GHSA-pmqp-h87c-mr78

    Dashboard / Vulnerabilities / GHSA-pmqp-h87c-mr78

    GHSA-pmqp-h87c-mr78

    Published: 18 May 2021Last Modified: 10 Sept 2026

    Summary: XML Entity Expansion and Improper Input Validation in Kubernetes API server

    Details: Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility. ### Specific Go Packages Affected k8s.io/kubernetes/pkg/apiserver

    Affected packages

    Package

    Name: k8s.io/kubernetes

    Purl: pkg:golang/k8s.io/kubernetes

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 1.0.0
    Fixed -1.13.12

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-pmqp-h87c-mr78 | CVE-DB