CVE-2021-25735
Validating Admission Webhook does not observe some previous fields
- Published
- Sep 6, 2021
- Updated
- Sep 16, 2024
- Assigning CNA
- kubernetes
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:HLow · next 30 days
- Percentile
- 92.5%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
A security issue was discovered in kube-apiserver that could allow node updates to bypass a Validating Admission Webhook. Clusters are only affected by this vulnerability if they run a Validating Admission Webhook for Nodes that denies admission based at least partially on the old state of the Node object. Validating Admission Webhook does not observe some previous fields.
Sources
1- CVE-2021-25735Exploit
Exploit for CVE-2021-25735 demonstrating Kubernetes Validating Admission Webhook bypass via node label manipulation, with deployable Docker container and webhook registration scripts.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.