Kubernetes CVE Tracker
High- and critical-severity CVEs affecting kubernetes/kubernetes, cilium/cilium, projectcalico/calico, containerd/containerd, falcosecurity/falco, kyverno/kyverno, istio/istio, sigstore/cosign, and getsops/sops. Pages publish within 24 hours of public disclosure with impact, affected versions, detection guidance, and mitigation.
Last reviewed: — 64 CVEs tracked
Showing 10 of 64
| # | CVE | Severity | Projects | Disclosed | Published | Summary |
|---|---|---|---|---|---|---|
| 1 | CVE-2026-49445 | CRITICAL9.2 | cilium | Sensitive information disclosure and cluster disruption via local Envoy admin socket access | ||
| 2 | CVE-2026-41520 | HIGH7.9 | cilium | Sensitive information included in cilium-bugtool debug archive | ||
| 3 | CVE-2026-41485 | HIGH7.7 | kyverno | Kyverno Controller Denial of Service via forEach Mutation Panic | ||
| 4 | GHSA-8wfp-579w-6r25 | HIGH7.7 | kyverno | Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) | ||
| 5 | CVE-2026-41323 | HIGH8.1 | kyverno | ServiceAccount token leaked to external servers via apiCall service URL | ||
| 6 | CVE-2026-41068 | HIGH7.7 | kyverno | Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) | ||
| 7 | CVE-2026-40868 | HIGH8.1 | kyverno | kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token | ||
| 8 | CVE-2026-4789 | HIGH8.5 | kyverno | SSRF via CEL http.Get/http.Post in NamespacedValidatingPolicy allows cross-namespace data access | ||
| 9 | GHSA-fmqp-4wfc-w3v7 | HIGH7.7 | kyverno | Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach | ||
| 10 | GHSA-qr4g-8hrp-c4rw | HIGH7.7 | kyverno | Unrestricted outbound requests in Kyverno apiCall enable non-blind SSRF |