CVE-2025-13281: Kubernetes
Medium severity, CVSS 5.8. EPSS: 0.4% chance of exploitation in the next 30 days.
A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).
Affected products
- Kubernetes Kubernetes: from v1.30.0, up to and including v1.30.14; from v1.31.0, up to and including v1.31.14; from v1.32.0, up to and including v1.32.9; from v1.33.0, up to and including v1.33.5; from v1.34.0, up to and including v1.34.1
Published 2025-12-14. Last modified 2026-06-17.