VYPR
Vendor

Submariner Io

Products
1
CVEs
3
Across products
3
Status
Private

Products

1

Recent CVEs

3
  • CVE-2026-66786CriSep 2, 2026
    risk 0.59cvss 9.1epss 0.01

    A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by publishing a CableName that includes newlines and…

  • CVE-2024-5042MedMay 17, 2024
    risk 0.36cvss 6.6epss 0.01

    A flaw was found in the Submariner project. Due to unnecessary role-based access control permissions, a privileged attacker can run a malicious container on a node that may allow them to steal service account tokens and further compromise other nodes and potentially the entire…

  • CVE-2026-66785LowAug 20, 2026
    risk 0.16cvss 2.5epss 0.00

    A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer clusters) by publishing a specially crafted network endpoint. The system fails to properly validate the network subnets provided…