Loading HuntDB...

GHSA-mfv7-gq43-w965

GitHub Security Advisory

Incomplete List of Disallowed Inputs in Kubernetes

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

A security issue was discovered in Kubernetes where a user may be able to redirect pod traffic to private networks on a Node. Kubernetes already prevents creation of Endpoint IPs in the localhost or link-local range, but the same validation was not performed on EndpointSlice IPs.

Affected Packages

Go k8s.io/kubernetes
Affected versions: 1.16.0 (fixed in 1.18.19)
Go k8s.io/kubernetes
Affected versions: 1.19.0 (fixed in 1.19.11)
Go k8s.io/kubernetes
Affected versions: 1.20.0 (fixed in 1.20.7)
Go k8s.io/kubernetes
Affected versions: 1.21.0 (fixed in 1.21.1)

Related CVEs

Key Information

GHSA ID
GHSA-mfv7-gq43-w965
Published
September 7, 2021 11:09 PM
Last Modified
September 14, 2021 6:47 PM
CVSS Score
5.0 /10
Primary Ecosystem
Go
Primary Package
k8s.io/kubernetes
GitHub Reviewed
✓ Yes

Dataset

Last updated: November 25, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.