Vulnerability Report: GO-2025-3774
- CVE-2025-4563, GHSA-hj2p-8wj8-pfq4
- Affects: k8s.io/kubernetes
- Published: Jul 28, 2025
- Modified: Aug 06, 2025
Kubernetes allows nodes to bypass dynamic resource allocation authorization checks in k8s.io/kubernetes
For detailed information about this vulnerability, visit https://github.com/advisories/GHSA-hj2p-8wj8-pfq4.
Affected Modules
-
PathGo Versions
-
from v1.32.0 before v1.32.6, from v1.33.0 before v1.33.2
Aliases
References
- https://github.com/advisories/GHSA-hj2p-8wj8-pfq4
- https://github.com/kubernetes/kubernetes/issues/132151
- https://github.com/kubernetes/kubernetes/pull/131844
- https://github.com/kubernetes/kubernetes/pull/131875
- https://github.com/kubernetes/kubernetes/pull/131876
- https://groups.google.com/g/kubernetes-security-announce/c/Zv84LMRuvMQ
- https://vuln.go.dev/ID/GO-2025-3774.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.