Kubevirt is a specialized virtualization platform that extends Kubernetes to manage virtual machine workloads, with a focused product portfolio centered on the core Kubevirt project and its complementary Containerized Data Importer component. The vulnerability surface reflects the platform's hybrid nature: exposure of sensitive information, improper authentication and certificate validation, path-traversal conditions, and permission-assignment weaknesses recur across products, indicating security challenges at the boundary between container orchestration and VM abstraction. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kubevirt over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-13325HIGH A flaw was found in KubeVirt's migration proxy. When spec.configuration.migrations.disableTLS is set to true on the KubeVirt custom resource, the target virt-handler binds a plain | Jun 26, 2026 | 8.5 | 37 | NO | NO |
CVE-2026-13201HIGH A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but downstream | Jun 24, 2026 | 7.3 | 31 | NO | NO |
CVE-2026-13318MEDIUM A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. When processing a port-forward request to a VirtualMachineInstance (VMI), virt-api | Jun 26, 2026 | 6.4 | 30 | NO | NO |
CVE-2020-14316CRITICAL A flaw was found in kubevirt 0.29 and earlier. Virtual Machine Instances (VMIs) can be used to gain access to the host's filesystem. Successful exploitation allows an attacker to a | Jul 29, 2020 | 9.9 | 30 | NO | NO |
CVE-2026-13208MEDIUM A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SEvent derive the VMI identity (namespace/name) solely from th | Jun 24, 2026 | 6.5 | 29 | NO | NO |
CVE-2026-13218MEDIUM A flaw was found in KubeVirt's virt-handler network cache handling. The WriteToCachedFile function writes data to a launcher-rooted path using os.WriteFile and os.Chown without sym | Jun 26, 2026 | 4.2 | 25 | NO | NO |
CVE-2025-64324HIGH KubeVirt is a virtual machine management add-on for Kubernetes. The `hostDisk` feature in KubeVirt allows mounting a host file or directory owned by the user with UID 107 into a VM | Nov 18, 2025 | 7.7 | 25 | NO | NO |
CVE-2026-13434MEDIUM A flaw was found in KubeVirt's network annotation generator. When a tenant creates a VirtualMachineInstance with a Multus network configuration, the supplied networkName value is w | Jun 26, 2026 | 4.9 | 24 | NO | NO |
A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Reader.ReadLine(), which buffers input indefinitely until a ne | Jun 26, 2026 | 3.8 | 24 | NO | NO |
CVE-2025-64434MEDIUM KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, due to the peer verification logic in virt-handler (via verifyPeerCert), an attacker who c | Nov 7, 2025 | 6.3 | 22 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kubevirt.
Media articles that mention a CVE ID that affects a product developed by Kubevirt — matched by CVE ID, not by vendor name.