GHSA-mfv7-gq43-w965
GitHub Security Advisory
Incomplete List of Disallowed Inputs in Kubernetes
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or link-local range, but the same validation was not performed on EndpointSlice IPs.
Affected Packages
Go
k8s.io/kubernetes
Affected versions:
1.16.0
(fixed in 1.18.19)
Go
k8s.io/kubernetes
Affected versions:
1.19.0
(fixed in 1.19.11)
Go
k8s.io/kubernetes
Affected versions:
1.20.0
(fixed in 1.20.7)
Go
k8s.io/kubernetes
Affected versions:
1.21.0
(fixed in 1.21.1)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: November 25, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.