VYPR
Medium severity6.2NVD Advisory· Published Feb 13, 2025· Updated Apr 15, 2026

CVE-2025-0426

CVE-2025-0426

Description

A security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthenticated kubelet read-only HTTP endpoint may cause a Node Denial of Service by filling the Node's disk.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
k8s.io/kubernetesGo
>= 1.32.0, < 1.32.21.32.2
k8s.io/kubernetesGo
>= 1.31.0, < 1.31.61.31.6
k8s.io/kubernetesGo
>= 1.30.0, < 1.30.101.30.10
k8s.io/kubernetesGo
< 1.29.141.29.14

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.