Vulnerability in NodeRestriction Admission Controller of Kubernetes
CVE-2025-5187
What is CVE-2025-5187?
A security flaw exists in the NodeRestriction admission controller within Kubernetes clusters, granting node users the ability to delete their respective node objects. This occurs when a user patches themselves with an OwnerReference pointing to a cluster-scoped resource. If that OwnerReference is not present or is removed, the corresponding node object is scheduled for deletion through the garbage collection process, which could lead to unintended consequences in cluster management and stability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Kubernetes v1.31.0
Kubernetes v1.32.0
Kubernetes v1.33.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved