CVE-2021-25740General(kubernetes / kubernetes)

LOWCVSS 3.1 · LOW

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch kubernetes kubernetes systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A security issue was discovered with Kubernetes that could enable users to send network traffic to locations they would otherwise not have access to via a confused deputy attack.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-441CWE-610

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kubernetes

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 5 classified signals
  • Disclosure: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-05-22); latest day: 1
  • 7 total mentions across 6 days

Affected systems

Vendors
Products
kubernetes

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-05-21: 1Mentions · 2026-05-22: 2Mentions · 2026-05-25: 1Mentions · 2026-06-01: 1Mentions · 2026-06-06: 1Mentions · 2026-08-23: 1PoC Mentioned / Linked · 2026-05-25: 1Patch / Workaround · 2026-06-01: 1Technical Details · 2026-05-21: 1Technical Details · 2026-06-01: 105-2105-2205-2506-0106-0608-23
Signal classification3 categories
General
571.4%
Disclosure
114.3%
PoC
114.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-211
Disclosure1
2026-05-222
General2
2026-05-251
PoC1
2026-06-011
General1
2026-06-061
General1
2026-08-231
General1
Full discourse7 posts
  • AWS Security Digest@AwsSecDigest
    PoC

    🛎️ AWS Security Digest 262 is out! 1️⃣ Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments by Seth Art 2️⃣ 3 prerequisites to adopting Claude Platform on AWS by Nigel Sood 3️⃣ Unpatchable Vulnerabilities of Kubernetes: CVE-2021-25740 by Rory McCune https://awssecuritydigest.com/past-issues/aws-security-digest-262

    Post summary

    The digest announces a resource for deploying intentionally vulnerable AWS environments and highlights an unpatchable Kubernetes CVE, indicating a focus on proof‑of‑concept scenarios.

    00001180
    1.7K followersView on X
  • Cyber Research@Cyb3rR3s34rch
    General

    Originally from DataDog: Unpatchable Vulnerabilities of Kubernetes: CVE-2021-25740 https://securitylabs.datadoghq.com/articles/unpatchable-kubernetes-vulnerabilities-cve-2021-25740/ ( :-{ı▓ #cloudsecurity #datadog #cyberresearch https://t.co/4LmUh33rxT

    Post summary

    The tweet references a DataDog article about the unpatchable Kubernetes vulnerability CVE-2021-25740, but it provides no technical details, PoC, exploit code, or evidence of exploitation.

    0001053
    61 followersView on X
  • Mas73r@Mas73r
    General

    Unpatchable Vulnerabilities of Kubernetes: CVE-2021-25740 https://securitylabs.datadoghq.com/articles/unpatchable-kubernetes-vulnerabilities-cve-2021-25740/

    Post summary

    The brief post references CVE‑2021‑25740 but offers no additional technical, exploit, or mitigation details.

    0000025
    463 followersView on X
  • Sergio Cuéllar ☁️ (@ 🏠)@5ergio_Cuellar
    General

    Update: Unfixed Kubernetes CVE records corrected! 🔒🔎 Learn about CVE-2020-8561, CVE-2020-8562, and CVE-2021-25740 architectural risks. #Kubernetes #Security #CVE #Tech https://kubernetes.io/blog/2026/05/26/reconciling-unfixed-kubernetes-cves/

    Post summary

    The post notes that a Kubernetes blog has corrected unfixed CVE records for CVE-2020-8561, CVE-2020-8562, and CVE-2021-25740, but offers no further technical or exploit details.

    0000023
    590 followersView on X
  • Daily Notes📚@0x_codex
    General

    1/ Kubernetes just made a security move that looks boring, but matters a lot: it corrected older CVE records for issues that are still unfixed. The result: scanners may suddenly start flagging risks that were always there, but previously hidden by bad metadata. #Kubernetes #Cybersecurity 2/ The key detail: these are not simple “forgot to patch” bugs. Kubernetes says CVE-2020-8561, CVE-2020-8562, and CVE-2021-25740 are architectural tradeoffs. Fixing them cleanly would break real cluster behavior: webhooks, DNS/proxy flows, or Endpoint/EndpointSlice-based networking. 3/ Example: CVE-2020-8561. The API server follows HTTP redirects when calling admission webhooks. That can let someone who controls webhook responses redirect kube-apiserver requests toward private networks. The mitigation is operational: keep API server verbosity below 10 and set `--profiling=false`. 4/ CVE-2020-8562 is a DNS TOCTOU problem. Kubernetes checks a resolved IP, then later connects after another resolution. In dynamic DNS environments, pinning the result can break legitimate setups, so the advised mitigation is a local caching resolver like dnsmasq with a low non-zero TTL. 5/ CVE-2021-25740 is even more Kubernetes-native: Endpoints and EndpointSlices can point traffic at manually specified IPs, which may let users route LoadBalancer/Ingress traffic across namespace boundaries. The mitigation is RBAC: restrict write access to Endpoints and EndpointSlices, especially in upgraded clusters. 6/ The lesson is bigger than these three CVEs. Security scanners are only as good as the metadata they ingest. When “fixed version” fields are wrong, automation creates false confidence. Kubernetes correcting old CVE records is a reminder that mature security is not just patches — it is accurate truth in the supply chain. #CloudNative #DevOps #OpenSource

    Post summary

    The post highlights that Kubernetes just corrected the metadata of older CVE records that remain unfixed, explains the technical nature of three specific vulnerabilities, and recommends operational mitigations instead of patching.

    0000020
    56 followersView on X
  • Mas73r@Mas73r
    General

    Unpatchable Vulnerabilities of Kubernetes: CVE-2021-25740 https://securitylabs.datadoghq.com/articles/unpatchable-kubernetes-vulnerabilities-cve-2021-25740/

    Post summary

    The text mentions the CVE-2021-25740 as an unpatchable Kubernetes vulnerability but provides no additional details on PoC, exploitation, patches, or technical specifics.

    0000026
    470 followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Disclosure

    Kubernetes CVE-2021-25740 can let users with EndpointSlice access redirect shared ingress or LoadBalancer traffic to unauthorized pods across namespaces in multi-tenant clusters. #Kubernetes #EndpointSlice #GatewayAPI https://ift.tt/Rz8H67U

    Post summary

    The tweet highlights that CVE-2021-25740 permits users with EndpointSlice access to redirect ingress/LoadBalancer traffic to unauthorized pods across namespaces, but offers no PoC, exploit, or active exploitation evidence, only technical details of the vulnerability.

    00000130
    4.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkuberneteskubernetes---

Explore more