GHSA-h7wq-jj8r-qm7p
GitHub Security Advisory
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
A flaw was found in kube-controller-manager. This issue occurs when the initial application of a HPA config YAML lacking a .spec.behavior.scaleUp block causes a denial of service due to KCM pods going into restart churn.
Affected Packages
Go
k8s.io/kubernetes
Affected versions:
0
(fixed in 1.27.0-alpha.1)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: June 18, 2025 6:25 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.