Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.1) | 0.62% | — | Linuxfoundation KubeedgeAI | 21/9/2026 | 24/9/2026 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.16.0 until 1.21.2, 1.22.2, and 1.23.1, the DecompressTarGz function in keadm/cmd/keadm/app/cmd/util/common.go joins archive entry names to the extraction destination without sufficient… | |
| Pendiente de análisis | Alta (8.8) | 0.48% | — | Linuxfoundation KubeedgeAI | 21/9/2026 | 24/9/2026 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.21.0 until 1.21.2, 1.22.2, and 1.23.1, ConfigUpdateJob processing in edge/pkg/taskmanager/actions/configupdatejob.go concatenates authenticated user-controlled updateFields values into… | |
| Pendiente de análisis | Alta (8.8) | 0.48% | — | Linuxfoundation KubeedgeAI | 21/9/2026 | 24/9/2026 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.12.0 until 1.21.2, 1.22.2, and 1.23.1, the v1alpha2 NodeUpgradeJob handler in edge/pkg/taskmanager/actions/nodeupgradejob.go concatenates authenticated user-controlled spec.version and… | |
| Pendiente de análisis | Media (6.5) | 0.50% | — | Linuxfoundation KubeedgeAI | 21/9/2026 | 29/9/2026 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. From 1.0.0 until 1.21.2, 1.22.2, and 1.23.1, Reader.Read in pkg/viaduct/pkg/packer trusts the 32-bit PackageHeader.PayloadLen received through the CloudHub viaduct message-processing path and… | |
| Aplazada | Alta (8.8) | 0.64% | — | Kubeedge CloudcoreAI | 29/8/2026 | 24/9/2026 | KubeEdge CloudCore through 1.23.1 accepts node task status reports on its HTTPS server without authentication verification. Attackers can reach CloudCore on port 10002 to mark upgrade jobs as succeeded or failed, deceiving the control plane about node upgrade status and blocking further upgrade scheduling. | |
| Modificada | Media (6.5) | 0.72% | — | Linuxfoundation Kubeedge | 11/7/2022 | 17/6/2026 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, a large response received by the viaduct WSClient can cause a DoS from memory exhaustion. The entire body of the response is being read into memory… | |
| Modificada | Media (6.5) | 0.70% | — | Linuxfoundation Kubeedge | 11/7/2022 | 17/6/2026 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, the Cloud Stream server and the Edge Stream server reads the entire message into memory without imposing a limit on the size of this message. An… | |
| Modificada | Media (6.5) | 0.70% | — | Linuxfoundation Kubeedge | 11/7/2022 | 17/6/2026 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, the CloudCore Router does not impose a limit on the size of responses to requests made by the REST handler. An attacker could use this weakness to… | |
| Modificada | Media (6.5) | 1.00% | — | Linuxfoundation Kubeedge | 11/7/2022 | 17/6/2026 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, EdgeCore may be susceptible to a DoS attack on CloudHub if an attacker was to send a well-crafted HTTP request to `/edge.crt`. If an attacker can… | |
| Modificada | Media (6.5) | 0.82% | — | Linuxfoundation Kubeedge | 11/7/2022 | 17/6/2026 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, several endpoints in the Cloud AdmissionController may be susceptible to a DoS attack if an HTTP request containing a very large Body is sent to it.… | |
| Modificada | Alta (7.5) | 1.7% | — | Linuxfoundation Kubeedge | 11/7/2022 | 17/6/2026 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at Edge. Prior to versions 1.11.1, 1.10.2, and 1.9.4, the ServiceBus server on the edge side may be susceptible to a DoS attack if an HTTP request containing a very large Body is sent to it. It is… | |
| Modificada | Media (5.7) | 0.82% | — | Linuxfoundation Kubeedge | 27/6/2022 | 17/6/2026 | KubeEdge is built upon Kubernetes and extends native containerized application orchestration and device management to hosts at the Edge. In affected versions a malicious message response from KubeEdge can crash the CSI Driver controller server by triggering a nil-pointer dereference panic. As a consequence, the CSI… | |
| Modificada | Media (5.7) | 0.61% | — | Linuxfoundation Kubeedge | 27/6/2022 | 17/6/2026 | KubeEdge is built upon Kubernetes and extends native containerized application orchestration and device management to hosts at the Edge. In affected versions a malicious message can crash CloudCore by triggering a nil-pointer dereference in the UDS Server. Since the UDS Server only communicates with the CSI Driver on… |