FlawAtlas
Search the atlas
CVE-2021-25736 Moderate

Kube-proxy may unintentionally forward traffic

Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (`spec.ports[*].port`) as a LoadBalancer Service when the LoadBalancer controller does not set the `status.loadBalancer.ingress[].ip` field. Clusters where the LoadBalancer controller sets the `status.loadBalancer.ingress[].ip` field are unaffected.

Exploit probability 0.9%
Published October 30, 2023
Required by Not available
Last source change July 6, 2026

02 / AFFECTED SOFTWARE

Affected packages

Go k8s.io/kubernetes
Unknown Unknown

70 explicit affected versions

Go k8s.io/kubernetes

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities GHSA-35c7-w35f-xwgh

Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (`spec.ports[*].port`) as a LoadBalancer Service when the LoadBalancer controller does not set the `status.loadBalancer.ingress[].ip` field. Clusters where the LoadBalancer controller sets the `status.loadBalancer.ingress[].ip` field are unaffected.

View original source
Open Source Vulnerabilities GO-2023-2159

Kube-proxy may unintentionally forward traffic in k8s.io/kubernetes

View original source
Open Source Vulnerabilities CVE-2021-25736

Kube-proxy on Windows can unintentionally forward traffic to local processes listening on the same port (“spec.ports[*].port”) as a LoadBalancer Service when the LoadBalancer controller does not set the “status.loadBalancer.ingress[].ip” field. Clusters where the LoadBalancer controller sets the “status.loadBalancer.ingress[].ip” field are unaffected.

View original source

05 / REFERENCES

Further evidence