Record summary

CVE-2025-5187 has a selected CVSS score of 6.7 (medium).

Description

A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 28, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected

CVE Listv1.31.0 to ≤ v1.31.11affected
v1.32.0 to ≤ v1.32.7affected
v1.33.0 to ≤ v1.33.3affected
GitHub AdvisoryBefore 1.31.12 · Fixed in 1.31.12affected
1.32.0-alpha.0 to < 1.32.8 · Fixed in 1.32.8affected
1.33.0-alpha.0 to < 1.33.4 · Fixed in 1.33.4affected

References

5