Gardener is a Kubernetes cluster-management platform with a focused vulnerability footprint centered on its core orchestration product. The observed weakness classes cluster around input validation and output sanitization issues, reflecting the parsing and API-interface demands of a container-orchestration control plane. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gardener over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-47284CRITICAL Gardener implements the automated management and operation of Kubernetes clusters as a service. A security vulnerability was discovered in the `gardenlet` component of Gardener pri | May 19, 2025 | 9.9 | 27 | NO | NO |
CVE-2025-47283CRITICAL Gardener implements the automated management and operation of Kubernetes clusters as a service. A security vulnerability was discovered in Gardener prior to versions 1.116.4, 1.117 | May 19, 2025 | 9.9 | 27 | NO | NO |
CVE-2018-2475HIGH Following the Gardener architecture, the Kubernetes apiserver of a Gardener managed shoot cluster resides in the corresponding seed cluster. Due to missing network isolation a shoo | Oct 9, 2018 | 8.5 | 27 | NO | NO |
CVE-2019-12494HIGH In Gardener before 0.20.0, incorrect access control in seed clusters allows information disclosure by sending HTTP GET requests from one's own shoot clusters to foreign shoot clust | Jun 5, 2019 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gardener.
Media articles that mention a CVE ID that affects a product developed by Gardener — matched by CVE ID, not by vendor name.