CVE-2020-8562General(kubernetes / kubernetes)

LOWCVSS 3.1 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch kubernetes kubernetes systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

As mitigations to a report from 2019 and CVE-2020-8555, Kubernetes attempts to prevent proxied connections from accessing link-local or localhost networks when making user-driven connections to Services, Pods, Nodes, or StorageClass service providers. As part of this mitigation Kubernetes does a DNS name resolution check and validates that response IPs are not in the link-local (169.254.0.0/16) or localhost (127.0.0.0/8) range. Kubernetes then performs a second DNS resolution without validation for the actual connection. If a non-standard DNS server returns different non-cached responses, a user may be able to bypass the proxy IP restriction and access private networks on the control plane.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kubernetes

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-10); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
kubernetes

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-10: 2Mentions · 2026-06-01: 1Mentions · 2026-06-06: 1Patch / Workaround · 2026-04-10: 1Patch / Workaround · 2026-06-01: 1Technical Details · 2026-04-10: 1Technical Details · 2026-06-01: 104-1006-0106-06
Signal classification2 categories
General
250.0%
Patch
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-102
General1Patch1
2026-06-011
Patch1
2026-06-061
General1
Full discourse4 posts
  • Sergio Cuéllar ☁️ (@ 🏠)@5ergio_Cuellar
    General

    Update: Unfixed Kubernetes CVE records corrected! 🔒🔎 Learn about CVE-2020-8561, CVE-2020-8562, and CVE-2021-25740 architectural risks. #Kubernetes #Security #CVE #Tech https://kubernetes.io/blog/2026/05/26/reconciling-unfixed-kubernetes-cves/

    Post summary

    The post announces a blog update that corrects the record of unfixed Kubernetes CVEs, listing their identifiers but providing no details on exploitation, patches, or technical specifics.

    0000023
    590 followersView on X
  • Daily Notes📚@0x_codex
    Patch

    1/ Kubernetes just made a security move that looks boring, but matters a lot: it corrected older CVE records for issues that are still unfixed. The result: scanners may suddenly start flagging risks that were always there, but previously hidden by bad metadata. #Kubernetes #Cybersecurity 2/ The key detail: these are not simple “forgot to patch” bugs. Kubernetes says CVE-2020-8561, CVE-2020-8562, and CVE-2021-25740 are architectural tradeoffs. Fixing them cleanly would break real cluster behavior: webhooks, DNS/proxy flows, or Endpoint/EndpointSlice-based networking. 3/ Example: CVE-2020-8561. The API server follows HTTP redirects when calling admission webhooks. That can let someone who controls webhook responses redirect kube-apiserver requests toward private networks. The mitigation is operational: keep API server verbosity below 10 and set `--profiling=false`. 4/ CVE-2020-8562 is a DNS TOCTOU problem. Kubernetes checks a resolved IP, then later connects after another resolution. In dynamic DNS environments, pinning the result can break legitimate setups, so the advised mitigation is a local caching resolver like dnsmasq with a low non-zero TTL. 5/ CVE-2021-25740 is even more Kubernetes-native: Endpoints and EndpointSlices can point traffic at manually specified IPs, which may let users route LoadBalancer/Ingress traffic across namespace boundaries. The mitigation is RBAC: restrict write access to Endpoints and EndpointSlices, especially in upgraded clusters. 6/ The lesson is bigger than these three CVEs. Security scanners are only as good as the metadata they ingest. When “fixed version” fields are wrong, automation creates false confidence. Kubernetes correcting old CVE records is a reminder that mature security is not just patches — it is accurate truth in the supply chain. #CloudNative #DevOps #OpenSource

    Post summary

    Kubernetes clarified older CVE records for architectural issues, provided technical details and mitigations, but no PoC, exploit, or active exploitation is reported.

    0000020
    56 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    CVE-2020-8562 exposes a TOCTOU race in Kubernetes API server proxy, enabling bypass of IP filters via DNS rebinding to access internal control plane services. Mitigations include DNS TTL enforcement and Konnectivity. #KubernetesVuln #TOCTOU #USA https://ift.tt/ZrB5QYS

    Post summary

    The post details a TOCTOU race in the Kubernetes API server proxy that allows DNS rebinding to bypass IP filters, and it recommends mitigations such as DNS TTL enforcement and Konnectivity.

    00000131
    3.9K followersView on X
  • Cyber Research@Cyb3rR3s34rch
    General

    Originally from DataDog: Unpatchable Vulnerabilities of Kubernetes: CVE-2020-8562 https://securitylabs.datadoghq.com/articles/unpatchable-kubernetes-vulnerabilities-cve-2020-8562/ ( :-{ı▓ #cloudsecurity #datadog #cyberresearch https://t.co/kQOBULSsjk

    Post summary

    The tweet merely points to a DataDog article about a Kubernetes vulnerability, offering no additional details, PoC, or evidence of exploitation.

    0000055
    53 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appkuberneteskubernetes---
Appkuberneteskubernetes1.21.0--

Explore more