CVE-2020-8561General(kubernetes / kubernetes)

LOWCVSS 4.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch kubernetes kubernetes systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A security issue was discovered in Kubernetes where actors that control the responses of MutatingWebhookConfiguration or ValidatingWebhookConfiguration requests are able to redirect kube-apiserver requests to private networks of the apiserver. If that user can view kube-apiserver logs when the log level is set to 10, they can view the redirected responses and headers in the logs.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-441CWE-610

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kubernetes

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 6 classified signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-03-27); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
kubernetes

3 versions affected across 1 product

Deep dive

Activity timeline8 mentions / 4d
01223Mentions · 2026-03-27: 3Mentions · 2026-03-28: 3Mentions · 2026-06-01: 1Mentions · 2026-06-06: 1Patch / Workaround · 2026-06-01: 1Technical Details · 2026-03-27: 1Technical Details · 2026-03-28: 1Technical Details · 2026-06-01: 103-2703-2806-0106-06
Signal classification3 categories
General
675.0%
Disclosure
112.5%
Patch
112.5%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-273
General3
2026-03-283
Disclosure1General2
2026-06-011
Patch1
2026-06-061
General1
Full discourse8 posts
  • DFIR Radar@DFIR_Radar
    General

    CVE-2020-8561 enables SSRF attacks by chaining validatingwebhookconfigurations with debug log manipulation on Kubernetes API servers. Particularly dangerous in managed cloud environments where attackers can probe CSP networks from control plane. #DFIR_Radar https://t.co/x76PJFx55M

    Post summary

    The tweet details the SSRF vector of CVE‑2020‑8561 via webhook config chaining and debug log manipulation on Kubernetes, underscoring its danger in managed cloud settings, but offers no PoC, patch, or active exploitation evidence.

    20020204
    1.2K followersView on X
  • DFIR Radar@DFIR_Radar
    General

    Source: https://securitylabs.datadoghq.com/articles/unpatchable-kubernetes-vulnerabilities-cve-2020-8561/

    Post summary

    The provided source link does not supply any concrete details about the CVE, leaving its status ambiguous.

    0001091
    1.0K followersView on X
  • 💻🥷 WarthogTK 🩺 🇺🇦🇪🇺✈️@warthogtk
    General

    Unpatchable Vulnerabilities of Kubernetes: CVE-2020-8561 | Datadog Security Labs https://securitylabs.datadoghq.com/articles/unpatchable-kubernetes-vulnerabilities-cve-2020-8561/

    Post summary

    The fragment only references a Datadog Security Labs article headline and URL about CVE-2020-8561, offering no specific details on PoCs, exploits, mitigations, or activity.

    0001071
    1.7K followersView on X
  • Sergio Cuéllar ☁️ (@ 🏠)@5ergio_Cuellar
    General

    Update: Unfixed Kubernetes CVE records corrected! 🔒🔎 Learn about CVE-2020-8561, CVE-2020-8562, and CVE-2021-25740 architectural risks. #Kubernetes #Security #CVE #Tech https://kubernetes.io/blog/2026/05/26/reconciling-unfixed-kubernetes-cves/

    Post summary

    The post announces that unfixed Kubernetes CVE records for CVE-2020-8561, CVE-2020-8562, and CVE-2021-25740 have been corrected and directs readers to a blog post for more details.

    0000023
    590 followersView on X
  • Daily Notes📚@0x_codex
    Patch

    1/ Kubernetes just made a security move that looks boring, but matters a lot: it corrected older CVE records for issues that are still unfixed. The result: scanners may suddenly start flagging risks that were always there, but previously hidden by bad metadata. #Kubernetes #Cybersecurity 2/ The key detail: these are not simple “forgot to patch” bugs. Kubernetes says CVE-2020-8561, CVE-2020-8562, and CVE-2021-25740 are architectural tradeoffs. Fixing them cleanly would break real cluster behavior: webhooks, DNS/proxy flows, or Endpoint/EndpointSlice-based networking. 3/ Example: CVE-2020-8561. The API server follows HTTP redirects when calling admission webhooks. That can let someone who controls webhook responses redirect kube-apiserver requests toward private networks. The mitigation is operational: keep API server verbosity below 10 and set `--profiling=false`. 4/ CVE-2020-8562 is a DNS TOCTOU problem. Kubernetes checks a resolved IP, then later connects after another resolution. In dynamic DNS environments, pinning the result can break legitimate setups, so the advised mitigation is a local caching resolver like dnsmasq with a low non-zero TTL. 5/ CVE-2021-25740 is even more Kubernetes-native: Endpoints and EndpointSlices can point traffic at manually specified IPs, which may let users route LoadBalancer/Ingress traffic across namespace boundaries. The mitigation is RBAC: restrict write access to Endpoints and EndpointSlices, especially in upgraded clusters. 6/ The lesson is bigger than these three CVEs. Security scanners are only as good as the metadata they ingest. When “fixed version” fields are wrong, automation creates false confidence. Kubernetes correcting old CVE records is a reminder that mature security is not just patches — it is accurate truth in the supply chain. #CloudNative #DevOps #OpenSource

    Post summary

    Kubernetes updated inaccurate CVE metadata, prompting scanners to surface old entries; the post details operational mitigations but does not present an exploit or claim active attacks.

    0000020
    56 followersView on X
  • Cyber Research@Cyb3rR3s34rch
    Disclosure

    Originally from DataDog: Unpatchable Vulnerabilities of Kubernetes: CVE-2020-8561 https://securitylabs.datadoghq.com/articles/unpatchable-kubernetes-vulnerabilities-cve-2020-8561/ ( :-{ı▓ #cloudsecurity #datadog #cyberresearch https://t.co/Ag0tolggTJ

    Post summary

    The tweet references a DataDog article announcing CVE-2020-8561 as an unpatchable Kubernetes vulnerability, providing a link but lacking PoC, exploit, or technical detail.

    0000040
    53 followersView on X
  • (((JReuben1)))@jreuben1
    General

    Unpatchable Vulnerabilities of Kubernetes: CVE-2020-8561 https://securitylabs.datadoghq.com/articles/unpatchable-kubernetes-vulnerabilities-cve-2020-8561/

    Post summary

    The article title references CVE-2020-8561 as an unpatchable Kubernetes vulnerability, but no further technical, PoC, or exploitation details are provided.

    0000078
    2.0K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    General

    CVE-2020-8561 exploits an SSRF flaw in Kubernetes API server’s ValidatingWebhookConfiguration and profiling endpoints to expose full responses. Requires cluster-admin creds to escalate impact. #KubernetesSecurity #SSRF #CVE20208561 https://ift.tt/LEbouZ0

    Post summary

    The tweet outlines the SSRF vulnerability CVE‑2020‑8561, specifying affected Kubernetes API server endpoints and credential requirements, but it gives no PoC, exploit code, active exploitation evidence, or patch notice.

    0000089
    3.9K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appkuberneteskubernetes1.20.11--
Appkuberneteskubernetes1.21.5--
Appkuberneteskubernetes1.22.2--

Explore more