Flux CD is a continuous-delivery platform for Kubernetes that automates application deployment and configuration management through declarative, Git-driven workflows. Its vulnerability profile, concentrated in components such as Flux2, Kustomize Controller, and Helm Controller, skews toward serious outcomes with an elevated share reaching critical severity, driven by recurrent weakness classes including path traversal, code injection, and OS command injection that arise in the parsing and execution of manifests and configurations. Defenders should treat Flux CD advisories as high-priority in environments where the platform reconciles untrusted or externally sourced Kubernetes configurations; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fluxcd over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24817CRITICAL Flux2 is an open and extensible continuous delivery solution for Kubernetes. Flux2 versions between 0.1.0 and 0.29.0, helm-controller 0.1.0 to v0.19.0, and kustomize-controller 0.1 | May 6, 2022 | 9.9 | 31 | NO | NO |
CVE-2022-24877HIGH Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious `kustomization.yaml` allows an attacker to ex | May 6, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-41254HIGH kustomize-controller is a Kubernetes operator, specialized in running continuous delivery pipelines for infrastructure and workloads defined with Kubernetes manifests and assembled | Nov 12, 2021 | 8.8 | 28 | NO | NO |
CVE-2022-36035HIGH Flux is a tool for keeping Kubernetes clusters in sync with sources of configuration (like Git repositories), and automating updates to configuration when there is new code to depl | Aug 31, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-24878MEDIUM Flux is an open and extensible continuous delivery solution for Kubernetes. Path Traversal in the kustomize-controller via a malicious `kustomization.yaml` allows an attacker to ca | May 6, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-39272MEDIUM Flux is an open and extensible continuous delivery solution for Kubernetes. Versions prior to 0.35.0 are subject to a Denial of Service. Users that have permissions to change Flux’ | Oct 22, 2022 | 4.3 | 19 | NO | NO |
CVE-2022-36049HIGH Flux2 is a tool for keeping Kubernetes clusters in sync with sources of configuration, and Flux's helm-controller is a Kubernetes operator that allows one to declaratively manage H | Sep 7, 2022 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fluxcd.
Media articles that mention a CVE ID that affects a product developed by Fluxcd — matched by CVE ID, not by vendor name.