top of page
perceptive_background_267k.jpg

KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.11.0-alpha.1 until 1.11.0-alpha.4, the T…

Published:

28 augustus 2026 om 00:00:00

Alert date:

28 augustus 2026 om 23:18:32

Source:

nvd.nist.gov

Click to open the original link from this advisory

Cloud & Virtualization

CVE-2026-55108 affects KubeVela, an open source application delivery platform, across multiple versions prior to 1.9.14, 1.10.9, and 1.11.0-alpha.4. The vulnerability exists in the Terraform remote configuration loader within pkg/controller/utils/capability.go, specifically in the GetTerraformConfigurationFromRemote function. An attacker with permission to create or update ComponentDefinition objects can exploit symlink following behavior to point variables.tf to /dev/zero or similar unbounded streams. This causes os.Stat and os.ReadFile to read unlimited data before any parsing validation occurs, leading to memory exhaustion. The attack can OOM-kill the cluster-wide vela-core controller, cause repeated Pod restarts, and pressure node memory especially when no effective container limits are configured. Patches have been released in versions 1.9.14, 1.10.9, and 1.11.0-alpha.4.

Technical details

Mitigation steps:

Affected products:

KubeVela

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page