SecAlerts
K

KubeVirt

Security Risk Profile

34
/100
low

Security Risk Score

Comprehensive risk assessment based on 33 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from March 25, 2019 to present

33
Total CVEs
13
Critical+High
0
Exploited
8
Unpatched

Threat Assessment

Avg CVSS
6.4
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
8
Critical/High
Risk Level
34/100
low

Severity Distribution

Critical
2
High
11
Medium
19
Low
1

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
3

Age Distribution

Common Weaknesses (CWE)

1
Path Traversal
5
2
Input Validation
3
3
Infoleak
2
4
Race Condition
2
5
SSRF
1

Most Affected Products

1. Kubevirt Kubevirt Kubernetes32
2. go/kubevirt.io/kubevirt17
3. redhat Openshift Virtualization7
4. Microsoft azl3 kubevirt 1.5.0-57
5. Microsoft cbl2 kubevirt 0.59.0-307

Recent Vulnerabilities

See more →
CVE-2026-17527
CVSS 7.7high

Virt-cdi-operator: containerized-data-importer: cdi.kubevirt.io:view aggregated clusterrole grants create on datavolumes/source, allowing unauthorized pvc clone

Jul 27, 2026🔧 No Patch
CVE-2026-13622
CVSS 8.8high

Kubevirt: virt-handler-rhel9: kubevirt: virt-handler migration proxy follows symlinks allowing container escape to host

Jun 29, 2026🔧 No Patch
CVE-2026-13434
CVSS 4.9medium

Virt-controller-rhel9: kubevirt: kubevirt: multus default-network annotation injection via unvalidated tenant networkname when externalnetresourceinjection is enabled

Jun 26, 2026🔧 No Patch
REDHAT-BUG-2493576
CVSS 4.0medium
Jun 26, 2026🔧 No Patch
CVE-2026-13325
CVSS 8.5high

Virt-handler-rhel9: kubevirt: kubevirt: disabletls migration setting removes authentication, exposing unauthenticated virtqemud proxy on all interfaces

Jun 26, 2026🔧 No Patch
REDHAT-BUG-2493378
CVSS 4.0medium
Jun 26, 2026🔧 No Patch
CVE-2026-13322
CVSS 3.8low

Kubevirt: virt-handler-rhel9: kubevirt: unbounded virtio-serial readline in virt-handler causes oom denial of service

Jun 25, 2026🔧 No Patch
CVE-2026-13318
CVSS 6.4medium

Virt-api-rhel9: kubevirt: kubevirt: ssrf in virt-api port-forward via unvalidated guest-agent-reported ip

Jun 25, 2026🔧 No Patch
CVE-2026-13218
CVSS 4.2medium

Kubevirt: kubevirt: symlink following in writetocachedfile allows host file overwrite from virt-launcher

Jun 25, 2026🔧 No Patch
CVE-2026-13208
CVSS 6.5medium

Kubevirt: virt-handler-rhel9: kubevirt: virt-handler notify server trusts vmi identity from unauthenticated grpc request body

Jun 24, 2026

Monitor KubeVirt in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.