| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-phqm-jgc3-qf8g | Kube-router Proxy Module Blindly Trusts ExternalIPs/LoadBalancer IPs Enabling Cluster-Wide Traffic Hijacking and DNS DoS |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 18 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Mar 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cloudnativelabs
Cloudnativelabs kube-router |
|
| Vendors & Products |
Cloudnativelabs
Cloudnativelabs kube-router |
Wed, 18 Mar 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kube-router is a turnkey solution for Kubernetes networking. Prior to version 2.8.0, Kube-router's proxy module does not validate externalIPs or loadBalancer IPs before programming them into the node's network configuration. Version 2.8.0 contains a patch for the issue. Available workarounds include enabling DenyServiceExternalIPs feature gate, deploying admission policy, restricting service creation RBAC, monitoring service changes, and applying BGP prefix filtering. | |
| Title | Kube-router Proxy Module Blindly Trusts ExternalIPs/LoadBalancer IPs Enabling Cluster-Wide Traffic Hijacking and DNS DoS | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-18T13:35:56.647Z
Reserved: 2026-03-11T14:47:05.686Z
Link: CVE-2026-32254
Updated: 2026-03-18T13:35:47.222Z
Status : Awaiting Analysis
Published: 2026-03-18T04:17:24.340
Modified: 2026-03-18T14:52:44.227
Link: CVE-2026-32254
No data.
OpenCVE Enrichment
Updated: 2026-03-18T10:41:55Z
Github GHSA