Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-4563

12
FAUCET Score

CVE-2025-4563 describes a vulnerability in the NodeRestriction admission controller, specifically when the DynamicResourceAllocation feature gate is enabled, allowing compromised nodes to bypass authorization checks for dynamic resource allocation during pod creation. This flaw enables the creation of mirror pods that can access unauthorized dynamic resources, potentially leading to privilege escalation. The vulnerability has a low CVSS score of 2.7 (AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L), indicating a network attack vector with low complexity but requiring high privileges, resulting in a low impact on availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
KubernetesKubernetes
v1.32.0 - v1.32.5, v1.33.0 - v1.33.1CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

2.7LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
1.2
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.63%
Probability of exploitation in next 30 days
EPSS Percentile
46.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0063 is in the 68th percentile among its peer group of 709 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

check_pointpatch availablevia llm_extracted
View patch
chromepatch availablevia llm_extracted
View patch
gopatch availablevia ghsa
Product: k8s.io/kubernetesFixed in: 1.33.2
gopatch availablevia ghsa
Product: k8s.io/kubernetesFixed in: 1.32.6
infiniflowpatch availablevia llm_extracted
View patch
microsoftpatch availablevia msrc
Product: azl3 kubernetes 1.30.10-9 on Azure Linux 3.0Fixed in: 1.30.10-9
microsoftpatch availablevia msrc
Product: 20133-17084Fixed in: 1.30.10-9
vuepatch availablevia llm_extracted
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift

Vendor Advisories (7)

goGHSA-hj2p-8wj8-pfq4low

kubernetes allows nodes to bypass dynamic resource allocation authorization checks

Jun 23, 2025
redhatCVE-2025-4563Low

kube-apiserver: NodeRestriction Admission Controller Dynamic Resource Allocation Bypass

Jun 19, 2025
microsoft2025-Jun/CVE-2025-4563Low

Nodes can bypass dynamic resource allocation authorization checks

Jun 10, 2025
infiniflowllm-infiniflow-ec8ffbf951c96ebf

Nodes can bypass dynamic resource allocation authorization checks

vuellm-vue-fad1495f955a4a14

Nodes can bypass dynamic resource allocation authorization checks

chromellm-chrome-cc55071af01300fe

Nodes can bypass dynamic resource allocation authorization checks

check_pointllm-check_point-32baa69d81d0620c

Nodes can bypass dynamic resource allocation authorization checks

References

github.com / kubernetes/kubernetes/issues/132151
groups.google.com / g/kubernetes-security-announce/c/Zv84LMRuvMQ