logo

Unpatchable Vulnerabilities of Kubernetes: CVE-2020-8562

ID: 188c39ac-531e-5532-8bd6-b433a96ddef0

STIX ID: report--188c39ac-531e-5532-8bd6-b433a96ddef0

Feed Name: Datadog Security Labs

Threat Score
50/100

Date Published: 2026-04-09

Date Updated: 2026-04-27

...
...

This report analyzes CVE-2020-8562, an unpatchable Kubernetes vulnerability where the API server proxy performs multiple DNS resolutions allowing an attacker to exploit a TOCTOU/DNS rebinding race and bypass private-IP filters (e.g., reach 127.0.0.1 or cloud metadata services). The write-up includes exploitation prerequisites (ability to create Node objects and use the proxy), a proof-of-concept attack, risk context (especially for managed Kubernetes control planes), and suggested mitigations such as enforcing DNS TTL minimums or using Konnectivity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.