Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Kubevirt

First CVE: Mar 25, 2019Active for: 7 yearsTotal CVEs: 21
17.0
VTI Score
Low

Kubevirt is a specialized virtualization platform that extends Kubernetes to manage virtual machine workloads, with a focused product portfolio centered on the core Kubevirt project and its complementary Containerized Data Importer component. The vulnerability surface reflects the platform's hybrid nature: exposure of sensitive information, improper authentication and certificate validation, path-traversal conditions, and permission-assignment weaknesses recur across products, indicating security challenges at the boundary between container orchestration and VM abstraction. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
21
Total CVEs
More Total CVEs than 96% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Kubevirt over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 25, 2019
7 years ago
Most Recent CVE
Jun 26, 2026
29 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-13325HIGH
A flaw was found in KubeVirt's migration proxy. When spec.configuration.migrations.disableTLS is set to true on the KubeVirt custom resource, the target virt-handler binds a plain
Jun 26, 20268.537NONO
CVE-2026-13201HIGH
A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but downstream
Jun 24, 20267.331NONO
CVE-2026-13318MEDIUM
A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. When processing a port-forward request to a VirtualMachineInstance (VMI), virt-api
Jun 26, 20266.430NONO
CVE-2020-14316CRITICAL
A flaw was found in kubevirt 0.29 and earlier. Virtual Machine Instances (VMIs) can be used to gain access to the host's filesystem. Successful exploitation allows an attacker to a
Jul 29, 20209.930NONO
CVE-2026-13208MEDIUM
A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SEvent derive the VMI identity (namespace/name) solely from th
Jun 24, 20266.529NONO
CVE-2026-13218MEDIUM
A flaw was found in KubeVirt's virt-handler network cache handling. The WriteToCachedFile function writes data to a launcher-rooted path using os.WriteFile and os.Chown without sym
Jun 26, 20264.225NONO
CVE-2025-64324HIGH
KubeVirt is a virtual machine management add-on for Kubernetes. The `hostDisk` feature in KubeVirt allows mounting a host file or directory owned by the user with UID 107 into a VM
Nov 18, 20257.725NONO
CVE-2026-13434MEDIUM
A flaw was found in KubeVirt's network annotation generator. When a tenant creates a VirtualMachineInstance with a Multus network configuration, the supplied networkName value is w
Jun 26, 20264.924NONO
CVE-2026-13322LOW
A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Reader.ReadLine(), which buffers input indefinitely until a ne
Jun 26, 20263.824NONO
CVE-2025-64434MEDIUM
KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, due to the peer verification logic in virt-handler (via verifyPeerCert), an attacker who c
Nov 7, 20256.322NONO
View all 21 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products21 CVEs
71%
19%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local10 (47.6%)
Network11 (52.4%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (57.1%)
High9 (42.9%)
Unknown0 (0.0%)
User Interaction
None21 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low17 (81.0%)
High1 (4.8%)
None3 (14.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Kubevirt.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Kubevirt — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Kubevirt's Products

View all 4 CNAs →

Top CWEs