https://seclists.org/oss-sec/2025/q4/221: [kubernetes] CVE-2025-13281: Portworx Half-Blind SSRF in kube-controller-manager
Published Dec 1, 2025
·Updated
Affected Software
1 affected component
Kubernetes kube-controller-manager>=1.31
Frequently Asked Questions
1
What is the severity of CVE-2025-13281?
CVE-2025-13281 is classified as a medium-severity vulnerability due to its potential to leak sensitive information.
2
How do I fix CVE-2025-13281?
To mitigate CVE-2025-13281, upgrade to the patched version of Kubernetes kube-controller-manager as soon as it is available.
3
What should I do if I cannot upgrade immediately for CVE-2025-13281?
If an immediate upgrade is not possible for CVE-2025-13281, consider disabling the use of the in-tree Portworx StorageClass until a fix is applied.
4
Who is affected by CVE-2025-13281?
Organizations using Kubernetes with the in-tree Portworx StorageClass are affected by CVE-2025-13281.
5
When was CVE-2025-13281 published?
CVE-2025-13281 was published on December 1, 2025.