CVE-2026-24005 is a Server-Side Request Forgery (SSRF) vulnerability affecting OpenKruise Kruise versions prior to 1.8.3 and 1.7.5. An authenticated attacker with PodProbeMarker creation permissions can exploit this by manipulating custom probe configurations to force the kruise-daemon, running with hostNetwork=true, to perform port scanning and SSRF from the node's network namespace, receiving feedback through status messages. This vulnerability has a CVSS score of 7.6 (HIGH), indicating a network attack vector with low attack complexity, leading to high confidentiality impact and low integrity and availability impacts. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.7.5CPE matchmatch criteria | cpe:2.3:a:openkruise:kruise:*:*:*:*:*:*:*:* | ||
>= 1.8.0, < 1.8.3CPE matchmatch criteria | cpe:2.3:a:openkruise:kruise:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.