Vulnerability in NodeRestriction Admission Controller of Kubernetes
CVE-2025-5187

6.7MEDIUM

Key Information:

Vendor

Kubernetes

Vendor
CVE Published:
27 August 2025

What is CVE-2025-5187?

A security flaw exists in the NodeRestriction admission controller within Kubernetes clusters, granting node users the ability to delete their respective node objects. This occurs when a user patches themselves with an OwnerReference pointing to a cluster-scoped resource. If that OwnerReference is not present or is removed, the corresponding node object is scheduled for deletion through the garbage collection process, which could lead to unintended consequences in cluster management and stability.

Affected Version(s)

Kubernetes v1.31.0

Kubernetes v1.32.0

Kubernetes v1.33.0

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Paul Viossat
.
CVE-2025-5187 : Vulnerability in NodeRestriction Admission Controller of Kubernetes