Intel

AIKIDO-2025-10995

github.com/kube-vip/kube-vip is vulnerable to Improper Access Control

Improper Access Control Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Dec 29, 2025

72

High Risk

This Affects:

GOgithub.com/kube-vip/kube-vip
1.0.0 - 1.0.2
Fixed in 1.0.3
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to a Service Port Security Bypass, where the --onlyAllowTrafficServicePorts flag and enable_service_security setting fail to apply intended port restriction rules, allowing an attacker who can route traffic to a load balancer IP (e.g., via BGP with kube-vip) to access sensitive Kubernetes API ports (like 6443 and 10250) that should be blocked, thereby exposing the cluster's control plane and node endpoints.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

github.com/kube-vip/kube-vip is vulnerable to Improper Access Control in versions 1.0.0 - 1.0.2.

How to fix this

Upgrade the github.com/kube-vip/kube-vip library to the patch version.