CVE-2026-24005

Source
https://cve.org/CVERecord?id=CVE-2026-24005
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24005.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-24005
Aliases
Downstream
Related
Published
2026-02-25T18:53:30.170Z
Modified
2026-04-10T05:39:19.808187Z
Severity
  • 0.0 (None) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N CVSS Calculator
Summary
OpenKruise PodProbeMarker is Vulnerable to SSRF via Unrestricted Host Field
Details

Kruise provides automated management of large-scale applications on Kubernetes. Prior to versions 1.8.3 and 1.7.5, PodProbeMarker allows defining custom probes with TCPSocket or HTTPGet handlers. The webhook validation does not restrict the Host field in these probe configurations. Since kruise-daemon runs with hostNetwork=true, it executes probes from the node network namespace. An attacker with PodProbeMarker creation permission can specify arbitrary Host values to trigger SSRF from the node, perform port scanning, and receive response feedback through NodePodProbe status messages. Versions 1.8.3 and 1.7.5 patch the issue.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-918"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24005.json"
}
References

Affected packages

Git / github.com/openkruise/kruise

Affected ranges

Type
GIT
Repo
https://github.com/openkruise/kruise
Events
Database specific
{
    "versions": [
        {
            "introduced": "1.8.0"
        },
        {
            "fixed": "1.8.3"
        }
    ]
}
Type
GIT
Repo
https://github.com/openkruise/kruise
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.7.5"
        }
    ]
}

Affected versions

v0.*
v0.1.0
v0.1.0-beta.1
v0.1.0-beta.2
v0.10.0
v0.2.0
v0.3.0
v0.3.1
v0.4.0
v0.4.1
v0.5.0
v0.6.0
v0.6.1
v0.7.0
v0.8.0
v0.9.0
v1.*
v1.0.0-alpha.1
v1.0.0-beta.0
v1.2.0
v1.3.0
v1.5.0
v1.5.2
v1.8.0
v1.8.1
v1.8.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24005.json"