Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

274 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.7)0.50%—Redhat Advanced Cluster Management FOR KubernetesRedhat Insights-client11/8/20265/9/2026
A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to level 2 or higher, the token is written in clear text to the pod log on every…
ModificadaMedia (6.8)0.69%—Redhat Advanced Cluster Management FOR KubernetesRedhat Insights-client11/8/20265/9/2026
A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL path. This occurs because the ClusterID, which is controlled by the spoke, is used directly in the request path without proper validation or URL encoding. This vulnerability…
ModificadaMedia (6.5)0.16%—Redhat Advanced Cluster Management FOR KubernetesRedhat Insights-client11/8/20265/9/2026
A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.openshift.com pull-secret token. A local user with access to pod logs on the hub could read this long-lived credential. This information disclosure could grant unauthorized…
AnalizadaCrítica (9.4)0.83%—Microsoft Azure Kubernetes Service11/8/202612/8/2026
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
En análisisMedia (5.4)0.16%—Cluster Management Toolkit FOR KubernetesAI11/8/202612/8/2026
Protection mechanism failure for some Cluster Management Toolkit for Kubernetes software before version v0.8.5 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result…
Pendiente de análisisCrítica (9.9)0.69%—Kuadrant AuthpolicyAIKubernetes ServiceaccountAI10/8/202627/8/2026
A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Username` and `X-MaaS-Group`, which are trusted verbatim. This lack of first-party authentication enables an attacker to gain unauthorized…
Pendiente de análisisCrítica (9)0.58%—Redhat Advanced Cluster Management FOR KubernetesAI5/8/20268/9/2026
A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub namespace can create a Channel resource pointing to a Helm repository they control and a…
Pendiente de análisisCrítica (9.1)0.64%—Multicluster Engine FOR Kubernetes ClustercuratorAI5/8/20268/9/2026
A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exploit this vulnerability by creating a namespaced ClusterCurator. This action inadvertently grants the tenant administrator the ability to mint a token for a…
Pendiente de análisisAlta (8.5)0.19%—Redhat Advanced Cluster Security FOR KubernetesAI31/7/20263/8/2026
A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identity metadata based on the openshift.io/encoded-deployment-config label. A user with permission to create Deployments can set this label to "null", causing ACS to treat the…
Pendiente de análisisAlta (7.1)0.23%—Kong Kubernetes Ingress ControllerAIKong OperatorAIKong GatewayAI29/7/202630/7/2026
Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. The embedded KIC collects CA-certificate Secrets across all watched namespaces using a label selector alone, without…
Pendiente de análisisAlta (7.1)0.23%—Kong Kubernetes Ingress ControllerAI29/7/202630/7/2026
Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. KIC collects CA-certificate Secrets across all watched namespaces using a label selector alone, without ingress-class or namespace restrictions. The…
Pendiente de análisisAlta (8.5)0.57%—Redhat Advanced Cluster Management FOR KubernetesAIRedhat Multicluster-engineAI24/7/202629/9/2026
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first removing caller-supplied values, and the spoke ServiceAccount holds…
AnalizadaCrítica (10)0.90%—Microsoft Azure Kubernetes Service24/7/202629/7/2026
Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a network.
Pendiente de análisisBaja (2.4)0.35%—Kubernetes Java Client LibraryAI23/7/202623/7/2026
A security issue was discovered in the Kubernetes Java client library where a compromised pod may be able to create new files in arbitrary locations on the client machine executing copy operations via non-tar copyDirectoryFromPod when enableTarCompressing is false.
AnalizadaAlta (8.7)0.57%—F5 Big-ip Next Cloud-native Network FunctionsF5 Big-ip Next FOR KubernetesF5 Big-ip Next Service Proxy FOR Kubernetes15/7/20266/8/2026
When an HTTP/2 profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Impact: System performance can degrade until the TMM process is either forced to restart or is manually restarted. This vulnerability allows a remote, unauthenticated attacker to cause a…
AplazadaAlta (7.8)0.18%—Kubernetes Cri-oAI15/7/20261/10/2026
A flaw was found in CRI-O. The fix for a previous vulnerability (CVE-2022-4318) was incorrect, allowing it to be bypassed. An attacker capable of setting environment variables on a container can inject a newline character into the HOME environment variable. This issue allows the addition of arbitrary lines into…
Pendiente de análisisAlta (8.7)0.43%—Spotfire EnterpriseAISpotfire Enterprise With External ConsumersAISpotfire ON KubernetesAI14/7/202615/7/2026
Vulnerability in Spotfire Spotfire Enterprise (Spotfire Server modules), Spotfire Spotfire Enterprise with External Consumers (Spotfire Server modules), Spotfire Spotfire on Kubernetes (Spotfire Server modules). This issue affects Spotfire Enterprise: through 14.0.12, through 14.4.2, through 14.5.0, through 14.6.1,…
AnalizadaCrítica (9.3)2.4%💥 ExploitSuyogs Mcp-server-kubernetes10/7/202617/7/2026
MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) that allows attackers to bypass the assertNoDangerousFlags security check by supplying resourceType and name parameters with leading dashes. Attackers can inject the…
Pendiente de análisisAlta (7.7)0.55%—Redhat Advanced Cluster Security FOR KubernetesAI6/7/20268/9/2026
A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. An authenticated user with a valid API token can send deeply nested queries that cause excessive resource consumption in Central, resulting in a…
AplazadaMedia (6.1)0.33%—Kubernetes KubectlAISuyogs Mcp-server-kubernetesAI11/6/202617/6/2026
mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.7.0, the kubectl_generic tool in mcp-server-kubernetes passes user-supplied flags directly to kubectl without any allowlist, enabling a privilege escalation attack within Kubernetes environments. An attacker…
AplazadaAlta (8.8)0.60%—Suyogs Mcp-server-kubernetesAI11/6/202617/6/2026
mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-server-kubernetes exposes three environment variables (ALLOW_ONLY_READONLY_TOOLS, ALLOW_ONLY_NON_DESTRUCTIVE_TOOLS, ALLOWED_TOOLS) documented as access controls for restricting which Kubernetes…
ModificadaAlta (7.7)1.0%—AxiosRedhat Advanced Cluster Management FOR KubernetesRedhat Advanced Cluster SecurityRedhat Ansible Automation Platform+811/6/202611/9/2026
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions…
AnalizadaAlta (8.8)0.37%—Microsoft Azure Kubernetes Service9/6/202623/7/2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.
ModificadaMedia (6.5)0.49%💥 PoCApache Flink Kubernetes Operator26/5/202624/7/2026
Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The FlinkSessionJob jarURI is currently not validated so that it points to user-owned files or addresses. This lets a user with CR create permissions read files from the operator…
AnalizadaAlta (8.7)0.21%—Apache-airflow-providers-cncf-kubernetes19/5/202624/7/2026
JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actions that were only available to running tasks via Task SDK and potentially allow to modify state of Airflow Database for…
Orbitaley — Vulnerabilidades