GHSA-4x4m-3c2p-qppc
Dashboard / Vulnerabilities / GHSA-4x4m-3c2p-qppc
GHSA-4x4m-3c2p-qppc
Summary: Kubernetes Nodes can delete themselves by adding an OwnerReference
Details: A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection.
References: https://nvd.nist.gov/vuln/detail/CVE-2025-5187, https://github.com/kubernetes/kubernetes/issues/133471, https://github.com/kubernetes/kubernetes/commit/a2d98cac56a0c5cb2d8abc4d087fc00846b3bc0f, https://github.com/kubernetes/kubernetes, https://groups.google.com/g/kubernetes-security-announce/c/znSNY7XCztE
Affected packages
Package
Name: k8s.io/kubernetes
Purl: pkg:golang/k8s.io/kubernetes
Affected ranges
Type: SEMVER
Events:
