Devspace is a development environment and workflow tool that occupies a niche within container and Kubernetes tooling, with its disclosed vulnerabilities centered on a single product line. The recurring weakness classes involve missing authentication controls for critical functions and exposure of sensitive information, reflecting the attack surface inherent to a local development platform with network connectivity and credential handling. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Devspace over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-42283HIGH DevSpace is a client-only developer tool for cloud-native development with Kubernetes. Prior to 6.3.21, DevSpace's UI server WebSocket accepts connections from all origins by defau | May 14, 2026 | 7.8 | 30 | NO | NO |
CVE-2020-15391CRITICAL The UI in DevSpace 4.13.0 allows web sites to execute actions on pods (on behalf of a victim) because of a lack of authentication for the WebSocket protocol. This leads to remote c | Jul 23, 2020 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Devspace.
Media articles that mention a CVE ID that affects a product developed by Devspace — matched by CVE ID, not by vendor name.