CVE-2025-13281 Details
Description
A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).
A half-blind Server Side Request Forgery (SSRF) vulnerability has been identified in the Kubernetes kube-controller-manager, specifically when the in-tree Portworx StorageClass is used. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints within the control plane's host network, including link-local or loopback services. The issue arises because kube-controller-manager can be manipulated to send GET requests from the host network, exposing the response data through event objects created by the manager.
Users can upgrade to kube-controller-manager versions 1.32.10, 1.33.6, or 1.34.2, or enable the CSIMigrationPortworx feature gate if it was manually disabled.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 14, 2025CISA-ADP
Assessed Dec 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2025/12/01/4 | CVE | Broken LinkMailing List |
| https://github.com/kubernetes/kubernetes/issues/135525 | [email protected] | Issue TrackingTechnical DescriptionVendor |
| https://groups.google.com/g/kubernetes-security-announce/c/EORqZg0k1l4/m/TtD-q0v7AgAJ | [email protected] | AdvisoryMailing ListRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| kube-controller-manager | <= v1.30.14 (semver) <= v1.31.14 (semver) <= v1.32.9 (semver) <= v1.33.5 (semver) <= v1.34.1 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 14, 2025 | New CVE Received | [email protected] |
| Dec 14, 2025 | CVE Modified | CVE |
Volerion