Skip to content

chore(deps): update module k8s.io/kubernetes to v1.32.10 [security]#78

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/go-k8s.io-kubernetes-vulnerability
Open

chore(deps): update module k8s.io/kubernetes to v1.32.10 [security]#78
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/go-k8s.io-kubernetes-vulnerability

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Dec 16, 2025

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
k8s.io/kubernetes v1.32.8v1.32.10 age adoption passing confidence

kube-controller-manager is vulnerable to half-blind Server Side Request Forgery through in-tree Portworx StorageClass

CVE-2025-13281 / GHSA-r6j8-c6r2-37rr

More information

Details

A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).

Severity

  • CVSS Score: 5.8 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

kubernetes/kubernetes (k8s.io/kubernetes)

v1.32.10: Kubernetes v1.32.10

Compare Source

See kubernetes-announce@. Additional binary downloads are linked in the CHANGELOG.

See the CHANGELOG for more details.

v1.32.9: Kubernetes v1.32.9

Compare Source

See kubernetes-announce@. Additional binary downloads are linked in the CHANGELOG.

See the CHANGELOG for more details.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot force-pushed the renovate/go-k8s.io-kubernetes-vulnerability branch from 6d2b814 to dad5b32 Compare February 2, 2026 18:10
@renovate renovate Bot force-pushed the renovate/go-k8s.io-kubernetes-vulnerability branch from dad5b32 to e2b7888 Compare February 12, 2026 11:33
@renovate renovate Bot force-pushed the renovate/go-k8s.io-kubernetes-vulnerability branch from e2b7888 to fdf8675 Compare March 2, 2026 19:38
@renovate renovate Bot changed the title chore(deps): update module k8s.io/kubernetes to v1.32.10 [security] chore(deps): update module k8s.io/kubernetes to v1.32.10 [security] - autoclosed Mar 27, 2026
@renovate renovate Bot closed this Mar 27, 2026
@renovate renovate Bot deleted the renovate/go-k8s.io-kubernetes-vulnerability branch March 27, 2026 02:02
@renovate renovate Bot changed the title chore(deps): update module k8s.io/kubernetes to v1.32.10 [security] - autoclosed chore(deps): update module k8s.io/kubernetes to v1.32.10 [security] Mar 30, 2026
@renovate renovate Bot reopened this Mar 30, 2026
@renovate renovate Bot force-pushed the renovate/go-k8s.io-kubernetes-vulnerability branch 2 times, most recently from fdf8675 to 24049dd Compare March 30, 2026 21:12
@renovate renovate Bot force-pushed the renovate/go-k8s.io-kubernetes-vulnerability branch from 24049dd to da155e0 Compare April 10, 2026 23:06
@renovate renovate Bot changed the title chore(deps): update module k8s.io/kubernetes to v1.32.10 [security] chore(deps): update module k8s.io/kubernetes to v1.32.10 [security] - autoclosed Apr 27, 2026
@renovate renovate Bot closed this Apr 27, 2026
@renovate renovate Bot changed the title chore(deps): update module k8s.io/kubernetes to v1.32.10 [security] - autoclosed chore(deps): update module k8s.io/kubernetes to v1.32.10 [security] Apr 27, 2026
@renovate renovate Bot reopened this Apr 27, 2026
@renovate renovate Bot force-pushed the renovate/go-k8s.io-kubernetes-vulnerability branch 2 times, most recently from da155e0 to f1489a6 Compare April 27, 2026 22:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants