Database/Container, Kubernetes & orchestration
Kubernetes (kubelet/kube-proxy): Node's 127.0.0.1-bound services reachable from adjacent hosts and pods
CVSS 5.4CVE-2020-8558Container, Kubernetes & orchestrationcurated
Impact
Node's 127.0.0.1-bound services reachable from adjacent hosts and pods; commonly reaches an unauthenticated kubelet or etcd
Who can reach it
Any pod on the node, or an adjacent host on the node network
What to do
Rolling kubelet/kube-proxy upgrade with node drain
References
Related entries
- Cilium: Ingress NetworkPolicies not enforced for pod traffic to L7 servicesCVE-2026-33726 · CiliumMedium
- Istio: serviceAccounts and notServiceAccounts in AuthorizationPolicy are evaluated incorrectlyCVE-2026-39350 · IstioMedium
- Cilium: CIDR ipBlock rules without selectors generate a wildcard, over-permitting trafficCVE-2026-56743 · CiliumMedium
- Elastic Cloud on Kubernetes: namespace-scoped user injects CA material into another namespace's trust bundleCVE-2026-78609 · Elastic Cloud on Kubernetes operator (cross-namespace Elasticsearch client trust bundle)Medium
- Rancher Fleet: unauthenticated webhook requests can change GitRepo polling interval in any namespaceCVE-2026-93539 · SUSE Rancher Fleet gitjob webhook service (unverified Git webhook)Medium
- Docker / moby: Default OCI spec does not mask /proc/acpi, so a container can change host hardware stateCVE-2018-10892 · Docker / mobyMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.