Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-8558

29
FAUCET Score

CVE-2020-8558 is a high-severity vulnerability affecting Kubernetes Kubelet and kube-proxy components in versions 1.1.0-1.16.10, 1.17.0-1.17.6, and 1.18.0-1.18.3. This flaw allows adjacent hosts to access TCP and UDP services bound to 127.0.0.1 on a node, which are typically intended for local access only. With a CVSS score of 8.8 (HIGH), the vulnerability has an adjacent network attack vector (AV:A) with low attack complexity (AC:L), posing a significant risk of high impact to confidentiality, integrity, and availability (C:H/I:H/A:H). While there are no known public exploits or Metasploit/Nuclei modules, it has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.1.0, <= 1.16.10CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
>= 1.17.0, <= 1.17.6CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*
>= 1.18.0, <= 1.18.3CPE matchmatch criteria
cpe:2.3:a:kubernetes:kubernetes:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
3.60%
Probability of exploitation in next 30 days
EPSS Percentile
88.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0360 is in the 93rd percentile among its peer group of 1,875 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (18)

check_pointpatch availablevia llm_extracted
View patch
chromepatch availablevia llm_extracted
View patch
denopatch availablevia llm_extracted
View patch
github_advisorypatch availablevia nvd_reference
View patch
gopatch availablevia ghsa
Product: k8s.io/kubernetesFixed in: 1.16.11
gopatch availablevia ghsa
Product: k8s.io/kubernetesFixed in: 1.18.4
gopatch availablevia ghsa
Product: k8s.io/kubernetesFixed in: 1.17.7
infiniflowpatch availablevia llm_extracted
View patch
invoiceplanepatch availablevia llm_extracted
View patch
pjsippatch availablevia llm_extracted
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.5Fixed in: openshift-0:4.5.0-202007012112.p0.git.0.582d7fc.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.4Fixed in: openshift4/ose-hyperkube:v4.4.0-202007120152.p0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.3Fixed in: openshift4/ose-hyperkube:v4.3.31-202007272153.p0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.3Fixed in: openshift-0:4.3.31-202007280738.p0.git.0.9884401.el8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 3.11Fixed in: atomic-openshift-0:3.11.248-1.git.0.92ee8ac.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.5Fixed in: openshift4/ose-hyperkube:v4.5.0-202007100518.p0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.4Fixed in: openshift-0:4.4.0-202007090832.p0.git.0.bc32fb1.el7
View patch
vuepatch availablevia llm_extracted
View patch

Vendor Advisories (9)

goGHSA-wqv3-8cm6-h6wghigh

Improper Authentication in Kubernetes

Feb 15, 2022
redhatCVE-2020-8558Moderate

kubernetes: node localhost services reachable via martian packets

Jul 8, 2020
pjsipllm-pjsip-6e02c3199d5e310eMEDIUM

Kubernetes Networking Vulnerability (Loopback Interface Traffic Interception)

Jan 1, 2020
denollm-deno-c37e2fbc523a152aMEDIUM

Kubernetes Networking Vulnerability (Loopback Interface Exposure)

chromellm-chrome-9d3fb7bf64f88173

Node setting allows for neighboring hosts to bypass localhost boundary

check_pointllm-check_point-d087d6200118eaa7

Node setting allows for neighboring hosts to bypass localhost boundary

infiniflowllm-infiniflow-fc728f598f9d5bfa

Node setting allows for neighboring hosts to bypass localhost boundary

vuellm-vue-e024e561177f162a

Node setting allows for neighboring hosts to bypass localhost boundary

invoiceplanellm-invoiceplane-27f6516467f3e8bcMEDIUM

A networking vulnerability, CVE-2020-8558, was recently discovered in Kubernetes. Services sometimes communicate with other applications running inside the same Pod using the local loopback interface (127.0.0.1).

References

github.com / kubernetes/kubernetes/issues/92315
ExploitMitigationPatchThird Party Advisory
groups.google.com / g/kubernetes-announce/c/sI4KmlH3S2I/m/TljjxOBvBQAJ
ExploitMailing ListMitigationThird Party Advisory
security.netapp.com / advisory/ntap-20200821-0001
Third Party Advisory