Database/Control plane, storage & DevOps
Volcano (admission webhook server, unbounded HTTP request body): The Volcano webhook server accepts request bodies of
Impact
The Volcano webhook server accepts request bodies of any size, so any pod in the cluster can OOM-kill it. When the admission webhook is down, Volcano job and pod admission fails, which stalls GPU scheduling for every tenant that goes through Volcano.
Who can reach it
Any in-cluster pod that can reach the Volcano webhook service endpoint. Requires only network reach, not Volcano permissions.
What to do
Upgrade Volcano to 1.12.4, 1.13.3 or 1.14.2 and restart the webhook deployment. In the meantime restrict the webhook Service with a NetworkPolicy so only the API server can reach it, and set a memory limit on the webhook pod.
References
Related entries
- HashiCorp Vault: slash injection in templated policy paths grants access to unintended pathsCVE-2026-5006 · HashiCorp Vault / Vault Enterprise (templated policy path rendering)Medium
- Renovate self-hosted: child processes inherit the full environment, exposing every secretCVE-2026-76227 · Renovate self-hosted (child process environment inheritance)Medium
- Ansible community.general OCAPI modules: TLS verification disabled, enclosure credentials exposedCVE-2026-87872 · Ansible community.general OCAPI modules (ocapi_command, ocapi_info)Medium
- rclone (S3 backend, redirect sanitization): When rclone's S3 backend follows a redirect it strips some sensitiveNCVD-2026-043-rclone-s3-backend-redirect-sanit · rclone (S3 backend, redirect sanitization)Medium
- SPI flash descriptor region configuration on a wide range of Supermicro boards: Any software running with sufficientCVE-2018-13787 · SPI flash descriptor region configuration on a wide range of Supermicro boardsMedium
- HPE ProLiant Gen10 System ROM (security restriction bypass): A local bypass of security restrictions in the System ROMCVE-2021-29213 · HPE ProLiant Gen10 System ROM (security restriction bypass)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.