CVE-2019-11253 is a high-severity improper input validation vulnerability in the Kubernetes API server, affecting versions v1.0-1.12 and specific earlier releases of v1.13, v1.14, v1.15, and v1.16, as well as Red Hat OpenShift Container Platform. An authorized user, or an anonymous user in clusters upgraded from pre-v1.14.0 versions, can send malicious YAML or JSON payloads to trigger a denial-of-service by consuming excessive CPU or memory, potentially crashing the API server. With a CVSS score of 7.5 (High) and an EPSS percentile of 0.80373, this vulnerability is easily exploitable over the network with low complexity and no user interaction, leading to high availability impact. While not on the CISA KEV catalog and with no known active exploitation, a Nuclei template exists for a "Billion Laughs" style DoS attack, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.1.0, <= 1.12.10CPE matchmatch criteria | cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* | ||
>= 1.13.0, < 1.13.12CPE matchmatch criteria | cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* | ||
>= 1.14.0, < 1.14.8CPE matchmatch criteria | cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* | ||
>= 1.15.0, < 1.15.5CPE matchmatch criteria | cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* | ||
>= 1.16.0, < 1.16.2CPE matchmatch criteria | cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
XML Entity Expansion and Improper Input Validation in Kubernetes API server
May 18, 2021kubernetes: YAML parsing vulnerable to "Billion Laughs" attack, allowing for remote denial of service
Sep 28, 2019Kubernetes API Server JSON/YAML parsing vulnerable to resource exhaustion attack
Kubernetes API Server JSON/YAML parsing vulnerable to resource exhaustion attack
Kubernetes API Server JSON/YAML parsing vulnerable to resource exhaustion attack
Kubernetes API Server JSON/YAML parsing vulnerable to resource exhaustion attack