Sicherheit
Security
All tracked CVEs and security advisories — sorted by date or severity. Each entry links to the official source. The plain-text explanations are generated automatically — the source remains authoritative.
| CVE / GHSA | Item | Vertical | Severity | Date |
|---|---|---|---|---|
| CVE-2025-32386 Source A vulnerability in Helm allows attackers to exhaust all available memory and crash the application by using specially crafted chart archive files that expand dramatically when decompressed. |
Helm | OS & platform | Medium | 07.06.2026 |
| CVE-2025-32387 Source A vulnerability in Helm allows specially crafted JSON Schema files within charts to cause a stack overflow that can crash the application. |
Helm | OS & platform | Medium | 07.06.2026 |
| CVE-2025-53547 Source A vulnerability in Helm allows attackers to execute malicious code on the local system by using specially crafted Chart.yaml files and symbolic links to Chart.lock files when dependencies are updated. |
Helm | OS & platform | High | 07.06.2026 |
| CVE-2025-55199 Source A vulnerability in Helm allows malicious chart files to consume all available memory and crash the system through crafted JSON Schema references pointing to problematic files. |
Helm | OS & platform | Medium | 07.06.2026 |
| CVE-2025-55198 Source A vulnerability in Helm causes the application to crash when certain YAML configuration files contain invalid or empty values, affecting the tool's availability. |
Helm | OS & platform | Medium | 07.06.2026 |
| CVE-2026-35206 Source A vulnerability in Helm, a Kubernetes package manager, allows specially crafted charts to write files to the wrong directory during extraction, potentially overwriting existing files in the target location. |
Helm | OS & platform | Medium | 07.06.2026 |
| CVE-2026-35205 Source Helm, a package manager for Kubernetes, fails to properly verify plugin signatures in versions 4.0.0 to 4.1.3 and installs unsigned plugins despite enabled signature verification, allowing malicious plugins to execute arbitrary code. |
Helm | OS & platform | Critical | 07.06.2026 |
| CVE-2026-35204 Source A security vulnerability in Helm (Kubernetes package manager) allows malicious plugins to overwrite arbitrary files on the system, potentially compromising the entire system. |
Helm | OS & platform | High | 07.06.2026 |
| CVE-2020-15257 Source A vulnerability in containerd allows malicious containers with root privileges to start new processes with elevated privileges when running in the same network namespace as the shim. |
containerd | OS & platform | Medium | 07.06.2026 |
| CVE-2020-15157 Source A vulnerability in containerd version 1.2.x allows attackers to steal registry credentials by publishing malicious container images with special URLs that trick containerd into sending authentication data to attacker-controlled servers. |
containerd | OS & platform | Medium | 07.06.2026 |
| CVE-2021-21334 Source A bug in containerd's CRI implementation can cause containers using the same image to receive incorrect environment variables, potentially sharing sensitive information between containers with different security contexts. |
containerd | OS & platform | Medium | 07.06.2026 |
| CVE-2021-32760 Source A bug in containerd allows specially crafted container images to modify file permissions of existing files on the host system, potentially blocking access for legitimate users or widening access to others. |
containerd | OS & platform | Medium | 07.06.2026 |
| CVE-2021-41103 Source A permission flaw in containerd allowed regular Linux users to access container directories and execute programs with elevated privileges or read and modify files. |
containerd | OS & platform | Medium | 07.06.2026 |
| GHSA-5j5w-g665-5m35 Source Containerd versions before 1.4.12 and 1.5.8 trust HTTP Content-Type headers when loading container images, allowing the same image digest to be interpreted differently and compromising the uniqueness of image identification. |
containerd | OS & platform | Medium | 07.06.2026 |
| CVE-2021-43816 Source A vulnerability in containerd allows containers on Linux systems with SELinux to relabel arbitrary host files through specially configured bind mounts, gaining full read/write access to those files. |
containerd | OS & platform | High | 07.06.2026 |
| CVE-2022-23648 Source A flaw in containerd allows containers with specially crafted configurations to access arbitrary files on the host system, potentially bypassing security policies and exposing sensitive information. |
containerd | OS & platform | Medium | 07.06.2026 |
| CVE-2022-24769 Source A bug in containerd caused containers to start with unusual Linux permissions, allowing programs inside containers to gain additional system privileges beyond what was intended. |
containerd | OS & platform | Low | 07.06.2026 |
| CVE-2022-31030 Source A bug in containerd allows programs inside containers to consume unlimited memory when using the ExecSync function, potentially exhausting all available system memory and denying service to other legitimate workloads. |
containerd | OS & platform | Medium | 07.06.2026 |
| CVE-2022-23471 Source A bug in containerd's CRI implementation allows users to exhaust host memory by causing a goroutine memory leak when faulty commands are executed. |
containerd | OS & platform | Medium | 07.06.2026 |
| CVE-2023-25173 Source A bug in containerd causes supplementary user groups to be improperly set up in containers, potentially allowing attackers with direct container access to bypass group restrictions and gain access to sensitive information. |
containerd | OS & platform | Medium | 07.06.2026 |
| CVE-2023-25153 Source A vulnerability in containerd allows attackers to cause denial-of-service attacks through maliciously crafted container images with large files, as there was no size limit when importing certain files during image processing. |
containerd | OS & platform | Medium | 07.06.2026 |
| GHSA-7ww5-4wqc-m92c Source Containerd containers can access hardware power consumption data by default, allowing attackers to bypass security features like encryption by analyzing power usage patterns. |
containerd | OS & platform | Medium | 07.06.2026 |
| CVE-2024-25621 Source Containerd creates important directories with overly permissive access rights, allowing local users on the host to access container metadata and Kubernetes volumes, potentially leading to privilege escalation. |
containerd | OS & platform | Medium | 07.06.2026 |
| CVE-2024-40635 Source A bug in containerd causes containers with very large user IDs to run as root user due to a number overflow, bypassing security policies that require non-root execution. |
containerd | OS & platform | Medium | 07.06.2026 |
| CVE-2025-64329 Source A bug in containerd's CRI Attach function causes memory leaks through improperly terminated goroutines. Repeated kubectl attach commands can exhaust the host's memory, potentially slowing down or crashing the system. |
containerd | OS & platform | Medium | 07.06.2026 |
| CVE-2025-47291 Source A bug in containerd causes usernamespaced containers to bypass Kubernetes resource limits by not being placed under the proper control group hierarchy, potentially leading to denial of service of the Kubernetes node. |
containerd | OS & platform | Medium | 07.06.2026 |
| CVE-2025-47290 Source A vulnerability in containerd version 2.1.0 allows malicious container images to arbitrarily modify or create files on the host system during image download operations. |
containerd | OS & platform | Critical | 07.06.2026 |
| CVE-2026-46680 Source A bug in containerd causes containers with large numeric user IDs to incorrectly run as root, allowing security restrictions to be bypassed. |
containerd | OS & platform | Medium | 07.06.2026 |
| CVE-2020-15113 Source etcd, a distributed database, creates certain directories with restricted permissions but fails to verify that existing directories have these secure permissions, potentially allowing unintended data access. |
etcd | OS & platform | Medium | 07.06.2026 |
| CVE-2020-15112 Source A vulnerability in etcd allows an invalid index to be used when reading WAL entries, which can cause etcd nodes to crash during the consensus process. |
etcd | OS & platform | Medium | 07.06.2026 |
| CVE-2020-15106 Source A vulnerability in etcd allows attackers to create malicious WAL files with extremely large frame sizes that can crash the system when other cluster participants attempt to process them. |
etcd | OS & platform | Medium | 07.06.2026 |
| GHSA-vjg6-93fv-qv64 Source A vulnerability in etcd causes incomplete logging of authentication failures when users without passwords attempt to log in, making security monitoring more difficult. |
etcd | OS & platform | Low | 07.06.2026 |
| GHSA-pm3m-32r3-7mfh Source A vulnerability in etcd allows negative values for data retention, causing the service to enter an infinite loop that consumes excessive CPU and floods logs. |
etcd | OS & platform | Low | 07.06.2026 |
| GHSA-9gp7-6833-wv89 Source A vulnerability in etcd causes the service to crash when a negative cluster size is provided during service discovery. |
etcd | OS & platform | Low | 07.06.2026 |
| GHSA-5x4g-q5rc-36jp Source The etcd database supports insecure encryption methods for TLS connections, which could weaken communication security. |
etcd | OS & platform | Low | 07.06.2026 |
| CVE-2020-15115 Source The etcd database does not validate user password length, allowing extremely short passwords like single characters, which makes it easier for attackers to guess or brute-force crack user credentials. |
etcd | OS & platform | Medium | 07.06.2026 |
| GHSA-528j-9r78-wffx Source etcd stores user credentials like passwords unencrypted in WAL log files on disk, potentially exposing sensitive login information if these files are not properly secured. |
etcd | OS & platform | Low | 07.06.2026 |
| CVE-2020-15114 Source A vulnerability in the etcd gateway allows configuring the gateway address as an endpoint, creating an infinite loop that exhausts all available file descriptors and crashes the service. |
etcd | OS & platform | High | 07.06.2026 |
| GHSA-j86v-2vjr-fg8f Source The etcd gateway component incompletely validates endpoints and allows connections to servers without TLS encryption through HTTPS URLs, potentially leading to insecure connections. |
etcd | OS & platform | Medium | 07.06.2026 |
| CVE-2020-15136 Source A vulnerability in etcd's gateway feature causes TLS authentication to only be performed for DNS SRV endpoints but not for manually specified endpoints, potentially allowing insecure connections. |
etcd | OS & platform | Medium | 07.06.2026 |
| GHSA-h8g9-6gvh-5mrc Source A vulnerability in etcd's gateway component causes authentication settings of endpoints to not be properly validated, potentially allowing unauthorized access. |
etcd | OS & platform | Low | 07.06.2026 |
| CVE-2023-32082 Source A vulnerability in etcd allows users to view key names through the LeaseTimeToLive API even without read permissions, leading to unintended information disclosure in authentication-enabled clusters. |
etcd | OS & platform | Low | 07.06.2026 |
| CVE-2026-33413 Source A vulnerability in etcd allows unauthorized users to bypass authentication and authorization checks to call certain functions, enabling them to view cluster topology, disrupt services, or permanently delete data. |
etcd | OS & platform | Medium | 07.06.2026 |
| CVE-2026-33343 Source A vulnerability in etcd allows authenticated users to bypass access controls through nested transactions and access all stored data, even though they should only have restricted permissions. |
etcd | OS & platform | Low | 07.06.2026 |
| CVE-2026-44283 Source A vulnerability in etcd allows authenticated users to bypass RBAC permission checks and gain unauthorized access to data or attach leases by using specific transaction operations. |
etcd | OS & platform | Low | 07.06.2026 |
| CVE-2024-31449 Source A security vulnerability in Valkey allows authenticated users to cause a buffer overflow through specially crafted Lua scripts, potentially leading to remote code execution. |
Valkey | OS & platform | High | 07.06.2026 |
| CVE-2024-31227 Source A vulnerability in Valkey allows authenticated users with sufficient privileges to create malformed ACL selectors that cause server crashes and denial of service when accessed. |
Valkey | OS & platform | Medium | 07.06.2026 |
| CVE-2024-31228 Source A vulnerability in the Valkey database allows authenticated users to crash the service using specially crafted, extremely long text patterns, resulting in a denial-of-service attack. |
Valkey | OS & platform | Medium | 07.06.2026 |
| CVE-2025-21605 Source A vulnerability in the Valkey database allows unauthenticated attackers to consume unlimited memory by causing output buffers to grow indefinitely, leading to server crashes or memory exhaustion. |
Valkey | OS & platform | High | 07.06.2026 |
| CVE-2025-49844 Source A vulnerability in the Valkey database allows authenticated users to trigger memory corruption through specially crafted Lua scripts, potentially enabling remote code execution on the server. |
Valkey | OS & platform | High | 07.06.2026 |