Skip to main content

Kubernetes CVE Tracker

High- and critical-severity CVEs affecting kubernetes/kubernetes, cilium/cilium, projectcalico/calico, containerd/containerd, falcosecurity/falco, kyverno/kyverno, istio/istio, sigstore/cosign, and getsops/sops. Pages publish within 24 hours of public disclosure with impact, affected versions, detection guidance, and mitigation.

Last reviewed: 64 CVEs tracked

Showing 10 of 64

#CVESeverityProjectsDisclosedPublishedSummary
1CVE-2026-49445CRITICAL9.2ciliumSensitive information disclosure and cluster disruption via local Envoy admin socket access
2CVE-2026-41520HIGH7.9ciliumSensitive information included in cilium-bugtool debug archive
3CVE-2026-41485HIGH7.7kyvernoKyverno Controller Denial of Service via forEach Mutation Panic
4GHSA-8wfp-579w-6r25HIGH7.7kyvernoKyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak)
5CVE-2026-41323HIGH8.1kyvernoServiceAccount token leaked to external servers via apiCall service URL
6CVE-2026-41068HIGH7.7kyvernoCross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix)
7CVE-2026-40868HIGH8.1kyvernokyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token
8CVE-2026-4789HIGH8.5kyvernoSSRF via CEL http.Get/http.Post in NamespacedValidatingPolicy allows cross-namespace data access
9GHSA-fmqp-4wfc-w3v7HIGH7.7kyvernoKyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach
10GHSA-qr4g-8hrp-c4rwHIGH7.7kyvernoUnrestricted outbound requests in Kyverno apiCall enable non-blind SSRF