Kubernetes
Kubernetes
Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.
This CVE identity is linked to the Lifecycle record Kubernetes. Use that record for publisher support phases and retirement dates.
A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.
CVE-observed version history
| CVE | Published | Affected versions | Fixed version information | Publisher evidence |
|---|---|---|---|---|
| CVE-2026-19444 | 28 Sep 2026 | Kubernetes: v1.36.0 ≤ v1.36.4, v1.35.0 ≤ v1.35.8, v1.34.0 ≤ v1.34.11, v1.0 ≤ v1.33.13 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2025-13281 | 14 Dec 2025 | v1.30.0 ≤ v1.30.14; v1.31.0 ≤ v1.31.14; v1.32.0 ≤ v1.32.9; v1.33.0 ≤ v1.33.5; v1.34.0 ≤ v1.34.1 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2025-5187 | 27 Aug 2025 | v1.31.0 ≤ v1.31.11; v1.32.0 ≤ v1.32.7; v1.33.0 ≤ v1.33.3 | For OpenShift Container Platform 4.18 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html/release_notes/ You can download the oc tool and use it to inspect release image metadata for x86_64, s390x, ppc64le, and aarch64 architectures. The image digests can be found at https://quay.io/repository/openshift-release-dev/ocp-release?tab=tags. The sha values for the release are as follows: (For x86_64 architecture) The image digest is sha256:2db093f063ad5310fa4e5ed2d2eda4bad5215c47092b72d1cfafbcfdbf1f4dd2 (For s390x architecture) The image digest is sha256:578636cf6c118e3f27e73e2d44895dd5dd619c50b8f1f3a32e08b1df628f9dcb (For ppc64le architecture) The image digest is sha256:6d3380150dd6b9fe1044503a96bf42199b271e7758466649c4b6fb08ff25c559 (For aarch64 architecture) The image digest is sha256:63d620c118a8bfb4b9d4344715a648327dcdcbd5d66488ae8c0f25cf63d98671 All OpenShift Container Platform 4.18 users are advised to upgrade to these updated packages and images when they are available in the appropriate release channel. To check for available updates, use the OpenShift CLI (oc) or web console. Instructions for upgrading a cluster are available at https://docs.redhat.com/en/documentation/openshift_container_platform/4.18/html-single/updating_clusters/index#updating-cluster-cli. | Update reference ↗ |
| CVE-2025-4563 | 23 Jun 2025 | v1.32.0 - v1.32.5; v1.33.0 - v1.33.1 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2024-5321 | 18 Jul 2024 | 1.27.0 ≤ 1.27.15; 1.28.0 ≤ 1.28.11; 1.29.0 ≤ 1.29.6; 1.30.0 ≤ 1.30.2 | 1.27.16; 1.28.12; 1.29.7; 1.30.3 | Update reference ↗ |
| CVE-2024-3177 | 22 Apr 2024 | ≤ 1.27.12; v1.28.0 - v1.28.8; v1.29.0 - v1.29.3 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2021-25736 | 30 Oct 2023 | ≤ v1.20.5 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2023-2728 | 3 Jul 2023 | v1.24.14 ≤ <=; v1.25.0 - v1.25.10; v1.26.0 - v1.26.5; v1.27.0 - v1.27.2 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2023-2727 | 3 Jul 2023 | v1.24.14 ≤ <=; v1.25.0 - v1.25.10; v1.26.0 - v1.26.5; v1.27.0 - v1.27.2 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2023-2431 | 16 Jun 2023 | < v1.24.14; v1.25.0 < v1.25.9; v1.26.0 < v1.26.4; v1.27.0 < v1.27.1 | For Windows Machine Config Operator upgrades, see the following documentation: https://docs.openshift.com/container-platform/latest/windows_containers/windows-node-upgrades.html | Update reference ↗ |
| CVE-2021-25749 | 24 May 2023 | kubelet v1.22.0 - v1.22.13 < v1.22.14; kubelet v1.23.0 - v1.23.10 < v1.23.11; kubelet v1.24.0 - v1.24.4 < v1.24.5 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2022-3294 | 1 Mar 2023 | unspecified ≤ v1.25.3; unspecified ≤ v1.24.7; unspecified ≤ v1.23.13; unspecified ≤ v1.22.15 | MicroShift 4.12.1 - RPMs | Update reference ↗ |
| CVE-2022-3162 | 1 Mar 2023 | unspecified ≤ v1.25.3; unspecified ≤ v1.24.7; unspecified ≤ v1.23.13; unspecified ≤ v1.22.15 | MicroShift 4.12.4 - RPMs For MicroShift 4.12, read the following documentation, which will be updated shortly for this release, for important instructions on how to install the latest RPMs and fully apply this asynchronous errata update: https://access.redhat.com/documentation/en-us/red_hat_build_of_microshift/4.12/html/release_notes/index | Update reference ↗ |
| CVE-2020-8562 | 1 Feb 2022 | < * | No fixed version is explicitly recorded in the structured CVE data. | Update reference ↗ |
| CVE-2021-25743 | 7 Jan 2022 | unspecified ≤ 1.23.1; next of 1.23.1 < unspecified; unspecified ≤ 1.22.5; next of 1.22.5 < unspecified; unspecified ≤ 1.21.8; next of 1.21.8 < unspecified; unspecified ≤ 1.20.14; next of 1.20.14 < unspecified | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2021-25741 | 20 Sep 2021 | unspecified ≤ 1.19.14; unspecified ≤ 1.20.10; unspecified ≤ 1.21.4; unspecified ≤ 1.22.1 | No fixed version is explicitly recorded in the structured CVE data. | Update reference ↗ |
| CVE-2021-25740 | 20 Sep 2021 | < * | No fixed version is explicitly recorded in the structured CVE data. | Update reference ↗ |
| CVE-2020-8561 | 20 Sep 2021 | < * | No fixed version is explicitly recorded in the structured CVE data. | Update reference ↗ |
| CVE-2021-25737 | 6 Sep 2021 | unspecified ≤ 1.18.18; unspecified ≤ 1.19.10; unspecified ≤ 1.20.6; unspecified ≤ 1.21.0 | For OpenShift Container Platform 4.8 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.8/release_notes/ocp-4-8-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.8/updating/updating-cluster-cli.html | Update reference ↗ |
| CVE-2021-25735 | 6 Sep 2021 | unspecified ≤ 1.18.17; unspecified ≤ 1.19.9; unspecified ≤ 1.20.5 | For OpenShift Container Platform 4.8 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errata update: https://docs.openshift.com/container-platform/4.8/release_notes/ocp-4-8-release-notes.html Details on how to access this content are available at https://docs.openshift.com/container-platform/4.8/updating/updating-cluster-cli.html | Update reference ↗ |
| CVE-2020-8554 | 21 Jan 2021 | < * | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2020-8563 | 7 Dec 2020 | < 1.19.3 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2020-8564 | 7 Dec 2020 | < 1.19.3; < 1.18.10; < 1.17.13 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2020-8565 | 7 Dec 2020 | <= 1.19.3; <= 1.18.10; <= 1.17.13; < 1.20.0-alpha2 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2020-8566 | 7 Dec 2020 | < 1.19.3; < 1.18.10; < 1.17.13 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2020-8558 | 27 Jul 2020 | prior to 1.18.4; prior to 1.17.7; prior to 1.16.11; 1.15; 1.14; 1.13; 1.12; 1.11 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2020-8557 | 23 Jul 2020 | 1.15; 1.14; 1.13; 1.12; 1.11; 1.10; 1.9; 1.8 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2019-11252 | 23 Jul 2020 | 1.16; 1.17; 1.6; 1.7; 1.8; 1.9; 1.10; 1.11 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2020-8559 | 22 Jul 2020 | 1.6; 1.7; 1.8; 1.9; 1.10; 1.11; 1.12; 1.13 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2020-8555 | 4 Jun 2020 | 1.18.0; 1.1; 1.2; 1.3; 1.4; 1.5; 1.6; 1.7 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2019-11254 | 1 Apr 2020 | prior to 1.15.10; prior to 1.16.7; prior to 1.17.3; 1.1; 1.2; 1.3; 1.4; 1.5 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2020-8552 | 27 Mar 2020 | unspecified < v1.17.3; unspecified < v1.16.7; unspecified < v1.15.10 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2020-8551 | 27 Mar 2020 | unspecified < v1.17.3; unspecified < v1.16.7; unspecified < v1.15.10 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2019-11251 | 3 Feb 2020 | prior to 1.13.11; prior to 1.14.7; prior to 1.15.4; 1.1; 1.2; 1.3; 1.4; 1.5 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2018-1002102 | 5 Dec 2019 | v1.14 < v1.14.0 | No fixed version is explicitly recorded in the structured CVE data. | Update reference ↗ |
| CVE-2019-11253 | 17 Oct 2019 | prior to 1.13.12; prior to 1.14.8; prior to 1.15.5; prior to 1.16.2; 1.1; 1.2; 1.3; 1.4 | No fixed version is explicitly recorded in the structured CVE data. | Update reference ↗ |
| CVE-2019-11250 | 29 Aug 2019 | prior to 1.16 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2019-11249 | 29 Aug 2019 | prior to 1.13.9; prior to 1.14.5; prior to 1.15.2; 1.1; 1.2; 1.4; 1.5; 1.6 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2019-11248 | 29 Aug 2019 | prior to 1.12.10; prior to 1.13.8; prior to 1.14.4; 1.1; 1.2; 1.4; 1.5; 1.6 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2019-11247 | 29 Aug 2019 | prior to 1.13.9; prior to 1.14.5; prior to 1.15.2; 1.7; 1.8; 1.9; 1.10; 1.11 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2019-11246 | 29 Aug 2019 | prior to 1.12.9; prior to 1.13.6; prior to 1.14.2; 1.1; 1.2; 1.4; 1.5; 1.6 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2019-11245 | 29 Aug 2019 | v1.13.6; v1.14.2 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2019-11244 | 22 Apr 2019 | v1.8.0 < v1.8*; v1.9.0 < v1.9*; v1.10.0 < v1.10*; v1.11.0 < v1.11*; v1.12.0 < v1.12*; v1.13.0 < v1.13*; v1.14.0 < v1.14* | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2019-11243 | 22 Apr 2019 | v1.12 ≤ v1.12.4; v1.13 ≤ v1.13.0 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2019-1002101 | 1 Apr 2019 | 1.1-1.10; 1.11 < 1.11.9; 1.12 < 1.12.7; 1.13 < 1.13.5 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2019-1002100 | 1 Apr 2019 | v1.0.x; v1.1.x; v1.2.x; v1.3.x; v1.4.x; v1.5.x; v1.6.x; v1.7.x | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2018-1002105 | 5 Dec 2018 | v1.0.x; v1.1.x; v1.2.x; v1.3.x; v1.4.x; v1.5.x; v1.6.x; v1.7.x | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2018-1002101 | 5 Dec 2018 | unspecified < v1.9.10; unspecified < v1.10.6; unspecified < v1.11.2 | An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. | Update reference ↗ |
| CVE-2018-1002100 | 1 Jun 2018 | v1.5.x; v1.6.x; v1.7.x; v1.8.x; unspecified < v1.9.6 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2017-1002102 | 13 Mar 2018 | v1.3.x; v1.4.x; v1.5.x; v1.6.x; unspecified < v1.7.14; unspecified < v1.8.9; unspecified < v1.9.4 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
How this record is maintained
The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.