Vulnerability GO-2026-6557
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
6 hours ago
October 01, 2026 at 08:23 PM UTC
KubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha2 API in github.com/kubeedge/kubeedge
v1.12.0 - v1.21.1
v1.12.0 - v1.21.1
Summary
KubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha2 API in github.com/kubeedge/kubeedge
Details
KubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha2 API in github.com/kubeedge/kubeedge
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
6 hours ago
KubeEdge: keadm DecompressTarGz path traversal enables arbitrary file write on Windows during edge node join in github.com/kubeedge/kubeedge
v1.16.0 - v1.21.1 GO-2026-6563
v1.16.0 - v1.21.1 GO-2026-6563
Unknown
6 hours ago
KubeEdge: Unbounded allocation in viaduct packer enables authenticated remote DoS against CloudHub in github.com/kubeedge/kubeedge
v1.0.0 - v1.21.1 GO-2026-6569
v1.0.0 - v1.21.1 GO-2026-6569
Unknown
6 hours ago
KubeEdge: ConfigUpdateJob updateFields enables remote shell injection and code execution on edge nodes in github.com/kubeedge/kubeedge
v1.21.0 - v1.21.1 GO-2026-6573
v1.21.0 - v1.21.1 GO-2026-6573
High Risk
9 days ago
KubeEdge: Command Injection in NodeUpgradeJob - RCE on edge nodes via v1alpha2 API
v1.12.0 - v1.21.1 and v1.22.0 - v1.22.1 and v1.23.0 GHSA-5jpj-293f-rhvj
v1.12.0 - v1.21.1 and v1.22.0 - v1.22.1 and v1.23.0 GHSA-5jpj-293f-rhvj
Medium Risk
9 days ago
KubeEdge: Unbounded allocation in viaduct packer enables authenticated remote DoS against CloudHub
v1.0.0 - v1.21.1 and v1.22.0 - v1.22.1 and v1.23.0 GHSA-gfw4-49f9-cp25
v1.0.0 - v1.21.1 and v1.22.0 - v1.22.1 and v1.23.0 GHSA-gfw4-49f9-cp25
Impacted packages
Timeline
Published
6 hours ago
October 01, 2026 at 08:23 PM UTC
Last Modified
6 hours ago
October 01, 2026 at 08:45 PM UTC