Kubernetes API Server JSON/YAML parsing vulnerable to resource exhaustion attack
Published Oct 17, 2019
7.5
HIGHCVSS 3.1
EPSS 25.94%
Description
Improper input validation in the Kubernetes API server in versions v1.0-1.12 and versions prior to v1.13.12, v1.14.8, v1.15.5, and v1.16.2 allows authorized users to send malicious YAML or JSON payloads, causing the API server to consume excessive CPU or memory, potentially crashing and becoming unavailable. Prior to v1.14.0, default RBAC policy authorized anonymous users to submit requests that could trigger this vulnerability. Clusters upgraded from a version prior to v1.14.0 keep the more permissive policy by default for backwards compatibility.
Affected products
-
- Version 1.1StatusaffectedConstraints-
- Version 1.10StatusaffectedConstraints-
- Version 1.11StatusaffectedConstraints-
- Version 1.12StatusaffectedConstraints-
- Version 1.2StatusaffectedConstraints-
- Version 1.3StatusaffectedConstraints-
- Version 1.4StatusaffectedConstraints-
- Version 1.5StatusaffectedConstraints-
- Version 1.6StatusaffectedConstraints-
- Version 1.7StatusaffectedConstraints-
- Version 1.8StatusaffectedConstraints-
- Version 1.9StatusaffectedConstraints-
- Version prior to 1.13.12StatusaffectedConstraints-
- Version prior to 1.14.8StatusaffectedConstraints-
- Version prior to 1.15.5StatusaffectedConstraints-
- Version prior to 1.16.2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Kubernetes | Kubernetes | n/a |
|
Configuration 1
- ≥ 1.1.0 · ≤ 1.12.10
- ≥ 1.13.0 · < 1.13.12
- ≥ 1.14.0 · < 1.14.8
- ≥ 1.15.0 · < 1.15.5
- ≥ 1.16.0 · < 1.16.2
Configuration 2
- 3.9
- 3.10
- 3.11
No data.
OpenShift Service Mesh 1.0
servicemesh-0:1.0.2-3.el8
Fixed · RHEA-2019:3809
OpenShift Service Mesh 1.0
servicemesh-cni-0:1.0.11-1.el8
Fixed · RHSA-2020:2870
OpenShift Service Mesh 1.0
servicemesh-cni-0:1.0.2-3.el8
Fixed · RHEA-2019:3809
OpenShift Service Mesh 1.0
servicemesh-grafana-0:6.2.2-24.el8
Fixed · RHEA-2019:3809
OpenShift Service Mesh 1.0
servicemesh-grafana-0:6.2.2-38.el8
Fixed · RHSA-2020:2861
OpenShift Service Mesh 1.0
servicemesh-operator-0:1.0.2-7.el8
Fixed · RHEA-2019:3809
OpenShift Service Mesh 1.0
servicemesh-prometheus-0:2.7.2-25.el8
Fixed · RHEA-2019:3809
OpenShift Service Mesh 1.0
servicemesh-prometheus-0:2.7.2-36.el8
Fixed · RHSA-2020:2863
OpenShift Service Mesh 1.0
servicemesh-proxy-0:1.0.2-3.el8
Fixed · RHEA-2019:3809
OpenShift Service Mesh 1.1
servicemesh-cni-0:1.1.4-2.el8
Fixed · RHSA-2020:2799
OpenShift Service Mesh 1.1
servicemesh-grafana-0:6.4.3-11.el8
Fixed · RHSA-2020:2796
OpenShift Service Mesh 1.1
servicemesh-operator-0:1.1.4-3.el8
Fixed · RHSA-2020:2795
Openshift Service Mesh 1.0
jaeger-0:v1.13.1.redhat5-1.el7
Fixed · RHEA-2019:3809
Openshift Service Mesh 1.0
jaeger-operator-0:v1.13.1.redhat8-1.el7
Fixed · RHEA-2019:3809
Openshift Service Mesh 1.0
kiali-0:v1.0.7.redhat1-1.el7
Fixed · RHEA-2019:3809
Red Hat OpenShift Container Platform 3.10
atomic-openshift-0:3.10.181-1.git.0.3ab4b3d.el7
Fixed · RHSA-2019:3239
Red Hat OpenShift Container Platform 3.11
atomic-openshift-0:3.11.154-1.git.0.7a097ad.el7
Fixed · RHSA-2019:3905
Red Hat OpenShift Container Platform 3.9
atomic-openshift-0:3.9.102-1.git.0.6411f52.el7
Fixed · RHSA-2019:3811
Red Hat OpenShift Container Platform 4.1
openshift-0:4.1.20-201910101746.git.0.a80aad5.el7
Fixed · RHSA-2019:3132
Red Hat OpenStack Platform 16.2
rhosp-rhel8-tech-preview/osp-director-operator:1.2.3-2
Fixed · RHSA-2022:2183
OpenShift Service Mesh 1
serivicemesh-grafana
Affected
Red Hat OpenStack Platform 16.2
osp-director-provisioner-container
Affected
Red Hat OpenStack Platform 16.2
rhosp-rhel8/osp-director-downloader
Will not fix
Red Hat Storage 3
heketi
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Service Mesh 1.0 | servicemesh-0:1.0.2-3.el8 | Fixed | RHEA-2019:3809 |
| OpenShift Service Mesh 1.0 | servicemesh-cni-0:1.0.11-1.el8 | Fixed | RHSA-2020:2870 |
| OpenShift Service Mesh 1.0 | servicemesh-cni-0:1.0.2-3.el8 | Fixed | RHEA-2019:3809 |
| OpenShift Service Mesh 1.0 | servicemesh-grafana-0:6.2.2-24.el8 | Fixed | RHEA-2019:3809 |
| OpenShift Service Mesh 1.0 | servicemesh-grafana-0:6.2.2-38.el8 | Fixed | RHSA-2020:2861 |
| OpenShift Service Mesh 1.0 | servicemesh-operator-0:1.0.2-7.el8 | Fixed | RHEA-2019:3809 |
| OpenShift Service Mesh 1.0 | servicemesh-prometheus-0:2.7.2-25.el8 | Fixed | RHEA-2019:3809 |
| OpenShift Service Mesh 1.0 | servicemesh-prometheus-0:2.7.2-36.el8 | Fixed | RHSA-2020:2863 |
| OpenShift Service Mesh 1.0 | servicemesh-proxy-0:1.0.2-3.el8 | Fixed | RHEA-2019:3809 |
| OpenShift Service Mesh 1.1 | servicemesh-cni-0:1.1.4-2.el8 | Fixed | RHSA-2020:2799 |
| OpenShift Service Mesh 1.1 | servicemesh-grafana-0:6.4.3-11.el8 | Fixed | RHSA-2020:2796 |
| OpenShift Service Mesh 1.1 | servicemesh-operator-0:1.1.4-3.el8 | Fixed | RHSA-2020:2795 |
| Openshift Service Mesh 1.0 | jaeger-0:v1.13.1.redhat5-1.el7 | Fixed | RHEA-2019:3809 |
| Openshift Service Mesh 1.0 | jaeger-operator-0:v1.13.1.redhat8-1.el7 | Fixed | RHEA-2019:3809 |
| Openshift Service Mesh 1.0 | kiali-0:v1.0.7.redhat1-1.el7 | Fixed | RHEA-2019:3809 |
| Red Hat OpenShift Container Platform 3.10 | atomic-openshift-0:3.10.181-1.git.0.3ab4b3d.el7 | Fixed | RHSA-2019:3239 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-0:3.11.154-1.git.0.7a097ad.el7 | Fixed | RHSA-2019:3905 |
| Red Hat OpenShift Container Platform 3.9 | atomic-openshift-0:3.9.102-1.git.0.6411f52.el7 | Fixed | RHSA-2019:3811 |
| Red Hat OpenShift Container Platform 4.1 | openshift-0:4.1.20-201910101746.git.0.a80aad5.el7 | Fixed | RHSA-2019:3132 |
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8-tech-preview/osp-director-operator:1.2.3-2 | Fixed | RHSA-2022:2183 |
| OpenShift Service Mesh 1 | serivicemesh-grafana | Affected | n/a |
| Red Hat OpenStack Platform 16.2 | osp-director-provisioner-container | Affected | n/a |
| Red Hat OpenStack Platform 16.2 | rhosp-rhel8/osp-director-downloader | Will not fix | n/a |
| Red Hat Storage 3 | heketi | Not affected | n/a |
k8s.io/kubernetes
Go
Introduced 1.15.0 Fixed 1.15.5k8s.io/kubernetes
Go
Introduced 1.16.0 Fixed 1.16.2k8s.io/kubernetes
Go
Introduced 1.0.0 Fixed 1.13.12k8s.io/kubernetes
Go
Introduced 1.14.0 Fixed 1.14.8
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | k8s.io/kubernetes | 1.15.0 | 1.15.5 |
| Go | k8s.io/kubernetes | 1.16.0 | 1.16.2 |
| Go | k8s.io/kubernetes | 1.0.0 | 1.13.12 |
| Go | k8s.io/kubernetes | 1.14.0 | 1.14.8 |
Remediation
Vendor solution
Exposure to requests from unauthenticated users can be mitigated by removing all write permissions from unauthenticated users, following instructions at https://github.com/kubernetes/kubernetes/issues/83253
Red Hat statement
For Red Hat OpenStack Platform, because kubernetes is not directly used in director-operator, the RHOSP Impact has been moved to Moderate.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
AV:N/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (68 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 25.94% (0.25939) | 97.92th | v5 (v2026.06.15) |
| Jun 15, 2026 | 25.94% (0.25939) | 97.71th | v5 (v2026.06.15) |
| Jun 10, 2026 | 82.79% (0.82787) | 99.26th | v4 (v2025.03.14) |
| May 29, 2026 | 84.51% (0.84511) | 99.34th | v4 (v2025.03.14) |
| May 22, 2026 | 85.85% (0.85850) | 99.40th | v4 (v2025.03.14) |
| Mar 4, 2026 | 82.97% (0.82968) | 99.23th | v4 (v2025.03.14) |
| Mar 2, 2026 | 80.37% (0.80373) | 99.10th | v4 (v2025.03.14) |
| Mar 1, 2026 | 78.03% (0.78033) | 98.99th | v4 (v2025.03.14) |
| Feb 22, 2026 | 81.03% (0.81025) | 99.12th | v4 (v2025.03.14) |
| Feb 4, 2026 | 78.75% (0.78747) | 99.01th | v4 (v2025.03.14) |
| Feb 1, 2026 | 75.31% (0.75315) | 98.85th | v4 (v2025.03.14) |
| Jan 20, 2026 | 78.75% (0.78747) | 99.00th | v4 (v2025.03.14) |
| Jan 18, 2026 | 81.95% (0.81952) | 99.17th | v4 (v2025.03.14) |
| Jan 5, 2026 | 86.29% (0.86289) | 99.38th | v4 (v2025.03.14) |
| Jan 4, 2026 | 87.51% (0.87508) | 99.43th | v4 (v2025.03.14) |
| Jan 1, 2026 | 85.90% (0.85903) | 99.37th | v4 (v2025.03.14) |
| Dec 30, 2025 | 87.51% (0.87508) | 99.43th | v4 (v2025.03.14) |
| Dec 4, 2025 | 39.06% (0.39063) | 97.10th | v4 (v2025.03.14) |
| Dec 1, 2025 | 31.24% (0.31240) | 96.60th | v4 (v2025.03.14) |
| Nov 21, 2025 | 39.06% (0.39063) | 97.10th | v4 (v2025.03.14) |
| Nov 18, 2025 | 22.87% (0.22869) | 95.52th | v4 (v2025.03.14) |
| Nov 4, 2025 | 39.06% (0.39063) | 97.09th | v4 (v2025.03.14) |
| Nov 1, 2025 | 31.24% (0.31240) | 96.57th | v4 (v2025.03.14) |
| Oct 4, 2025 | 39.06% (0.39063) | 97.16th | v4 (v2025.03.14) |
| Oct 1, 2025 | 31.24% (0.31240) | 96.62th | v4 (v2025.03.14) |
| Sep 4, 2025 | 39.80% (0.39799) | 97.23th | v4 (v2025.03.14) |
| Sep 1, 2025 | 31.92% (0.31924) | 96.69th | v4 (v2025.03.14) |
| Aug 20, 2025 | 39.81% (0.39811) | 97.21th | v4 (v2025.03.14) |
| Aug 19, 2025 | 31.94% (0.31935) | 96.66th | v4 (v2025.03.14) |
| Aug 4, 2025 | 39.80% (0.39799) | 97.19th | v4 (v2025.03.14) |
| Aug 1, 2025 | 31.92% (0.31924) | 96.67th | v4 (v2025.03.14) |
| Jul 5, 2025 | 39.80% (0.39799) | 97.15th | v4 (v2025.03.14) |
| Jul 1, 2025 | 31.92% (0.31924) | 96.63th | v4 (v2025.03.14) |
| Jun 4, 2025 | 39.80% (0.39799) | 97.13th | v4 (v2025.03.14) |
| Jun 1, 2025 | 31.94% (0.31935) | 96.59th | v4 (v2025.03.14) |
| May 17, 2025 | 39.80% (0.39799) | 97.11th | v4 (v2025.03.14) |
| May 15, 2025 | 44.76% (0.44764) | 97.40th | v4 (v2025.03.14) |
| May 4, 2025 | 39.80% (0.39799) | 97.10th | v4 (v2025.03.14) |
| May 1, 2025 | 31.92% (0.31924) | 96.55th | v4 (v2025.03.14) |
| Apr 3, 2025 | 39.80% (0.39799) | 97.03th | v4 (v2025.03.14) |
| Apr 2, 2025 | 31.92% (0.31924) | 96.44th | v4 (v2025.03.14) |
| Mar 30, 2025 | 39.80% (0.39799) | 97.02th | v4 (v2025.03.14) |
| Mar 29, 2025 | 64.34% (0.64341) | 97.82th | v4 (v2025.03.14) |
| Mar 27, 2025 | 39.80% (0.39799) | 96.83th | v4 (v2025.03.14) |
| Mar 25, 2025 | 31.92% (0.31924) | 96.40th | v4 (v2025.03.14) |
| Mar 24, 2025 | 39.80% (0.39799) | 97.00th | v4 (v2025.03.14) |
| Mar 23, 2025 | 53.12% (0.53116) | 97.65th | v4 (v2025.03.14) |
| Mar 22, 2025 | 31.92% (0.31924) | 96.46th | v4 (v2025.03.14) |
| Mar 21, 2025 | 39.80% (0.39799) | 97.05th | v4 (v2025.03.14) |
| Mar 20, 2025 | 31.92% (0.31924) | 96.46th | v4 (v2025.03.14) |
| Mar 17, 2025 | 39.80% (0.39799) | 96.99th | v4 (v2025.03.14) |
| Dec 12, 2024 | 2.59% (0.02588) | 90.66th | v3 (v2023.03.01) |
| Feb 8, 2024 | 1.88% (0.01882) | 88.02th | v3 (v2023.03.01) |
| Nov 8, 2023 | 1.91% (0.01907) | 87.21th | v3 (v2023.03.01) |
| Sep 23, 2023 | 1.28% (0.01278) | 84.10th | v3 (v2023.03.01) |
| Sep 7, 2023 | 1.12% (0.01121) | 82.85th | v3 (v2023.03.01) |
| Jul 8, 2023 | 0.83% (0.00825) | 79.63th | v3 (v2023.03.01) |
| May 8, 2023 | 1.09% (0.01087) | 82.18th | v3 (v2023.03.01) |
| Apr 8, 2023 | 0.83% (0.00825) | 79.43th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.58% (0.00583) | 74.79th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.11% (0.01108) | 55.18th | v2 (v2022.01.01) |
| Sep 17, 2022 | 1.11% (0.01108) | 53.57th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.11% (0.01108) | 51.54th | v2 (v2022.01.01) |
| Feb 4, 2022 | 8.93% (0.08934) | 82.99th | v2 (v2022.01.01) |
| Feb 3, 2022 | 6.21% (0.06208) | 81.93th | v1 |
| Jan 6, 2022 | 6.21% (0.06208) | 81.75th | v1 |
| Sep 1, 2021 | 1.45% (0.01454) | 71.88th | v1 |
| Apr 14, 2021 | 1.45% (0.01454) | 0.00th | v1 |
References (16)
- https://access.redhat.com/errata/RHSA-2019:3239 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3811 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3905 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-11253 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1757701 Issue Tracking
- https://gist.github.com/bgeesaman/0e0349e94cd22c48bf14d8a9b7d6b8f2
- https://github.com/advisories/GHSA-pmqp-h87c-mr78 Advisory
- https://github.com/kubernetes/kubernetes/issues/83253 x_refsource_CONFIRMExploitIssue TrackingMitigationThird Party Advisory
- https://github.com/kubernetes/kubernetes/pull/83261
- https://groups.google.com/forum/#!topic/kubernetes-security-announce/jk8polzSUxs
- https://groups.google.com/forum/#%21topic/kubernetes-security-announce/jk8polzSUxs mailing-listx_refsource_MLISTPermissions Required
- https://nvd.nist.gov/vuln/detail/CVE-2019-11253
- https://pkg.go.dev/vuln/GO-2022-0703
- https://security.netapp.com/advisory/ntap-20191031-0006 x_refsource_CONFIRMThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-11253
- https://www.stackrox.com/post/2019/09/protecting-kubernetes-api-against-cve-2019-11253-billion-laughs-attack/
Change history (0)
No recorded changes yet.