Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-11254

24
FAUCET Score

CVE-2019-11254 is a denial-of-service vulnerability affecting the Kubernetes API Server in versions 1.1-1.14, and specific later versions prior to 1.15.10, 1.16.7, and 1.17.3. An authorized user can exploit this by sending maliciously crafted YAML payloads, causing the kube-apiserver to consume excessive CPU resources. Rated as MEDIUM severity with a CVSS score of 6.5, this vulnerability has a network attack vector, low attack complexity, and a high impact on availability. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.15.10CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
>= 1.16.0, < 1.16.7CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
>= 1.17.0, < 1.17.3CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.36%
Probability of exploitation in next 30 days
EPSS Percentile
82.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0236 is in the 93rd percentile among its peer group of 21,974 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (16)

check_pointpatch availablevia llm_extracted
View patch
chromepatch availablevia llm_extracted
View patch
denopatch availablevia llm_extracted
View patch
gopatch availablevia ghsa
Product: gopkg.in/yaml.v2Fixed in: 2.2.8
infiniflowpatch availablevia llm_extracted
View patch
invoiceplanepatch availablevia llm_extracted
pjsippatch availablevia llm_extracted
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.5Fixed in: openshift4/ose-oauth-server-rhel7:v4.5.0-202007012112.p0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.5Fixed in: openshift-0:4.5.0-202007012112.p0.git.0.582d7fc.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-openshift-0:3.11.232-1.git.0.a5bc32f.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.3Fixed in: openshift4/ose-openshift-apiserver-rhel7:v4.3.9-202003230345
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.5Fixed in: openshift4/ose-hyperkube:v4.5.0-202007100518.p0
View patch
vuepatch availablevia llm_extracted
View patch
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-oauth-server-rhel8
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-service-catalog
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-hypershift

Vendor Advisories (10)

goGHSA-wxc4-f4m6-wwqvmedium

Excessive Platform Resource Consumption within a Loop in Kubernetes

Dec 20, 2021
microsoft2020-Apr/CVE-2019-11254Moderate

Kubernetes API Server denial of service vulnerability from malicious YAML payloads

Apr 14, 2020
redhatCVE-2019-11254Moderate

kubernetes: Denial of service in API server via crafted YAML payloads by authorized users

Mar 27, 2020
pjsipllm-pjsip-6d1e20da7ffdd038MEDIUM

Kubernetes API Server Denial of Service

Jan 1, 2019
denollm-deno-8d39de6bcdc5fef9MEDIUM

Kubernetes API Server Denial of Service Vulnerability

chromellm-chrome-92cb8b1ec4773a3f

kube-apiserver Denial of Service vulnerability from malicious YAML payloads

vuellm-vue-0afb39a695cd13a2

kube-apiserver Denial of Service vulnerability from malicious YAML payloads

infiniflowllm-infiniflow-0479fc2e2df16e8e

kube-apiserver Denial of Service vulnerability from malicious YAML payloads

check_pointllm-check_point-05ea4630ba638fac

kube-apiserver Denial of Service vulnerability from malicious YAML payloads

invoiceplanellm-invoiceplane-78d0859854da4d6dMEDIUM

This is a Denial of Service (DoS) vulnerability that impacts the API server.

References

github.com / kubernetes/kubernetes/issues/89535
Third Party Advisory
groups.google.com / d/msg/kubernetes-announce/ALL9s73E5ck/4yHe8J-PBAAJ
Third Party Advisory
security.netapp.com / advisory/ntap-20200413-0003
Third Party Advisory