Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-8552

19
FAUCET Score

CVE-2020-8552 is a denial-of-service vulnerability affecting the Kubernetes API server in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2, including Fedora Project distributions. With a CVSS score of 4.3 (Medium), it can be exploited by an authenticated attacker making successful API requests, leading to low impact on availability. There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.15.9CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
>= 1.16.0, <= 1.16.6CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
>= 1.17.0, <= 1.17.2CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
32CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
< v1.15.10CPE match
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.3MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
2.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.43%
Probability of exploitation in next 30 days
EPSS Percentile
82.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0243 is in the 93rd percentile among its peer group of 21,977 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (36)

check_pointpatch availablevia llm_extracted
View patch
chromepatch availablevia llm_extracted
View patch
denopatch availablevia llm_extracted
View patch
github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: k8s.io/apiserverFixed in: 0.17.3
gopatch availablevia ghsa
Product: k8s.io/apiserverFixed in: 0.15.10
gopatch availablevia ghsa
Product: k8s.io/apiserverFixed in: 0.16.7
infiniflowpatch availablevia llm_extracted
View patch
invoiceplanepatch availablevia llm_extracted
pjsippatch availablevia llm_extracted
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-openshift-node-problem-detector-0:3.11.219-1.git.1.5ae8753.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-openshift-service-idler-0:3.11.219-1.git.1.958cdae.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: golang-github-openshift-oauth-proxy-0:3.11.219-1.git.1.076ae14.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: golang-github-prometheus-alertmanager-0:3.11.219-1.git.1.9a593f8.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: golang-github-prometheus-node_exporter-0:3.11.219-1.git.1.7fa9674.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: golang-github-prometheus-prometheus-0:3.11.219-1.git.1.3f6e657.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: openshift-ansible-0:3.11.219-1.git.0.8845382.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: openshift-enterprise-autoheal-0:3.11.219-1.git.1.c544df9.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: openshift-enterprise-cluster-capacity-0:3.11.219-1.git.1.ca1ee51.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: openshift-kuryr-0:3.11.219-1.git.1.717d59f.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-openshift-0:3.11.248-1.git.0.92ee8ac.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.2Fixed in: openshift4/ose-hyperkube:v4.2.29-202004140532
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.2Fixed in: openshift-0:4.2.29-202004120346.git.0.d948116.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.2Fixed in: openshift4/ose-openshift-apiserver-rhel7:v4.2.34-202005252115
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.3Fixed in: openshift-0:4.3.9-202003230116.git.0.ebf9a26.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.3Fixed in: openshift4/ose-hyperkube:v4.3.9-202003230345
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.3Fixed in: openshift4/ose-openshift-apiserver-rhel7:v4.3.9-202003230345
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-enterprise-service-catalog-1:3.11.219-1.git.1.717017c.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-openshift-metrics-server-0:3.11.219-1.git.1.6fe54fb.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-openshift-cluster-autoscaler-0:3.11.219-1.git.1.1ad3e34.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-openshift-0:3.11.219-1.git.0.0c21387.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-openshift-dockerregistry-0:3.11.219-1.git.1.8323991.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-openshift-descheduler-0:3.11.219-1.git.1.7e5b9ee.el7
View patch
vuepatch availablevia llm_extracted
View patch
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-service-catalog
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-hypershift

Vendor Advisories (9)

goGHSA-82hx-w2r5-c2wqmedium

Kubernetes API Server DoS Via API Requests

Feb 15, 2022
redhatCVE-2020-8552Moderate

kubernetes: Use of unbounded 'client' label in apiserver_request_total allows for memory exhaustion

Mar 23, 2020
pjsipllm-pjsip-3531fbd23a0014cdMEDIUM

Kubernetes Kubelet and API Server Denial of Service

Jan 1, 2020
denollm-deno-3bdcbc62fa4f0a0fMEDIUM

Kubernetes API Server Denial of Service Vulnerability

chromellm-chrome-14268d64757a1b8a

apiserver DoS (oom)

check_pointllm-check_point-1b88ec164580c3d4

apiserver DoS (oom)

infiniflowllm-infiniflow-c53bb610af47950b

apiserver DoS (oom)

vuellm-vue-a1b3bdc5bb4cf383

apiserver DoS (oom)

invoiceplanellm-invoiceplane-923040ca521b5ea5MEDIUM

This is a Denial of Service (DoS) vulnerability that impacts the API server.

References

github.com / kubernetes/kubernetes/issues/89378
Issue TrackingPatchThird Party Advisory
groups.google.com / forum
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/3SOCLOPTSYABTE4CLTSPDIFE6ZZZR4LX
security.netapp.com / advisory/ntap-20200413-0003
Third Party Advisory