Kyma Project maintains an application integration and microservices platform for Kubernetes environments, with a narrow but deliberately exposed product scope. The observed vulnerability footprint, while limited, should be tracked by defenders operating Kyma-based deployments as part of broader Kubernetes security inventory; current exposure counts and severity figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kyma Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-38182HIGH Due to insufficient input validation of Kyma, authenticated users can pass a Header of their choice and escalate privileges which can completely compromise the cluster. | Dec 14, 2021 | 8.8 | 28 | NO | NO |
CVE-2021-33708HIGH Due to insufficient input validation in Kyma, authenticated users can pass a Header of their choice and escalate privileges. | Aug 10, 2021 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kyma Project.
Media articles that mention a CVE ID that affects a product developed by Kyma Project — matched by CVE ID, not by vendor name.