logo

Unpatchable Vulnerabilities of Kubernetes: CVE-2021-25740

ID: b83c31cc-1642-56e6-af1c-32792016518f

STIX ID: report--b83c31cc-1642-56e6-af1c-32792016518f

Feed Name: Datadog Security Labs

Threat Score
50/100

Date Published: 2026-05-21

Date Updated: 2026-05-21

...
...

This post examines CVE-2021-25740, an "unpatchable" Kubernetes vulnerability that allows an attacker with permission to edit Endpoint/EndpointSlice objects to redirect shared ingress or LoadBalancer traffic to other tenants' pods, potentially bypassing network policies; the article explains how Services and EndpointSlices work, demonstrates the attack scenario in multi-tenant clusters, and recommends mitigations such as removing EndpointSlice edit privileges, avoiding shared load balancers/ingress, or migrating to the Gateway API and notes a proof-of-concept is available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.