Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. k8s.io/kubernetes
  4. ›
  5. CVE-2025-5187

CVE-2025-5187: Kubernetes Nodes can delete themselves by adding an OwnerReference

August 27, 2025

A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection.

References

  • github.com/advisories/GHSA-4x4m-3c2p-qppc
  • github.com/kubernetes/kubernetes
  • github.com/kubernetes/kubernetes/commit/a2d98cac56a0c5cb2d8abc4d087fc00846b3bc0f
  • github.com/kubernetes/kubernetes/issues/133471
  • groups.google.com/g/kubernetes-security-announce/c/znSNY7XCztE
  • nvd.nist.gov/vuln/detail/CVE-2025-5187

Code Behaviors & Features

Detect and mitigate CVE-2025-5187 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.31.12, all versions starting from 1.32.0-alpha.0 before 1.32.8, all versions starting from 1.33.0-alpha.0 before 1.33.4

Fixed versions

  • 1.31.12
  • 1.32.8
  • 1.33.4

Solution

Upgrade to versions 1.31.12, 1.32.8, 1.33.4 or above.

Impact 6.7 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L

Learn more about CVSS

Weakness

  • CWE-863: Incorrect Authorization

Source file

go/k8s.io/kubernetes/CVE-2025-5187.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Thu, 28 Aug 2025 00:19:02 +0000.