CVE-2026-32254
HIGHkube-router <2.8.0 Proxy Module - ExternalIP Traffic Hijacking
Title source: manualDescription
Kube-router is a turnkey solution for Kubernetes networking. Prior to version 2.8.0, Kube-router's proxy module does not validate externalIPs or loadBalancer IPs before programming them into the node's network configuration. Version 2.8.0 contains a patch for the issue. Available workarounds include enabling DenyServiceExternalIPs feature gate, deploying admission policy, restricting service creation RBAC, monitoring service changes, and applying BGP prefix filtering.
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/cloudnativelabs/kube-router/security/advisories/GHSA-phqm-jgc3-qf8g
X_Refsource_Misc x_refsource_misc
https://github.com/cloudnativelabs/kube-router/commit/a1f0b2eea3ee0f66b9a5b5c49dcb714619ccd456
X_Refsource_Misc x_refsource_misc
https://github.com/cloudnativelabs/kube-router/releases/tag/v2.8.0
Scores
CVSS v3
7.1
EPSS
0.0030
EPSS Percentile
21.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-284
Status
published
Products (3)
cloudnativelabs/kube-router
0 - 2.8.0Go
cloudnativelabs/kube-router
< 2.8.0
kube-router/kube-router
< 2.8.0
Published
Mar 18, 2026
Tracked Since
Mar 18, 2026