Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Kubernetes — Vulnerabilities & Security Advisories 52

All 52 CVE vulnerabilities found in Kubernetes, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerabilities for the Kubernetes product, categorized by specific weakness types and assigned tags. It collects critical security flaws affecting the platform, covering a defined historical range of published advisories and security bulletins. Readers can use this resource to track vendor-published advisories, analyze the characteristics of a particular weakness class, and review the complete vulnerability history associated with the product. The data helps security teams identify patterns in exploit trends and evaluate the risk profile of their deployments. No marketing language is used; the content remains factual and directly useful for audit, compliance, and incident response workflows. Specific CVE identifiers are omitted to maintain a generalized view of the vulnerability landscape rather than individual case studies. This aggregation supports strategic decisions regarding patching priorities and configuration hardening.

Vendor: Kubernetes

CVE ID Title CVSS Severity Published
CVE-2019-11254 Kubernetes API Server denial of service vulnerability from malicious YAML payloads CWE-1050 6.5 Medium 2020-04-01
CVE-2020-8552 Kubernetes API server denial of service CWE-789 5.3 Medium 2020-03-27
CVE-2020-8551 Kubernetes kubelet denial of service CWE-789 4.3 Medium 2020-03-27
CVE-2019-11251 kubectl cp allows symlink directory traversal CWE-61 4.8 Medium 2020-02-03
CVE-2018-1002102 Kubernetes API server follows unvalidated redirects from streaming Kubelet endpoints CWE-601 2.6 Low 2019-12-05
CVE-2019-11253 Kubernetes API Server JSON/YAML parsing vulnerable to resource exhaustion attack CWE-20 7.5 High 2019-10-17
CVE-2019-11250 Kubernetes client-go logs authorization headers at debug verbosity levels CWE-532 6.5 - 2019-08-29
CVE-2019-11249 kubectl cp allows symlink directory traversal CWE-61 5.7 - 2019-08-29
CVE-2019-11248 Kubernetes kubelet exposes /debug/pprof info on healthz port CWE-419 5.4 - 2019-08-29
CVE-2019-11247 Kubernetes kube-apiserver allows access to custom resources via wrong scope CWE-20 8.3 - 2019-08-29
CVE-2019-11246 kubectl cp allows symlink directory traversal CWE-61 5.7 - 2019-08-29
CVE-2019-11245 kubelet-started container uid changes to root after first restart or if image is already pulled to the node CWE-703 7.8 - 2019-08-29
CVE-2019-11244 kubectl creates world-writeable cached schema files CWE-524 5.5 - 2019-04-22
CVE-2019-11243 Google Kubernetes 信任管理问题漏洞 CWE-271 8.1 - 2019-04-22
CVE-2019-1002101 kubectl cp path traversal 5.0 - 2019-04-01
CVE-2019-1002100 Google Kubernetes 资源管理错误漏洞 6.5 - 2019-04-01
CVE-2018-1002105 Google Kubernetes 权限许可和访问控制漏洞 9.8 - 2018-12-05
CVE-2018-1002101 Google Kubernetes 命令注入漏洞 8.8 - 2018-12-05
CVE-2018-1002100 Google Kubernetes 安全漏洞 5.5 - 2018-06-01
CVE-2017-1002102 Google Kubernetes 安全漏洞 5.3 - 2018-03-13
CVE-2017-1002101 Google Kubernetes 安全漏洞 8.2 - 2018-03-13
CVE-2017-1002100 Google Kubernetes 安全漏洞 6.5 - 2017-09-14

All 52 known CVE vulnerabilities affecting Kubernetes with full Chinese analysis, references, and POCs where available.