Vulnerability record · CVE-2019-1002100 · published 1 April 2019
CVE-2019-1002100: Kubernetes allocation without limits vulnerability
Kubernetes · Kubernetes
In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patch --type json` or `"Content-Type: application/json-patch+json"`) that consumes excessive resources while processing, causing a Denial of Service on the API Server.
Description
In all Kubernetes versions prior to v1.11.8, v1.12.6, and v1.13.4, users that are authorized to make patch requests to the Kubernetes API Server can send a specially crafted patch of type "json-patch" (e.g. `kubectl patch --type json` or `"Content-Type: application/json-patch+json"`) that consumes excessive resources while processing, causing a Denial of Service on the API Server.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/107290 | Broken LinkThird Party AdvisoryVDB Entry |
| https://access.redhat.com/errata/RHSA-2019:1851 | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2019:3239 | Third Party Advisory |
| https://github.com/kubernetes/kubernetes/issues/74534 | Issue TrackingVendor Advisory |
| https://groups.google.com/forum/#%21topic/kubernetes-announce/vmUUNkYfG9g | |
| https://security.netapp.com/advisory/ntap-20190416-0002/ | Third Party Advisory |
| http://www.securityfocus.com/bid/107290 | Broken LinkThird Party AdvisoryVDB Entry |
| https://access.redhat.com/errata/RHSA-2019:1851 | Third Party Advisory |
| https://access.redhat.com/errata/RHSA-2019:3239 | Third Party Advisory |
| https://github.com/kubernetes/kubernetes/issues/74534 | Issue TrackingVendor Advisory |
| https://groups.google.com/forum/#%21topic/kubernetes-announce/vmUUNkYfG9g | |
| https://security.netapp.com/advisory/ntap-20190416-0002/ | Third Party Advisory |
Track CVE-2019-1002100 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-1002100), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.