CVE-2025-5187: Kubernetes
Medium severity, CVSS 6.7. EPSS: 0.6% chance of exploitation in the next 30 days.
A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection.
Affected products
- Kubernetes Kubernetes: from v1.31.0, up to and including v1.31.11; from v1.32.0, up to and including v1.32.7; from v1.33.0, up to and including v1.33.3
Published 2025-08-27. Last modified 2026-06-17.