GCP-2026-006
<p><strong>Published: </strong>2026-01-29</p><p><strong>Updated: </strong>2026-02-20</p><strong>Reference: </strong><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15467">CVE-2025-15467</a><p><strong>2026-02-20 Update: </strong> Added patch versions for GKE.</p><devsite-selector> <section> <h3 data-text="GKE" id="gcp-2026-006-gke" tabindex="-1">GKE</h3> <p><strong>Updated: </strong>2026-02-20</p> <table> <thead> <tr> <th>Description</th> <th>Severity</th> </tr> </thead> <tbody> <tr> <td> <p>Multiple security vulnerabilities have been identified in the OpenSSL library. The most significant finding is CVE-2025-15467, a critical vulnerability that might allow for remote code execution (RCE) or denial of service (DoS) attacks via network-based vectors.</p> <p>GKE control plane and infrastructure is not vulnerable. GKE core infrastructure, including the Kubernetes API Server and Kubelet, remains unaffected. These services use <a href="https://github.com/boringcrypto">BoringCrypto</a> (a security-hardened module derived from <a href="https://boringssl.googlesource.com/boringssl/+/fed35d32245ee4563691d21f55c12b4f8dac840a/crypto/fipsmodule/FIPS.md">BoringSSL</a>), which does not contain the vulnerable code found in the standard OpenSSL distribution.</p> <p>GKE Nodes: The <a href="https://www.openssl.org/">OpenSSL</a> library included in the GKE Node OS images (Container-Optimized OS and Ubuntu) contains the vulnerable code. While the control plane is secure, software running within your nodes or administrative tools on the host OS might be at risk.</p> <p>Updated GKE versions will include will the latest version of OpenSSL, which addresses the following CVEs:</p> <p> </p><ul> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-11187">CVE-2025-11187</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-15467">CVE-2025-15467</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-15468">CVE-2025-15468</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-15469">CVE-2025-15469</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-66199">CVE-2025-66199</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-68160">CVE-2025-68160</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-69418">CVE-2025-69418</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-69419">CVE-2025-69419</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-69420">CVE-2025-69420</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-69421">CVE-2025-69421</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2026-22795">CVE-2026-22795</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2026-22796">CVE-2026-22796</a></li> </ul> <h4 data-text="What should I do?" id="what-should-i-do_71" tabindex="-1">What should I do?</h4> <p><strong>2026-02-20 Update:</strong> The following versions of GKE are updated with code to fix this vulnerability. Upgrade your GKE node pools to the following versions or later: </p><ul> <li>1.35.0-gke.2398000</li> <li>1.34.3-gke.1318000</li> <li>1.33.5-gke.2392000</li> <li>1.32.11-gke.1264000</li> </ul> <hr/> <p>There is no action at this time. This security bulletin will be updated when new GKE versions are available that use the patched version of OpenSSL.</p> </td> <td>High</td> </tr> </tbody> </table> </section> <section> <h3 data-text="GDC (VMware)" id="gcp-2026-006-gdcvmware" tabindex="-1">GDC (VMware)</h3> <table> <thead> <tr> <th>Description</th> <th>Severity</th> </tr> </thead> <tbody> <tr> <td> <p>Multiple security vulnerabilities have been identified in the OpenSSL library. The most significant finding is CVE-2025-15467, a critical vulnerability that might allow for remote code execution (RCE) or denial of service (DoS) attacks via network-based vectors.</p> <p>GDC software for VMware control plane and infrastructure is not vulnerable. GDC software for VMware core infrastructure, including the Kubernetes API Server and Kubelet, remains unaffected. These services use <a href="https://github.com/boringcrypto">BoringCrypto</a> (a security-hardened module derived from <a href="https://boringssl.googlesource.com/boringssl/+/fed35d32245ee4563691d21f55c12b4f8dac840a/crypto/fipsmodule/FIPS.md">BoringSSL</a>), which does not contain the vulnerable code found in the standard OpenSSL distribution.</p> <p>GDC software for VMware Nodes: The <a href="https://www.openssl.org/">OpenSSL</a> library included in the GDC software for VMware Node OS images (Container-Optimized OS and Ubuntu) contains the vulnerable code. While the control plane is secure, software running within your nodes or administrative tools on the host OS might be at risk.</p> <p>Updated GDC software for VMware versions will include will the latest version of OpenSSL, which addresses the following CVEs:</p> <p> </p><ul> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-11187">CVE-2025-11187</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-15467">CVE-2025-15467</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-15468">CVE-2025-15468</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-15469">CVE-2025-15469</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-66199">CVE-2025-66199</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-68160">CVE-2025-68160</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-69418">CVE-2025-69418</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-69419">CVE-2025-69419</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-69420">CVE-2025-69420</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-69421">CVE-2025-69421</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2026-22795">CVE-2026-22795</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2026-22796">CVE-2026-22796</a></li> </ul> <h4 data-text="What should I do?" id="what-should-i-do_72" tabindex="-1">What should I do?</h4> <p>There is no action at this time. This security bulletin will be updated when new Google Distributed Cloud versions are available that use the patched version of OpenSSL.</p> </td> <td>High</td> </tr> </tbody> </table> </section> <section> <h3 data-text="GKE on AWS" id="gcp-2026-006-gkeaws" tabindex="-1">GKE on AWS</h3> <table> <thead> <tr> <th>Description</th> <th>Severity</th> </tr> </thead> <tbody> <tr> <td> <p>Multiple security vulnerabilities have been identified in the OpenSSL library. The most significant finding is CVE-2025-15467, a critical vulnerability that might allow for remote code execution (RCE) or denial of service (DoS) attacks via network-based vectors.</p> <p>GKE on AWS control plane and infrastructure is not vulnerable. GKE on AWS core infrastructure, including the Kubernetes API Server and Kubelet, remains unaffected. These services use <a href="https://github.com/boringcrypto">BoringCrypto</a> (a security-hardened module derived from <a href="https://boringssl.googlesource.com/boringssl/+/fed35d32245ee4563691d21f55c12b4f8dac840a/crypto/fipsmodule/FIPS.md">BoringSSL</a>), which does not contain the vulnerable code found in the standard OpenSSL distribution.</p> <p>GKE on AWS Nodes: The <a href="https://www.openssl.org/">OpenSSL</a> library included in the GKE on AWS Node OS images (Container-Optimized OS and Ubuntu) contains the vulnerable code. While the control plane is secure, software running within your nodes or administrative tools on the host OS might be at risk.</p> <p>Updated GKE on AWS versions will include will the latest version of OpenSSL, which addresses the following CVEs:</p> <p> </p><ul> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-11187">CVE-2025-11187</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-15467">CVE-2025-15467</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-15468">CVE-2025-15468</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-15469">CVE-2025-15469</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-66199">CVE-2025-66199</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-68160">CVE-2025-68160</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-69418">CVE-2025-69418</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-69419">CVE-2025-69419</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-69420">CVE-2025-69420</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-69421">CVE-2025-69421</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2026-22795">CVE-2026-22795</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2026-22796">CVE-2026-22796</a></li> </ul> <h4 data-text="What should I do?" id="what-should-i-do_73" tabindex="-1">What should I do?</h4> <p>There is no action at this time. This security bulletin will be updated when new GKE on AWS versions are available that use the patched version of OpenSSL.</p> </td> <td>High</td> </tr> </tbody> </table> </section> <section> <h3 data-text="GKE on Azure" id="gcp-2026-006-gkeazure" tabindex="-1">GKE on Azure</h3> <table> <thead> <tr> <th>Description</th> <th>Severity</th> </tr> </thead> <tbody> <tr> <td> <p>Multiple security vulnerabilities have been identified in the OpenSSL library. The most significant finding is CVE-2025-15467, a critical vulnerability that might allow for remote code execution (RCE) or denial of service (DoS) attacks via network-based vectors.</p> <p>GKE on Azure control plane and infrastructure is not vulnerable. GKE on Azure core infrastructure, including the Kubernetes API Server and Kubelet, remains unaffected. These services use <a href="https://github.com/boringcrypto">BoringCrypto</a> (a security-hardened module derived from <a href="https://boringssl.googlesource.com/boringssl/+/fed35d32245ee4563691d21f55c12b4f8dac840a/crypto/fipsmodule/FIPS.md">BoringSSL</a>), which does not contain the vulnerable code found in the standard OpenSSL distribution.</p> <p>GKE on Azure Nodes: The <a href="https://www.openssl.org/">OpenSSL</a> library included in the GKE on Azure Node OS images (Container-Optimized OS and Ubuntu) contains the vulnerable code. While the control plane is secure, software running within your nodes or administrative tools on the host OS might be at risk.</p> <p>Updated GKE on Azure versions will include will the latest version of OpenSSL, which addresses the following CVEs:</p> <p> </p><ul> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-11187">CVE-2025-11187</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-15467">CVE-2025-15467</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-15468">CVE-2025-15468</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-15469">CVE-2025-15469</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-66199">CVE-2025-66199</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-68160">CVE-2025-68160</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-69418">CVE-2025-69418</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-69419">CVE-2025-69419</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-69420">CVE-2025-69420</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2025-69421">CVE-2025-69421</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2026-22795">CVE-2026-22795</a></li> <li><a href="https://openssl-library.org/news/vulnerabilities/#CVE-2026-22796">CVE-2026-22796</a></li> </ul> <h4 data-text="What should I do?" id="what-should-i-do_74" tabindex="-1">What should I do?</h4> <p>There is no action at this time. This security bulletin will be updated when new GKE on Azure versions are available that use the patched version of OpenSSL.</p> </td> <td>High</td> </tr> </tbody> </table> </section> <section> <h3 data-text="GDC (bare metal)" id="gcp-2026-006-gdcbm" tabindex="-1">GDC (bare metal)</h3> <table> <thead> <tr> <th>Description</th> <th>Severity</th> </tr> </thead> <tbody> <tr> <td> <p>Several security issues have been discovered in OpenSSL. The most critical is CVE-2025-15467, which could be used to execute a denial of service or remote code execution attack over the internet.</p> <p>GDC software for bare metal is not vulnerable to this threat. GDC software for bare metal uses <a href="https://github.com/boringcrypto">BoringCrypto</a> for network facing services such as the Kubernetes apiserver and Kubelet, and BoringCrypto is not affected by this vulnerability. BoringCrypto is extracted from <a href="https://boringssl.googlesource.com/boringssl/+/fed35d32245ee4563691d21f55c12b4f8dac840a/crypto/fipsmodule/FIPS.md">BoringSSL</a>, a fork of <a href="https://www.openssl.org/">OpenSSL</a> focused on security hardening and performance.</p> <p>GDC software for bare metal does not provide a node OS. Customers are responsible for installing and maintaining a supported Linux distribution on physical hardware before installing the GKE software.</p> <h4 data-text="What should I do?" id="what-should-i-do_75" tabindex="-1">What should I do?</h4> <p>Update your Linux OS image to one that includes the latest Open SSL distribution.</p> </td> <td>High</td> </tr> </tbody> </table> </section> </devsite-selector>
Timeline
- Jan 29, 2026 CVE Published
References
- https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-006-gdcbm web
- GCP-2026-006 (High) advisory
- https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-006-gke web
- https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-006-gdcvmware web
- https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-006-gkeazure web
- https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-006-gkeaws web
- GCP-2026-006 (High) advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-15467 web
- https://github.com/boringcrypto web
- https://boringssl.googlesource.com/boringssl/+/fed35d32245ee4563691d21f55c12b4f8dac840a/crypto/fipsmodule/FIPS.md web
- https://www.openssl.org/ web
- https://openssl-library.org/news/vulnerabilities/#CVE-2025-11187 web
- https://openssl-library.org/news/vulnerabilities/#CVE-2025-15467 web
- https://openssl-library.org/news/vulnerabilities/#CVE-2025-15468 web
- https://openssl-library.org/news/vulnerabilities/#CVE-2025-15469 web
- https://openssl-library.org/news/vulnerabilities/#CVE-2025-66199 web
- https://openssl-library.org/news/vulnerabilities/#CVE-2025-68160 web
- https://openssl-library.org/news/vulnerabilities/#CVE-2025-69418 web
- https://openssl-library.org/news/vulnerabilities/#CVE-2025-69419 web
- https://openssl-library.org/news/vulnerabilities/#CVE-2025-69420 web
…and 3 more