{"id":"CVE-2025-0426","aliases":["GHSA-jgfp-53c3-624w","GO-2025-3465"],"url":"https://o3.security/vulnerability/CVE-2025-0426","summary":"Node Denial of Service via kubelet Checkpoint API","details":"A security issue was discovered in Kubernetes where a large number of container checkpoint requests made to the unauthenticated kubelet read-only HTTP endpoint may cause a Node Denial of Service by filling the Node's disk.","published":"2025-02-13T15:16:13.703Z","modified":"2026-08-12T03:51:27.419018600Z","cvss":{"score":6.2,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":{"score":0.00372,"percentile":0.30888,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"k8s.io/kubernetes","fixedVersion":"1.32.2"},{"ecosystem":"Go","name":"k8s.io/kubernetes","fixedVersion":"1.31.6"},{"ecosystem":"Go","name":"k8s.io/kubernetes","fixedVersion":"1.30.10"},{"ecosystem":"Go","name":"k8s.io/kubernetes","fixedVersion":"1.29.14"}],"fix":null,"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/02/13/1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/0xxx/CVE-2025-0426.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-0426"},{"type":"REPORT","url":"https://github.com/kubernetes/kubernetes/issues/130016"},{"type":"PACKAGE","url":"https://github.com/kubernetes/kubernetes"},{"type":"ARTICLE","url":"https://groups.google.com/g/kubernetes-security-announce/c/KiODfu8i6w8"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-jgfp-53c3-624w"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:27.419018600Z"}}