Database/Container, Kubernetes & orchestration

cert-manager: Challenge resource handling flaw in cert-manager 1.18.0-1.19.5 and 1.20.x
CVSS 7.3CVE-2026-62290Container, Kubernetes & orchestrationcurated
Impact
Challenge resource handling flaw in cert-manager 1.18.0-1.19.5 and 1.20.x
Who can reach it
Cluster user with namespace access who can create Certificates
What to do
Rolling cert-manager upgrade to 1.19.6/1.20.3+; no GPU drain
References
Related entries
- Cilium (SDS secret sync for L7 network policies): A tenant confined to their own namespace reaches across and rewritesNCVD-2026-046-cilium-sds-secret-sync-for-l7-ne · Cilium (SDS secret sync for L7 network policies)High
- Harbor: SQL injection via user-groupsCVE-2019-19029 · HarborHigh
- Rancher: restricted-admin role escalates to full adminCVE-2021-36784 · RancherHigh
- Cilium: Debug mode logs the contents of the cilium-secrets namespace, including TLS private keysCVE-2023-29002 · CiliumHigh
- Kubernetes (in-tree storage): Crafted PV/pod on Windows nodes escalates to node admin via in-tree storage pluginCVE-2023-5528 · Kubernetes (in-tree storage)High
- Cilium: HTTP policies not consistently applied to all trafficCVE-2024-28248 · CiliumHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.