CVE-2026-32254

Kube-router is a turnkey solution for Kubernetes networking. Prior to version 2.8.0, Kube-router's proxy module does not validate externalIPs or loadBalancer IPs before programming them into the node's network configuration. Version 2.8.0 contains a patch for the issue. Available workarounds include enabling DenyServiceExternalIPs feature gate, deploying admission policy, restricting service creation RBAC, monitoring service changes, and applying BGP prefix filtering.
Configurations

Configuration 1 (hide)

cpe:2.3:a:kube-router:kube-router:*:*:*:*:*:kubernetes:*:*

History

19 Mar 2026, 18:06

Type Values Removed Values Added
CPE cpe:2.3:a:kube-router:kube-router:*:*:*:*:*:kubernetes:*:*
First Time Kube-router kube-router
Kube-router
References () https://github.com/cloudnativelabs/kube-router/commit/a1f0b2eea3ee0f66b9a5b5c49dcb714619ccd456 - () https://github.com/cloudnativelabs/kube-router/commit/a1f0b2eea3ee0f66b9a5b5c49dcb714619ccd456 - Patch
References () https://github.com/cloudnativelabs/kube-router/releases/tag/v2.8.0 - () https://github.com/cloudnativelabs/kube-router/releases/tag/v2.8.0 - Product, Release Notes
References () https://github.com/cloudnativelabs/kube-router/security/advisories/GHSA-phqm-jgc3-qf8g - () https://github.com/cloudnativelabs/kube-router/security/advisories/GHSA-phqm-jgc3-qf8g - Exploit, Mitigation, Patch, Vendor Advisory

18 Mar 2026, 14:16

Type Values Removed Values Added
References () https://github.com/cloudnativelabs/kube-router/security/advisories/GHSA-phqm-jgc3-qf8g - () https://github.com/cloudnativelabs/kube-router/security/advisories/GHSA-phqm-jgc3-qf8g -
Summary
  • (es) Kube-router es una solución llave en mano para redes de Kubernetes. Antes de la versión 2.8.0, el módulo proxy de Kube-router no valida las externalIPs o las IPs de loadBalancer antes de programarlas en la configuración de red del nodo. La versión 2.8.0 contiene un parche para el problema. Las soluciones alternativas disponibles incluyen habilitar la puerta de características DenyServiceExternalIPs, desplegar una política de admisión, restringir el RBAC de creación de servicios, monitorear los cambios de servicio y aplicar el filtrado de prefijos BGP.

18 Mar 2026, 04:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-18 04:17

Updated : 2026-03-19 18:06


NVD link : CVE-2026-32254

Mitre link : CVE-2026-32254

CVE.ORG link : CVE-2026-32254


JSON object : View

Products Affected

kube-router

  • kube-router
CWE
CWE-284

Improper Access Control