Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-phqm-jgc3-qf8g | Kube-router Proxy Module Blindly Trusts ExternalIPs/LoadBalancer IPs Enabling Cluster-Wide Traffic Hijacking and DNS DoS |
Thu, 19 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kube-router
Kube-router kube-router |
|
| CPEs | cpe:2.3:a:kube-router:kube-router:*:*:*:*:*:kubernetes:*:* | |
| Vendors & Products |
Kube-router
Kube-router kube-router |
Wed, 18 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cloudnativelabs
Cloudnativelabs kube-router |
|
| Vendors & Products |
Cloudnativelabs
Cloudnativelabs kube-router |
Wed, 18 Mar 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kube-router is a turnkey solution for Kubernetes networking. Prior to version 2.8.0, Kube-router's proxy module does not validate externalIPs or loadBalancer IPs before programming them into the node's network configuration. Version 2.8.0 contains a patch for the issue. Available workarounds include enabling DenyServiceExternalIPs feature gate, deploying admission policy, restricting service creation RBAC, monitoring service changes, and applying BGP prefix filtering. | |
| Title | Kube-router Proxy Module Blindly Trusts ExternalIPs/LoadBalancer IPs Enabling Cluster-Wide Traffic Hijacking and DNS DoS | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-18T13:35:56.647Z
Reserved: 2026-03-11T14:47:05.686Z
Link: CVE-2026-32254
Updated: 2026-03-18T13:35:47.222Z
Status : Analyzed
Published: 2026-03-18T04:17:24.340
Modified: 2026-03-19T18:06:51.620
Link: CVE-2026-32254
No data.
OpenCVE Enrichment
Updated: 2026-03-24T10:59:25Z
Github GHSA