logo

Unpatchable Vulnerabilities of Kubernetes: CVE-2020-8554

ID: b0a6a2e5-1f72-5df1-862e-932ce31c3b97

STIX ID: report--b0a6a2e5-1f72-5df1-862e-932ce31c3b97

Feed Name: Datadog Security Labs

Threat Score
40/100

Date Published: 2026-01-14

Date Updated: 2026-04-27

...
...

This blog describes CVE-2020-8554, an “unpatchable” Kubernetes vulnerability where creating Service objects with ExternalIP entries causes kube-proxy to add iptables rules that can redirect external traffic to attacker-controlled pods. The post walks through how kube-proxy manipulates iptables, shows a PoC Service manifest and resulting iptables chains, and recommends mitigations including DenyServiceExternalIPs admission controller, policy controllers (e.g., Kyverno), GitOps checks, or using Cilium's kube-proxy replacement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.