Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-1002105

85
FAUCET Score

CVE-2018-1002105 is a critical vulnerability affecting Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, as well as related products like OpenShift Container Platform and NetApp Trident. This flaw allows attackers to bypass authentication and send arbitrary requests to backend servers by exploiting incorrect handling of proxied upgrade requests in the kube-apiserver. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk due to its network-based attack vector, low complexity, and potential for complete compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog, exploit code is publicly available on ExploitDB, and the vulnerability has garnered significant community discussion and media coverage, indicating a high likelihood of exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.0.0, <= 1.9.11CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
>= 1.10.0, <= 1.10.10CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
>= 1.11.0, <= 1.11.4CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
>= 1.12.0, <= 1.12.2CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
1.9.12CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:1.9.12:beta0:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

9.8CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
86.98%
Probability of exploitation in next 30 days
EPSS Percentile
99.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-46053 · Dec 10, 2018
This CVE's current EPSS score of 0.8698 is in the 99th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (35)

check_pointpatch availablevia llm_extracted
View patch
chromepatch availablevia llm_extracted
View patch
github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: github.com/kubernetes/kubernetesFixed in: 1.11.5
gopatch availablevia ghsa
Product: github.com/kubernetes/kubernetesFixed in: 1.12.3
gopatch availablevia ghsa
Product: github.com/kubernetes/kubernetesFixed in: 1.10.11
infiniflowpatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.10Fixed in: atomic-enterprise-service-catalog-1:3.10.72-1.git.1450.7d3f435.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.10Fixed in: atomic-openshift-node-problem-detector-0:3.10.72-1.git.252.fa9e8ae.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.10Fixed in: atomic-openshift-web-console-0:3.10.72-1.git.395.d23c438.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.10Fixed in: golang-github-prometheus-node_exporter-0:3.10.72-1.git.1060.64daa26.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.10Fixed in: openshift-ansible-0:3.10.73-1.git.0.8b65cea.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.10Fixed in: openshift-enterprise-cluster-capacity-0:3.10.72-1.git.380.0fd53e8.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.10Fixed in: openshift-monitor-project-lifecycle-0:3.10.72-1.git.59.5358725.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.10Fixed in: openshift-monitor-sample-app-0:3.10.72-1.git.5.de405bc.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-openshift-0:3.11.43-1.git.0.647ac05.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.2Fixed in: atomic-openshift-0:3.2.1.34-2.git.20.6367d5d.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.3Fixed in: atomic-openshift-0:3.3.1.46.45-1.git.0.2ce596e.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.3Fixed in: openshift-ansible-0:3.3.149-1.git.0.3859ddb.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.4Fixed in: atomic-openshift-0:3.4.1.44.57-1.git.0.a631031.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.4Fixed in: openshift-ansible-0:3.4.172-1.git.0.33fe526.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.5Fixed in: atomic-openshift-0:3.5.5.31.80-1.git.0.c4a0780.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.5Fixed in: cockpit-0:160-3.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.5Fixed in: openshift-ansible-0:3.5.175-1.git.0.1274ebe.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.6Fixed in: atomic-openshift-0:3.6.173.0.140-1.git.0.9686d52.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.6Fixed in: openshift-ansible-0:3.6.173.0.140-1.git.0.0ccb19b.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.7Fixed in: atomic-openshift-0:3.7.72-1.git.0.925b9cd.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.7Fixed in: openshift-ansible-0:3.7.72-1.git.0.5c45a8a.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.8Fixed in: atomic-openshift-0:3.8.44-1.git.0.9be0abd.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.9Fixed in: atomic-openshift-0:3.9.51-1.git.0.dc3a40b.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.10Fixed in: atomic-openshift-0:3.10.72-1.git.0.3cb2fdc.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.10Fixed in: atomic-openshift-dockerregistry-0:3.10.72-1.git.390.186ec4f.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.10Fixed in: atomic-openshift-descheduler-0:3.10.72-1.git.299.953c1c8.el7
View patch
vuepatch availablevia llm_extracted
View patch
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Enterprise 3.0Fixed in: openshift

Vendor Advisories (6)

goGHSA-579h-mv94-g4gpcritical

Privilege Escalation in Kubernetes

Feb 15, 2022
redhatCVE-2018-1002105Critical

kubernetes: authentication/authorization bypass in the handling of non-101 responses

Dec 3, 2018
vuellm-vue-c74ea1909884a17a

proxy request handling in kube-apiserver can leave vulnerable TCP connections

chromellm-chrome-1c32f65a23aa2617

proxy request handling in kube-apiserver can leave vulnerable TCP connections

check_pointllm-check_point-2c86f0f59c49386c

proxy request handling in kube-apiserver can leave vulnerable TCP connections

infiniflowllm-infiniflow-45cfd4099890d8b4

proxy request handling in kube-apiserver can leave vulnerable TCP connections

References

lists.opensuse.org / opensuse-security-announce/2020-04/msg00041.html
access.redhat.com / errata/RHSA-2018:3537
Third Party Advisory
access.redhat.com / errata/RHSA-2018:3549
Third Party Advisory
access.redhat.com / errata/RHSA-2018:3551
Third Party Advisory
access.redhat.com / errata/RHSA-2018:3598
Third Party Advisory
access.redhat.com / errata/RHSA-2018:3624
Third Party Advisory
access.redhat.com / errata/RHSA-2018:3742
Third Party Advisory
access.redhat.com / errata/RHSA-2018:3752
Third Party Advisory
access.redhat.com / errata/RHSA-2018:3754
Third Party Advisory
github.com / evict/poc_CVE-2018-1002105
ExploitThird Party Advisory
github.com / kubernetes/kubernetes/issues/71411
Issue TrackingMitigationPatchThird Party Advisory
groups.google.com / forum
security.netapp.com / advisory/ntap-20190416-0001
Third Party Advisory
coalfire.com / The-Coalfire-Blog/December-2018/Kubernetes-Vulnerability-What-You-Can-Should-Do
MitigationThird Party Advisory
exploit-db.com / exploits/46052
ExploitThird Party AdvisoryVDB Entry
exploit-db.com / exploits/46053
ExploitThird Party AdvisoryVDB Entry
openwall.com / lists/oss-security/2019/06/28/2
openwall.com / lists/oss-security/2019/07/06/3
openwall.com / lists/oss-security/2019/07/06/4
securityfocus.com / bid/106068
Third Party AdvisoryVDB Entry