Memory Exhaustion Vulnerability in KubeEdge from KubeEdge Technologies
CVE-2026-62370
What is CVE-2026-62370?
KubeEdge, an open-source platform for extending container orchestration capabilities to Edge hosts, is susceptible to a memory exhaustion vulnerability. Versions ranging from 1.0.0 to 1.21.2, 1.22.2, and 1.23.1 are affected due to improper handling of the PackageHeader.PayloadLen value in the package-processing flow. An authenticated edge peer can exploit this vulnerability by sending maliciously crafted messages with excessively large payloads, leading to memory allocation issues that may cause the CloudHub to terminate or enter restart loops, thereby disrupting cloud-edge communication. This vulnerability does not allow unauthorized access or code execution and has been rectified in versions 1.21.2, 1.22.2, and 1.23.1.
Affected Version(s)
kubeedge >= 1.0.0, < 1.21.2 < 1.0.0, 1.21.2
kubeedge >= 1.22.0, < 1.22.2 < 1.22.0, 1.22.2
kubeedge >= 1.23.0, < 1.23.1 < 1.23.0, 1.23.1
