A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection.
History

Thu, 28 Aug 2025 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
References
Metrics threat_severity

None

threat_severity

Moderate


Wed, 27 Aug 2025 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Kubernetes
Kubernetes kubernetes
Vendors & Products Kubernetes
Kubernetes kubernetes

Wed, 27 Aug 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 27 Aug 2025 16:45:00 +0000

Type Values Removed Values Added
Description A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection.
Title Nodes can delete themselves by adding an OwnerReference
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: kubernetes

Published: 2025-08-27T16:20:56.778Z

Updated: 2025-08-28T03:55:26.841Z

Reserved: 2025-05-25T18:24:14.173Z

Link: CVE-2025-5187

cve-icon Vulnrichment

Updated: 2025-08-27T17:20:49.729Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-27T17:15:48.270

Modified: 2025-08-29T16:24:09.860

Link: CVE-2025-5187

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-08-12T16:00:00Z

Links: CVE-2025-5187 - Bugzilla