Cloudark's vulnerability footprint centers on KubePlus, a Kubernetes extension product that provides custom resource and operator management capabilities. The durable signal reflects application-layer command and request handling issues, with recurrent weakness classes including code injection, argument injection, and server-side request forgery that are characteristic of dynamic orchestration and templating workflows. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cloudark over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-29955HIGH The `/registercrd` endpoint in KubePlus 4.14 in the kubeconfiggenerator component is vulnerable to command injection. The component uses `subprocess.Popen()` with `shell=True` para | Apr 13, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-29954HIGH In KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF vulnerability when processing the chartURL field of ResourceComposition resources. The field | Mar 30, 2026 | 7.6 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cloudark.
Media articles that mention a CVE ID that affects a product developed by Cloudark — matched by CVE ID, not by vendor name.