GHSA-x6mj-w4jf-jmgw
GitHub Security Advisory
Server Side Request Forgery (SSRF) in Kubernetes
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a Server Side Request Forgery (SSRF) that allows certain authorized users to leak up to 500 bytes of arbitrary information from unprotected endpoints within the master's host network (such as link-local or loopback services).
Affected Packages
Go
k8s.io/kubernetes
Affected versions:
1.18.0
(fixed in 1.18.1)
Go
k8s.io/kubernetes
Affected versions:
1.17.0
(fixed in 1.17.4)
Go
k8s.io/kubernetes
Affected versions:
1.16.0
(fixed in 1.16.9)
Go
k8s.io/kubernetes
Affected versions:
0
(fixed in 1.15.12)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: November 26, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.