Database/Container, Kubernetes & orchestration
Kubernetes (kube-proxy): Windows kube-proxy forwards LoadBalancer traffic to local processes on the same port
CVSS 5.8CVE-2021-25736Container, Kubernetes & orchestrationcurated
Impact
Windows kube-proxy forwards LoadBalancer traffic to local processes on the same port
Who can reach it
Unauthenticated network via the LB
What to do
Rolling kube-proxy upgrade on Windows nodes
References
Related entries
- Cilium: L3 port-range plus L7 allow combination results in over-permissive policyCVE-2024-52529 · CiliumMedium
- Kubernetes (kube-controller-manager): Half-blind SSRF via the Portworx in-tree volume plugin in kube-controller-managerCVE-2025-13281 · Kubernetes (kube-controller-manager)Medium
- Kata Containers: Default configuration allows pod creators more than intendedCVE-2026-44210 · Kata ContainersMedium
- Kuma: Universal-mode dataplane skips TLS verification, exposing its token to proxy takeoverCVE-2026-52724 · Kuma kuma-dp (Universal mode control-plane TLS verification)Medium
- KubePi: authenticated cluster manager can read and modify clusters outside their granted scopeCVE-2026-69129 · KubePi (cluster-scoped API authorization)Medium
- containerd: Goroutine leak in the CRI stream server terminal-resize path exhausts host memoryCVE-2022-23471 · containerdMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.