K3s is a lightweight Kubernetes distribution designed for resource-constrained and edge-computing environments, and its limited vulnerability footprint centers on the core product itself. The observed weakness pattern reflects the system's resource-management role, with exposure centered on improper resource allocation and throttling that can lead to denial-of-service conditions in containerized deployments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by K3s over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-46599MEDIUM CNCF K3s 1.32 before 1.32.4-rc1+k3s1 has a Kubernetes kubelet configuration change with the unintended consequence that, in some situations, ReadOnlyPort is set to 10255. For examp | Apr 25, 2025 | 6.8 | 19 | NO | NO |
CVE-2023-32187HIGH An Allocation of Resources Without Limits or Throttling vulnerability in SUSE k3s allows attackers with access to K3s servers' apiserver/supervisor port (TCP 6443) cause denial of | Sep 18, 2023 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by K3s.
Media articles that mention a CVE ID that affects a product developed by K3s — matched by CVE ID, not by vendor name.