Kubevirt
This hub aggregates every CVE we track for Kubevirt, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
19
CVEs tracked
1
Critical
5
High
0
In CISA KEV
Severity distribution
MEDIUM12HIGH5LOW1CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
7
0
0
0
0
0
0
6
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Kubevirt.
- CVE-2026-13434Virt-controller-rhel9: kubevirt: kubevirt: multus default-network annotation injection via unvalidated tenant networkname when externalnetresourceinjection is enabled4.9
- CVE-2026-13322Kubevirt: virt-handler-rhel9: kubevirt: unbounded virtio-serial readline in virt-handler causes oom denial of service3.8
- CVE-2026-13318Virt-api-rhel9: kubevirt: kubevirt: ssrf in virt-api port-forward via unvalidated guest-agent-reported ip6.4
- CVE-2026-13218Kubevirt: kubevirt: symlink following in writetocachedfile allows host file overwrite from virt-launcher4.2
- CVE-2026-13201Kubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enables notify socket hijacking and node-level vm disruption7.3
- CVE-2026-13208Kubevirt: virt-handler-rhel9: kubevirt: virt-handler notify server trusts vmi identity from unauthenticated grpc request body6.5
- CVE-2025-64324KubeVirt Vulnerable to Arbitrary Host File Read and Write7.7
- CVE-2025-64433KubeVirt Arbitrary Container File Read6.5
- CVE-2025-64437KubeVirt Isolation Detection Flaw Allows Arbitrary File Permission Changes5.0
- CVE-2025-64436KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes5.3
- CVE-2025-64435KubeVirt VMI Denial-of-Service (DoS) Using Pod Impersonation5.3
- CVE-2025-64434KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing4.7
- CVE-2025-64432KubeVirt Affected by an Authentication Bypass in Kubernetes Aggregation Layer4.7
- CVE-2024-33394An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.5.9
- CVE-2023-26484On a compromised KubeVirt node, the virt-handler service account can be used to modify all node specs8.2
Product normalization is registry-driven with AI assist and human review. How it works