Vulnerability record · CVE-2026-24005 · published 25 February 2026
CVE-2026-24005: Openkruise kruise server-side request forgery (ssrf) vulnerability
Openkruise · Kruise
Kruise provides automated management of large-scale applications on Kubernetes. Prior to versions 1.8.3 and 1.7.5, PodProbeMarker allows defining custom probes with TCPSocket or HTTPGet handlers. The webhook validation does not restrict the Host field in these probe configurations. Since kruise-daemon runs with hostNetwork=true, it executes probes from the node network namespace. An attacker with PodProbeMarker creation permission can specify arbitrary Host values to trigger SSRF from the node, perform port scanning, and receive response feedback through NodePodProbe status messages. Versions 1.8.3 and 1.7.5 patch the issue.
Description
Kruise provides automated management of large-scale applications on Kubernetes. Prior to versions 1.8.3 and 1.7.5, PodProbeMarker allows defining custom probes with TCPSocket or HTTPGet handlers. The webhook validation does not restrict the Host field in these probe configurations. Since kruise-daemon runs with hostNetwork=true, it executes probes from the node network namespace. An attacker with PodProbeMarker creation permission can specify arbitrary Host values to trigger SSRF from the node, perform port scanning, and receive response feedback through NodePodProbe status messages. Versions 1.8.3 and 1.7.5 patch the issue.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/openkruise/kruise/commit/94364b76adf3e8a1749a31afe809a163bed29613 | Patch |
| https://github.com/openkruise/kruise/releases/tag/v1.7.5 | ProductRelease Notes |
| https://github.com/openkruise/kruise/releases/tag/v1.8.3 | ProductRelease Notes |
| https://github.com/openkruise/kruise/security/advisories/GHSA-9fj4-3849-rv9g | ExploitMitigationVendor Advisory |
Track CVE-2026-24005 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-24005), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.