Security Advisory

CVE-2025-13281

5.8
MEDIUM

Vulnerability Description

A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback services).
Published Date December 14, 2025
Official Source NIST NVD Advisory