CVE-2026-32241General(flannel-io / flannel)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch flannel-io flannel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Flannel is a network fabric for containers, designed for Kubernetes. The Flannel project includes an experimental Extension backend that allows users to easily prototype new backend types. In versions of Flannel prior to 0.28.2, this Extension backend is vulnerable to a command injection that allows an attacker who can set Kubernetes Node annotations to achieve root-level arbitrary command execution on every flannel node in the cluster. The Extension backend's SubnetAddCommand and SubnetRemoveCommand receive attacker-controlled data via stdin (from the `flannel.alpha.coreos.com/backend-data` Node annotation). The content of this annotation is unmarshalled and piped directly to a shell command without checks. Kubernetes clusters using Flannel with the Extension backend are affected by this vulnerability. Other backends such as vxlan and wireguard are unaffected. The vulnerability is fixed in version v0.28.2. As a workaround, use Flannel with another backend such as vxlan or wireguard.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • flannel

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-29)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
flannel

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-28: 1Mentions · 2026-03-29: 2Patch / Workaround · 2026-03-29: 1Technical Details · 2026-03-29: 103-2803-29
Signal classification2 categories
General
266.7%
Patch
133.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-03-281
General1
2026-03-292
General1Patch1
Full discourse3 posts
  • NerdieNews@NewsNerdie
    Patch

    CVE-2026-32241 in Flannel allows cross-node remote code execution via BackendData injection, posing a severe risk to network security. Patch immediately to prevent potential exploits across nodes. This vulnerability bypasses standard defenses. #CyberSecurity #InfoSec https://t.co/mgAFvhXciO

    Post summary

    The tweet warns of CVE-2026-32241 in Flannel, a cross-node remote code execution flaw via BackendData injection, urging users to patch immediately.

    0000032
    53 followersView on X
  • PurpleOps@PurpleOps_io
    General

    🔍 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐔𝐩𝐝𝐚𝐭𝐞 𝐆𝐮𝐢𝐝𝐞 - 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐑𝐞𝐬𝐩𝐨𝐧𝐬𝐞 𝐂𝐞𝐧𝐭𝐞𝐫 • The Microsoft Security Response Center publishes a Security Update Guide. • This guide provides information for vulnerability CVE-2026-32241. • Update details are accessible via the MSRC website. The Microsoft Security Response Center publishes a Security Update Guide concerning vulnerability CVE-2026-32241, with details available on their official website.

    Post summary

    The post announces a Microsoft Security Update Guide covering CVE-2026-32241, with information available on the MSRC website, but provides no technical or exploit details.

    0000052
    96 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-32241 Flannel is a network fabric for containers, designed for Kubernetes. The Flannel project includes an experimental Extension backend that allows users to easily protot… https://www.cve.org/CVERecord?id=CVE-2026-32241

    Post summary

    The post references CVE-2026-32241 in the context of Flannel’s experimental Extension backend but provides no technical details, practical exploits, or mitigation information.

    00000135
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appflannel-ioflannel-kubernetes-

Explore more