Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-11253

52
FAUCET Score

CVE-2019-11253 is a high-severity improper input validation vulnerability in the Kubernetes API server, affecting versions v1.0-1.12 and specific earlier releases of v1.13, v1.14, v1.15, and v1.16, as well as Red Hat OpenShift Container Platform. An authorized user, or an anonymous user in clusters upgraded from pre-v1.14.0 versions, can send malicious YAML or JSON payloads to trigger a denial-of-service by consuming excessive CPU or memory, potentially crashing the API server. With a CVSS score of 7.5 (High) and an EPSS percentile of 0.80373, this vulnerability is easily exploitable over the network with low complexity and no user interaction, leading to high availability impact. While not on the CISA KEV catalog and with no known active exploitation, a Nuclei template exists for a "Billion Laughs" style DoS attack, though there is minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.1.0, <= 1.12.10CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
>= 1.13.0, < 1.13.12CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
>= 1.14.0, < 1.14.8CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
>= 1.15.0, < 1.15.5CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
>= 1.16.0, < 1.16.2CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
25.94%
Probability of exploitation in next 30 days
EPSS Percentile
97.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Nuclei: CVE-2019-11253 · Dec 26, 2025
This CVE's current EPSS score of 0.2594 is in the 96th percentile among its peer group of 51,455 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (31)

check_pointpatch availablevia llm_extracted
View patch
chromepatch availablevia llm_extracted
View patch
gopatch availablevia ghsa
Product: k8s.io/kubernetesFixed in: 1.14.8
gopatch availablevia ghsa
Product: k8s.io/kubernetesFixed in: 1.15.5
gopatch availablevia ghsa
Product: k8s.io/kubernetesFixed in: 1.16.2
gopatch availablevia ghsa
Product: k8s.io/kubernetesFixed in: 1.13.12
infiniflowpatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Openshift Service Mesh 1.0Fixed in: kiali-0:v1.0.7.redhat1-1.el7
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Service Mesh 1.0Fixed in: servicemesh-0:1.0.2-3.el8
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Service Mesh 1.0Fixed in: servicemesh-cni-0:1.0.2-3.el8
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Service Mesh 1.0Fixed in: servicemesh-grafana-0:6.2.2-24.el8
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Service Mesh 1.0Fixed in: servicemesh-operator-0:1.0.2-7.el8
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Service Mesh 1.0Fixed in: servicemesh-prometheus-0:2.7.2-25.el8
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Service Mesh 1.0Fixed in: servicemesh-proxy-0:1.0.2-3.el8
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Service Mesh 1.0Fixed in: servicemesh-grafana-0:6.2.2-38.el8
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Service Mesh 1.0Fixed in: servicemesh-prometheus-0:2.7.2-36.el8
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Service Mesh 1.0Fixed in: servicemesh-cni-0:1.0.11-1.el8
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Service Mesh 1.1Fixed in: servicemesh-operator-0:1.1.4-3.el8
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Service Mesh 1.1Fixed in: servicemesh-grafana-0:6.4.3-11.el8
View patch
redhatpatch availablevia redhat_api
Product: OpenShift Service Mesh 1.1Fixed in: servicemesh-cni-0:1.1.4-2.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.10Fixed in: atomic-openshift-0:3.10.181-1.git.0.3ab4b3d.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-openshift-0:3.11.154-1.git.0.7a097ad.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.9Fixed in: atomic-openshift-0:3.9.102-1.git.0.6411f52.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.1Fixed in: openshift-0:4.1.20-201910101746.git.0.a80aad5.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenStack Platform 16.2Fixed in: rhosp-rhel8-tech-preview/osp-director-operator:1.2.3-2
View patch
redhatpatch availablevia redhat_api
Product: Openshift Service Mesh 1.0Fixed in: jaeger-operator-0:v1.13.1.redhat8-1.el7
View patch
redhatpatch availablevia redhat_api
Product: Openshift Service Mesh 1.0Fixed in: jaeger-0:v1.13.1.redhat5-1.el7
View patch
vuepatch availablevia llm_extracted
View patch
github_advisoryworkaround availablevia nvd_reference
View patch
redhatno patchvia redhat_api
Product: Red Hat OpenStack Platform 16.2Fixed in: osp-director-provisioner-container
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 16.2Fixed in: rhosp-rhel8/osp-director-downloader

Vendor Advisories (6)

goGHSA-pmqp-h87c-mr78high

XML Entity Expansion and Improper Input Validation in Kubernetes API server

May 18, 2021
redhatCVE-2019-11253Important

kubernetes: YAML parsing vulnerable to "Billion Laughs" attack, allowing for remote denial of service

Sep 28, 2019
vuellm-vue-df0868d9b724bd26

Kubernetes API Server JSON/YAML parsing vulnerable to resource exhaustion attack

chromellm-chrome-cd3c22cff1383ca1

Kubernetes API Server JSON/YAML parsing vulnerable to resource exhaustion attack

check_pointllm-check_point-b3f78d44bbd90b0f

Kubernetes API Server JSON/YAML parsing vulnerable to resource exhaustion attack

infiniflowllm-infiniflow-44d5aaf193189a76

Kubernetes API Server JSON/YAML parsing vulnerable to resource exhaustion attack

References

access.redhat.com / errata/RHSA-2019:3239
Third Party Advisory
access.redhat.com / errata/RHSA-2019:3811
Third Party Advisory
access.redhat.com / errata/RHSA-2019:3905
Third Party Advisory
github.com / kubernetes/kubernetes/issues/83253
ExploitIssue TrackingMitigationThird Party Advisory
groups.google.com / forum
Permissions Required
security.netapp.com / advisory/ntap-20191031-0006
Third Party Advisory