GPU VulnDB

Database/Container, Kubernetes & orchestration

KubeVirt: virt-handler notify server derives VMI identity from the request body without validating the connection

CVE-2026-13208Container, Kubernetes & orchestrationcurated

Impact

virt-handler notify server derives VMI identity from the request body without validating the connection; cross-VM event spoofing

Who can reach it

An attacker with virt-launcher access

What to do

Upgrade KubeVirt

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.