 23, 2022
- Argo CD: Path traversal plus improper access control in the repo-serverHighMar 23, 2022
- CRI-O: "cr8escape": kernel sysctl injection via pod spec gives container escape and arbitrary code executionHighMar 16, 2022
- containerd: Crafted image config allows arbitrary host file read by containers launched via the CRI pluginHighMar 3, 2022
- Istio: Crafted message crashes istiodHighFeb 22, 2022
- Envoy: Type-confusion in default certificate validationHighFeb 22, 2022
- Envoy: Envoy accepts any peer certificate rather than restricting to configured CAsMediumFeb 22, 2022
cosign / sigstore: Cosign can be tricked into claiming a Rekor transparency-log entry exists when it does notLowFeb 18, 2022- CRI-O: "Safe" sysctls applied to the host when a pod uses host IPC/networkMediumFeb 9, 2022
- Argo CD: Directory traversal via Helm charts discloses credentials from other Applications' value filesHighFeb 4, 2022
- Istio: A user with CREATE on Gateway API resources escalates privilege in istiodMediumJan 19, 2022
- Argo Workflows (Argo Server, HTML artifact serving): MULTI-TENANT ISOLATION: A workflow can emit an HTML artifactHigh2022
2023
- Rancher: Sensitive data leaked into Rancher audit logsHighOct 16, 2024
gVisor: Reference-counting bug in mount-point tracking panics the sandboxMediumMay 15, 2024
Slurm: SQL injection against the SlurmDBD accounting databaseCriticalDec 14, 2023
Slurm: Double free allowing denial of service or possibly arbitrary code executionCriticalDec 14, 2023
Slurm: slurmd message-integrity bypass permits reuse of root-level authentication tokensHighDec 14, 2023
Slurm: A user can modify their extended group list used by sbcast and open files with unauthorized permissionsHighDec 14, 2023
Slurm: Improper message-integrity enforcement allows RPC traffic modificationHighDec 14, 2023- Kubernetes (in-tree storage): Crafted PV/pod on Windows nodes escalates to node admin via in-tree storage pluginHighNov 14, 2023
- Harbor: Timing condition allows creating and stopping jobs and retrieving job infoMediumNov 9, 2023
cosign / sigstore: Attacker-controlled registry returns unbounded attestations, DoSing the verifierLowNov 7, 2023- kubernetes-csi-proxy: Insufficient input sanitisation in csi-proxy leads to Windows node adminHighNov 3, 2023
Slurm: Filesystem race conditions allow gaining ownership of, overwriting, or deleting filesHighNov 3, 2023- Kubernetes: Command injection via pod spec on Windows nodesHighOct 31, 2023
- Kubernetes: Second Windows-node input-sanitisation escalation to adminHighOct 31, 2023
- ingress-nginx: Annotation injection causes arbitrary command execution in the controller podHighOct 25, 2023
- ingress-nginx: Code injection via the permanent-redirect annotationHighOct 25, 2023
- Envoy: "HTTP/2 Rapid Reset": stream-cancellation flood exhausts server resourcesHighOct 10, 2023
- Cilium: An attacker able to update pod labels causes Cilium to apply the wrong network policyHighSep 27, 2023
- Cilium: A user who can create CiliumNetworkPolicy in one namespace affects traffic cluster-wideMediumSep 27, 2023
- Argo CD: Cluster secrets stored in the last-applied-configuration annotation are readable by anyone with get accessCriticalSep 7, 2023
- Envoy: Malicious client constructs permanently valid credentials in the OAuth filterHighJul 25, 2023
- Envoy: Mixed-case HTTP/2 schemes defeat case-sensitive internal scheme checksHighJul 25, 2023
- Kubernetes (kube-apiserver): Ephemeral containers bypass the ImagePolicyWebhook, so unapproved images runMediumJul 3, 2023
- Kubernetes (kube-apiserver): Ephemeral containers bypass the ServiceAccount mountable-secrets policyMediumJul 3, 2023
- Kubernetes (kubelet): Pods with an empty localhost seccomp profile field silently bypass seccomp enforcementLowJun 16, 2023
- secrets-store-csi-driver: Service account tokens written to driver logsMediumJun 7, 2023
- Rancher: Standard users manipulate Kubernetes secrets in the local (management) clusterCriticalJun 1, 2023
- Rancher: Update-logic failure misconfigures Rancher's admission webhook, disabling the validation that enforcesCriticalMay 4, 2023
- Cilium: Debug mode logs the contents of the cilium-secrets namespace, including TLS private keysHighApr 18, 2023
- Envoy: Client can forge the x-envoy-original-path header and bypass JWT checksHighApr 4, 2023
- Envoy: Request properties are not escaped when generating request headersHighApr 4, 2023
- Docker / moby: Swarm overlay-network encryption silently not appliedHighApr 4, 2023
- Docker / moby: Encrypted overlay network traffic can be unencrypted due to missing rulesMediumApr 4, 2023
- Docker / moby: Unauthenticated injection of traffic into an encrypted overlay networkMediumApr 4, 2023
- runc: AppArmor bypass when /proc inside the container is symlinked with a specific mount configMediumMar 29, 2023
- runc: Rootless runc leaves /sys/fs/cgroup writable inside the containerMediumMar 29, 2023
- Podman: TOCTOU during volume export lets a symlink swap expose arbitrary host filesMediumMar 27, 2023
- Cilium: On agent start, eBPF programs are briefly detached, so traffic bypasses NetworkPolicyMediumMar 17, 2023
- Cilium: Agent pod hostPath allows writing to /opt/cni/bin, replacing the CNI binary on the hostMediumMar 17, 2023
KubeVirt: A compromised node's virt-handler service account can be abused cluster-wideHighMar 15, 2023- BuildKit: Git URL credentials in a build request are persisted into the build cache and can be read by other buildsMediumMar 6, 2023
- runc: Regression of CVE-2019-19921: incorrect access control leading to privilege escalation via volume mountsHighMar 3, 2023
- Argo CD: Improper authorization lets a user modify resources outside their permitted projectsCriticalFeb 16, 2023
- containerd: Unbounded read on OCI image import causes containerd OOMMediumFeb 16, 2023
- containerd: Supplementary groups not set up correctly inside containersMediumFeb 16, 2023
- Argo CD: Repository access credentials leaked in error messages surfaced in the UI and logsMediumFeb 8, 2023
- Argo CD: Improper authorization causes the API to accept tokens it should rejectCriticalJan 26, 2023
- Argo CD: Authorization bypass lets an Application be synced to a destination it is not permitted to reachHighJan 26, 2023
2020
- Rancher: Incorrectly applied authorization check lets a namespace be moved into a different projectHighDec 12, 2023
- Kubernetes (kube-apiserver): TOCTOU/DNS-rebinding bypass of the link-local and localhost proxy protectionsLowFeb 1, 2022
- Kubernetes (kube-apiserver): Admission webhook responses redirect apiserver requests into private networksMediumSep 20, 2021
- Harbor: Catalog registry API exposed on an unauthenticated pathMediumFeb 2, 2021
- Kubernetes (kube-apiserver): Any user who can create a Service with externalIPs (or patch LB status) intercepts clusterMediumJan 21, 2021
- Kubernetes (cloud-controller-manager): vSphere cloud credentials leaked into logs at verbosity 4+MediumDec 7, 2020
- Kubernetes: Malformed docker config leaks registry pull secrets into logsMediumDec 7, 2020
- Kubernetes: Authorization and bearer tokens written to logs at verbosity 9MediumDec 7, 2020
- Kubernetes (kube-controller-manager): Ceph RBD admin secrets written to controller-manager logsMediumDec 7, 2020
- containerd: containerd-shim abstract-socket API exposed to host-network containersMediumDec 1, 2020
Slurm: RPC buffer overflow in the PMIx MPI pluginCriticalNov 27, 2020
Firecracker: Unbounded serial console buffer growth leaks host memoryHighOct 16, 2020- containerd: "ContainerDrip": registry credentials leaked to an attacker-controlled URL referenced in an image manifestMediumOct 16, 2020
- Istio: DENY AuthorizationPolicy with wildcard-suffix principals silently fails to denyMediumOct 1, 2020
- etcd: Gateway can be pointed at itself, causing an infinite loop and control-plane DoSHighAug 6, 2020
- etcd: Gateway TLS authentication applied only to endpoints found in DNS SRV recordsMediumAug 6, 2020
- etcd: No password length validation permits one-character etcd passwordsMediumAug 6, 2020
Firecracker: Network stack freezes under heavy ingressMediumAug 4, 2020- ingress-nginx: A tenant can overwrite another ingress's basic-auth password fileMediumJul 29, 2020
- Kubernetes (kubelet/kube-proxy): Node's 127.0.0.1-bound services reachable from adjacent hosts and podsMediumJul 27, 2020
- Kubernetes (kubelet): Pod writes to its own /etc/hosts unaccounted for in evictionMediumJul 23, 2020
- Kubernetes (kube-apiserver): Unvalidated redirect on proxied upgrade requests lets a compromised node escalate to otherMediumJul 22, 2020
- Harbor: SSRF: a user who can edit projects scans the Harbor host's intranetMediumJul 15, 2020
- Kubernetes (kube-controller-manager): Half-blind SSRF from the controller manager into the cloud metadata serviceMediumJun 5, 2020
Slurm: Race condition in message aggregation allows launching a process as another userHighMay 21, 2020- Helm: The `lookup` template function discloses in-cluster resources, including Secrets, to a chart authorHighApr 24, 2020
- Kubernetes (kube-apiserver): Successful API requests can DoS the apiserverMediumMar 27, 2020
- Kubernetes (kubelet): Kubelet API DoS, including via the unauthenticated read-only portMediumMar 27, 2020
- Istio: Authentication Policy exact-path matching allows unauthorized access to HTTP pathsHighFeb 12, 2020
2021
- Kubernetes (kube-proxy): Windows kube-proxy forwards LoadBalancer traffic to local processes on the same portMediumOct 30, 2023
- Kubernetes (kubelet): Windows workloads run as ContainerAdministrator despite runAsNonRootHighMay 24, 2023
- ingress-nginx: Newline character bypasses `path` sanitizationHighMay 24, 2023
- Rancher: Cluster owners, members and even base users retrieve plaintext credentials via the Kubernetes APICriticalSep 7, 2022
- Rancher: Insufficiently protected credentials let project members read passwords and API tokensCriticalSep 7, 2022
- ingress-nginx: Ingress `path` can be pointed at the service-account token fileHighMay 6, 2022
- ingress-nginx: Directive injection through Ingress annotations obtains controller credentialsHighMay 6, 2022
- Rancher: restricted-admin role escalates to full adminHighMay 2, 2022
- Kubernetes (kubectl): kubectl does not neutralise ANSI escape sequences in outputLowJan 7, 2022
- containerd: On SELinux hosts, an unprivileged pod with a hostPath volume can gain full read/write to the host filesystemHighJan 5, 2022
- runc: Netlink bytemsg length integer overflow in libcontainer allows config injection / partial escapeMediumDec 6, 2021
- OCI Distribution Spec: Content-Type alone determines manifest type, so a manifest can be interpreted differentlyLowNov 17, 2021
- ingress-nginx: Custom nginx snippets in an Ingress annotation retrieve the ingress-nginx service-account tokenHighOct 29, 2021
- containerd: Container root dirs and plugin dirs created world-traversableHighOct 4, 2021
- Docker / moby: /var/lib/docker subdirectories world-traversableMediumOct 4, 2021
- Docker / moby: `docker cp` into a crafted container changes Unix permissions of existing host filesLowOct 4, 2021
- Kubernetes (kubelet): subPath volume mount symlink race gives access to host files and directories outside the volumeHighSep 20, 2021
- Kubernetes: Endpoint/EndpointSlice confused-deputy lets users reach networks they should notLowSep 20, 2021
- Kubernetes (kube-apiserver): Node updates bypass a validating admission webhook, defeating node-level policyMediumSep 6, 2021
- Kubernetes: Endpoint IPs can redirect pod traffic to private node networksLowSep 6, 2021
- Envoy: ext-authz header handling flaw allows bypassing the external authorization serviceHighAug 24, 2021
- Envoy: URI fragment treated as part of the pathHighAug 24, 2021
- Envoy: Processing continues after a local reply, causing undefined behaviourHighAug 24, 2021
- Istio: Case-sensitivity mismatch in host matching bypasses authorization policyHighAug 24, 2021
- Istio: Host header with a port bypasses AuthorizationPolicy host matchingHighAug 24, 2021
- containerd: Crafted image can change Unix file permissions of existing host files during extractionMediumJul 19, 2021
- Istio: Gateway/DestinationRule credentialName can read TLS secrets from other namespacesHighJun 29, 2021
- Helm: Helm repository credentials leaked to a redirected third-party hostMediumJun 16, 2021
- Istio: With AUTO_PASSTHROUGH gateways, an external client reaches arbitrary in-cluster services, bypassingCriticalJun 2, 2021
- Envoy: Escaped slash sequences %2F and %5C not decodedHighMay 28, 2021
- runc: Container filesystem breakout via directory traversal in mount handlingHighMay 27, 2021
- Istio: Multiple or escaped slashes bypass an Istio authorization policyMediumMay 27, 2021
Slurm: Environment mishandling in PrologSlurmctld/EpilogSlurmctld gives remote code execution as SlurmUserHighMay 13, 2021- Argo CD: /api/version leaks internal system information without authenticationHighMar 15, 2021
- Envoy: JWT with an issuer absent from the provider list bypasses JWT authenticationHighMar 11, 2021
- containerd: Environment variables from an unrelated image leak into a container, exposing another tenant's secretsMediumMar 10, 2021
- Podman: File permissions not checked for non-root users in a privileged containerHighFeb 11, 2021
- Argo CD: Tokens keep working after the user account is disabledMediumFeb 9, 2021
- Docker / moby: With --userns-remap, remapped root can escalate to real host rootMediumFeb 2, 2021
- Docker / moby: Malformed image manifest crashes dockerdMediumFeb 2, 2021
- Podman: Rootless containers see all traffic as coming from 127.0.0.1, defeating localhost-trust checksMediumFeb 2, 2021
- Argo Workflows (controller, expression template evaluation of input parameters): MULTI-TENANT ISOLATION: WhenUnscored2021
- Argo Workflows (Argo Server, TLS keys baked into the container image): MULTI-TENANT ISOLATION: Argo Server's TLSUnscored2021
- Argo Workflows (Argo Server, --auth-mode=client on Kubernetes 1.19+ outside a pod): MULTI-TENANT ISOLATION: In thisUnscored2021
- Argo Workflows (Argo Server default --auth-mode=server before 3.0): MULTI-TENANT ISOLATION: Before 3.0 the Argo ServerUnscored2021
2019
- Kubernetes (kube-apiserver): YAML parsing CPU exhaustion in the apiserverMediumApr 1, 2020
- Harbor: Privilege escalation in the Harbor registryHighMar 20, 2020
- Harbor: SQL injection via user-groupsHighMar 20, 2020
- runc: Volume-mount race gives incorrect access control and privilege escalation to hostHighFeb 12, 2020
- Kubernetes (kubectl): Double-symlink in tar output escapes the kubectl cp destinationMediumFeb 3, 2020
- Envoy: HTTP/2 request writes to the heap outside request buffers when the upstream is HTTP/1CriticalDec 13, 2019
- Envoy: Header whitespace handling enables request smuggling and authorization bypassCriticalDec 13, 2019
Firecracker: vsock buffer overflow producing potentially exploitable crashesCriticalDec 11, 2019- CRI-O: All pod processes share one memory cgroup, so a workload OOM kills conmon and destabilises the nodeMediumNov 25, 2019
- Helm: Malicious chart includes sensitive host content such as /etc/passwd, or triggers DoS, when loadedCriticalNov 12, 2019
- Harbor: Broken access control allows creating robot accounts with push/pull rights to projects the user does not ownHighOct 18, 2019
- Kubernetes (kube-apiserver): "Billion laughs": malicious YAML/JSON payload consumes all apiserver memoryHighOct 17, 2019
- runc: AppArmor restriction bypass via mount-target check flawHighSep 25, 2019
- Harbor: Non-admin users create admin accounts via POST /api/usersMediumSep 8, 2019
- Kubernetes (kubelet): /debug/pprof exposed on the unauthenticated kubelet healthz portHighAug 29, 2019
- Kubernetes (kube-apiserver): Cluster-scoped custom resources reachable through namespaced requests, so namespace-scopedHighAug 29, 2019
- Kubernetes (kubectl): `kubectl cp` path traversal from a malicious container tar overwrites files on the operator'sMediumAug 29, 2019
- Kubernetes (kubectl): Follow-up incomplete fix for the kubectl cp traversalMediumAug 29, 2019
- Kubernetes (client-go): Bearer tokens logged at verbosity 7+MediumAug 29, 2019
- Kubernetes (kubelet): Container restart runs as uid 0 despite mustRunAsNonRootMediumAug 29, 2019
- Docker Desktop: Trojan docker-credential-wincred.exe in a world-writable path gives local privilege escalationHighAug 28, 2019
- Docker / moby: Command execution via crafted remote git build path in `docker build`HighAug 22, 2019
- Docker / moby: Code injection into `docker cp` via nsswitch loading a library from the container chrootCriticalJul 29, 2019
- Docker / moby: Docker Engine in debug mode writes secrets into the debug logHighJul 18, 2019
- Helm: Improper certificate validation allows unauthorized clients to connect to TillerCriticalJul 17, 2019
- Envoy: No URL path normalization, so `something/../admin` bypasses access controlMediumApr 25, 2019
- CNI portmap plugin: portmap inserts rules ahead of the KUBE-SERVICES chain, so hostPort traffic bypasses NetworkPolicyHighApr 2, 2019
- runc: Host runc binary overwritten from inside a containerHighFeb 11, 2019
- Helm: Path traversal in `helm fetch --untar` writes outside the target directoryMediumFeb 4, 2019
2018
- Docker / moby: `docker cp` symlink-exchange TOCTOU gives arbitrary host read/write as rootHighMay 23, 2019
- Docker / moby: Default OCI spec does not mask /proc/acpi, so a container can change host hardware stateMediumJul 6, 2018
- CRI-O: Ambient-capability mishandling runs containers with elevated privilegesHighMay 18, 2018