📦 Kubevirt

by Kubevirt

🔍 What is Kubevirt?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-64324

HIGH CVSS 7.7 Nov 18, 2025

A logic bug in KubeVirt's hostDisk feature allows attackers to read and write arbitrary files owned by privileged users on the host system. This affects KubeVirt versions before 1.6.1 and 1.7.0 when u...

CVE-2023-26484

HIGH CVSS 8.2 Mar 15, 2023

This vulnerability in KubeVirt allows a compromised Kubernetes node to use the virt-handler service account to modify other node specifications, potentially leading to cluster-wide privilege escalatio...

CVE-2025-64436

MEDIUM CVSS 5.3 Nov 7, 2025

This vulnerability in KubeVirt allows attackers with access to the virt-handler service account to force VM migrations to compromised nodes or mark all nodes as unschedulable. This affects KubeVirt de...

CVE-2025-64437

MEDIUM CVSS 5.0 Nov 7, 2025

This CVE allows attackers who control the virt-launcher pod filesystem to change ownership of arbitrary host node files to the unprivileged UID 107 user, compromising data confidentiality, integrity, ...

CVE-2025-64433

MEDIUM CVSS 6.5 Nov 7, 2025

This vulnerability in KubeVirt allows a malicious user with control over a PersistentVolumeClaim (PVC) to read arbitrary files from the virt-launcher pod's file system. Attackers can exploit improper ...

CVE-2025-64434

MEDIUM CVSS 4.7 Nov 7, 2025

This vulnerability in KubeVirt allows an attacker who compromises a virt-handler instance to impersonate virt-api using shared credentials, enabling privileged operations against other virt-handler in...

CVE-2025-64435

MEDIUM CVSS 5.3 Nov 7, 2025

This vulnerability in KubeVirt allows attackers to disrupt virtual machine control by creating malicious pods with matching labels. Attackers can cause denial-of-service by misleading the virt-control...

CVE-2025-64432

MEDIUM CVSS 4.7 Nov 7, 2025

This vulnerability in KubeVirt allows attackers to bypass RBAC controls by exploiting a flawed mTLS authentication implementation in the virt-api component. Attackers can impersonate the Kubernetes AP...