CVE-2026-32254Disclosure(kube-router / kube-router)

LOWCVSS 7.1 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch kube-router kube-router systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Kube-router is a turnkey solution for Kubernetes networking. Prior to version 2.8.0, Kube-router's proxy module does not validate externalIPs or loadBalancer IPs before programming them into the node's network configuration. Version 2.8.0 contains a patch for the issue. Available workarounds include enabling DenyServiceExternalIPs feature gate, deploying admission policy, restricting service creation RBAC, monitoring service changes, and applying BGP prefix filtering.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kube-router

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Products
kube-router

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-18: 4Patch / Workaround · 2026-03-18: 1Technical Details · 2026-03-18: 403-18
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-32254 Kube-router Privilege Escalation via Unvalidated External IP Configuration https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32254

    Post summary

    CVE-2026-32254 exposes a privilege escalation flaw in Kube-router caused by unvalidated external IP configuration; the provided text offers vulnerability details but no PoC, exploit code, patch, or evidence of active exploitation.

    0000145
    4.0K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-32254 📊 Severity: 7.1 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-32254 #CVE-2026-32254 #CVE #High  #CyberSecurity #InfoSec https://t.co/dEDpA3YI1n

    Post summary

    The tweet announces the existence of CVE-2026-32254, noting a 7.1 severity score and high risk, but offers no further technical or remedial details.

    0000032
    104 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-32254 - Kube-router Proxy Module Blindly Trusts ExternalIPs/LoadBalancer IPs Enabling Cluster-Wide Traffic Hijacking and DNS DoS Intel Report: https://ift.tt/tUQRqz7

    Post summary

    The tweet alerts about the newly disclosed CVE‑2026‑32254, a kube‑router proxy vulnerability that could allow cluster‑wide traffic hijacking and DNS denial of service; it provides technical details but no exploitation proof or patch information.

    0000048
    335 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32254 Kube-router is a turnkey solution for Kubernetes networking. Prior to version 2.8.0, Kube-router's proxy module does not validate externalIPs or loadBalancer IPs befo… https://www.cve.org/CVERecord?id=CVE-2026-32254

    Post summary

    The text details CVE‑2026‑32254, a kube‑router proxy module flaw that does not validate external IPs or load balancer IPs, and notes that versions prior to 2.8.0 are vulnerable, implying an upgrade patches the issue.

    0000079
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkube-routerkube-router-kubernetes-

Explore more