CVE-2025-5187
ADVISORY - githubSummary
A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection.
EPSS Score: 0.00029 (0.077)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Incorrect Authorization
ADVISORY - github
Incorrect Authorization
ADVISORY - gitlab
ADVISORY - redhat
Missing Authentication for Critical Function
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in