VDB

GO-2025-3774

GO-2025-3774 PUBLISHED CVSS 9.300000190734863 CRITICAL

Kubernetes allows nodes to bypass dynamic resource allocation authorization checks in k8s.io/kubernetes

Risk Scores

CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
chainguardargo-cd-3.10, 0, 0
chainguardcalico-fips-3.300, 0, 0
chainguardcalico-3.300, 0, 0
chainguardvcluster0, 0, 0
wolfivcluster0, 0, 0
chainguardblob-csi-fips-1.260, 0, 0
chainguardrancher-fleet-fips0, 0, 0
chainguardyunikorn-k8shim0, 0, 0
wolfiyunikorn-k8shim0, 0, 0
chainguardrancher-fleet0, 0, 0
chainguardkubernetes-csi-driver-hostpath0, 0, 0
wolfidocker-machine-driver-harvester0, 0, 0
chainguardyunikorn-k8shim-fips0, 0, 0
chainguardmesosphere-vsphere-csi-fips*, *, *
chainguardcloud-provider-gcp-cloud-controller-manager0, 0, 0
chainguardlonghorn-share-manager-fips-1.80, 0, 0
chainguardrancher-system-agent0, 0, 0
chainguardargo-cd-3.00, 0, 0
chainguardrancher-agent-2.120, 0, 0
chainguardazuredisk-csi-1.320, 0, 0

…and 28 more

Timeline

  • Jul 28, 2025 CVE Published
  • Feb 4, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›