Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-7598

16
FAUCET Score

CVE-2024-7598 is a low-severity security flaw in Kubernetes where a malicious pod could temporarily bypass network policy restrictions during namespace deletion. This occurs because network policies might be deleted before the pods they protect, creating a brief window of un-enforced network access. The vulnerability has a CVSS score of 3.1 (LOW) with an adjacent attack vector and high attack complexity, resulting in a potential low impact on confidentiality. There is no known active exploitation, public exploit code, or KEV listing, though it has received minimal community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
KubernetesKube-Apiserver
1.3.0CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

3.1LOW

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.6
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
22.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0030 is in the 33rd percentile among its peer group of 122 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

check_pointpatch availablevia llm_extracted
View patch
chromepatch availablevia llm_extracted
View patch
infiniflowpatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: azl3 kubernetes 1.30.10-25 on Azure Linux 3.0Fixed in: 1.30.10-26
microsoftpatch availablevia msrc
Product: 21378-17084Fixed in: 1.30.10-26
vuepatch availablevia llm_extracted
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-kube-proxy-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-hyperkube-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift

Vendor Advisories (7)

goGHSA-r56h-j38w-hrqqlow

Kubernetes kube-apiserver Vulnerable to Race Condition

Mar 20, 2025
redhatCVE-2024-7598Low

kube-apiserver: Network restriction bypass via race condition during namespace termination

Mar 20, 2025
microsoft2025-Mar/CVE-2024-7598

Network restriction bypass via race condition during namespace termination

Mar 11, 2025
infiniflowllm-infiniflow-c1ae04f0f98cad2f

Network restriction bypass via race condition during namespace termination

vuellm-vue-e6609566d55b18df

Network restriction bypass via race condition during namespace termination

chromellm-chrome-4d84a9af0e4fa74f

Network restriction bypass via race condition during namespace termination

check_pointllm-check_point-408426294dc93729

Network restriction bypass via race condition during namespace termination

References

openwall.com / lists/oss-security/2025/03/20/2
github.com / kubernetes/kubernetes/issues/126587
groups.google.com / g/kubernetes-security-announce/c/67D7UFqiPRc