CVE-2026-24005

Kruise provides automated management of large-scale applications on Kubernetes. Prior to versions 1.8.3 and 1.7.5, PodProbeMarker allows defining custom probes with TCPSocket or HTTPGet handlers. The webhook validation does not restrict the Host field in these probe configurations. Since kruise-daemon runs with hostNetwork=true, it executes probes from the node network namespace. An attacker with PodProbeMarker creation permission can specify arbitrary Host values to trigger SSRF from the node, perform port scanning, and receive response feedback through NodePodProbe status messages. Versions 1.8.3 and 1.7.5 patch the issue.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openkruise:kruise:*:*:*:*:*:*:*:*
cpe:2.3:a:openkruise:kruise:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:22

Type Values Removed Values Added
Summary
  • (es) Kruise proporciona gestión automatizada de aplicaciones a gran escala en Kubernetes. Antes de las versiones 1.8.3 y 1.7.5, PodProbeMarker permite definir sondas personalizadas con manejadores TCPSocket o HTTPGet. La validación del webhook no restringe el campo Host en estas configuraciones de sonda. Dado que kruise-daemon se ejecuta con hostNetwork=true, ejecuta sondas desde el espacio de nombres de red del nodo. Un atacante con permiso de creación de PodProbeMarker puede especificar valores de Host arbitrarios para activar SSRF desde el nodo, realizar escaneo de puertos y recibir retroalimentación de la respuesta a través de mensajes de estado de NodePodProbe. Las versiones 1.8.3 y 1.7.5 parchean el problema.

05 Mar 2026, 00:42

Type Values Removed Values Added
References () https://github.com/openkruise/kruise/commit/94364b76adf3e8a1749a31afe809a163bed29613 - () https://github.com/openkruise/kruise/commit/94364b76adf3e8a1749a31afe809a163bed29613 - Patch
References () https://github.com/openkruise/kruise/releases/tag/v1.7.5 - () https://github.com/openkruise/kruise/releases/tag/v1.7.5 - Product, Release Notes
References () https://github.com/openkruise/kruise/releases/tag/v1.8.3 - () https://github.com/openkruise/kruise/releases/tag/v1.8.3 - Product, Release Notes
References () https://github.com/openkruise/kruise/security/advisories/GHSA-9fj4-3849-rv9g - () https://github.com/openkruise/kruise/security/advisories/GHSA-9fj4-3849-rv9g - Exploit, Mitigation, Vendor Advisory
First Time Openkruise
Openkruise kruise
CPE cpe:2.3:a:openkruise:kruise:*:*:*:*:*:*:*:*

25 Feb 2026, 19:43

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-25 19:43

Updated : 2026-06-17 10:22


NVD link : CVE-2026-24005

Mitre link : CVE-2026-24005

CVE.ORG link : CVE-2026-24005


JSON object : View

Products Affected

openkruise

  • kruise
CWE
CWE-918

Server-Side Request Forgery (SSRF)