Vulnerability Description
KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cluster custom resource's connection configuration and immediately calls Discovery().ServerVersion() against the CRD-specified Kubernetes API endpoint, which is parsed only for URL syntax (url.Parse) with no allow/deny-list for loopback, RFC1918 private ranges, link-local, or cloud-metadata addresses (e.g. 169.254.169.254). A user able to create or update a Cluster CRD can force the controller-manager and apiserver pods to issue outbound requests to arbitrary internal or metadata endpoints.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/ashikmd7/kubeSphere/blob/main/SSRF%20via%20Cluster%20CRD%20Ku
- https://github.com/kubesphere/kubesphere
FAQ
What is CVE-2026-71208?
CVE-2026-71208 is a vulnerability with a CVSS score of 6.5 (MEDIUM). KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cluster custom resource's connection configuration and immediately calls Discovery...
How severe is CVE-2026-71208?
CVE-2026-71208 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-71208?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.