github.com
https://github.com/kubernetes/kubernetes CVE-2021-25736
MEDIUM
Windows kube-proxy LoadBalancer contention
Record summary
CVE-2021-25736 has a selected CVSS score of 5.8 (medium).
Description
Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (“spec.ports[*].port”) as a LoadBalancer Service when the LoadBalancer controller does not set the “status.loadBalancer.ingress[].ip” field. Clusters where the LoadBalancer controller sets the “status.loadBalancer.ingress[].ip” field are unaffected.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 12, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
KubernetesBrowse Kubernetes / KubernetesDefault status: unaffected | CVE List | Through v1.20.5 | affected |
k8s.io/kubernetesBrowse Go / k8s.io/kubernetes | GitHub Advisory | Before 1.21.0 · Fixed in 1.21.0 | affected |
References
6github.com
https://github.com/kubernetes/kubernetes/commit/b014610de3e5cf1bb0f7844b5758d29fc18b75e6 github.com
https://github.com/kubernetes/kubernetes/pull/99958 groups.google.com
https://groups.google.com/g/kubernetes-security-announce/c/lIoOPObO51Q/m/O15LOazPAgAJ nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-25736 security.netapp.com
https://security.netapp.com/advisory/ntap-20231221-0003