CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-54247

mediumCVSS 4.3covered by 1 sourcefirst seen 2026-07-17
Summary The Kubernetes admission webhook handler reads the entire request body using io.ReadAll(r.Body) without any size limit. Any client that can reach the webhook port within the cluster can send a multi-GB payload, causing the skipper process to exhaust memory and be OOM-killed. This disrupts all Kubernetes admission control, potentially blocking all pod creation and updates. Vulnerable Code // dataclients/kubernetes/admission/admission.go:76 body, err := io.ReadAll(r.Body) // <-- NO SIZE LIMIT if err != nil { log.Errorf("Failed to read request: %v", err) w.WriteHeader(http.StatusInternalServerError) invalidRequests.WithLabelValues(admitterName).Inc() return } var review admissionReview err = json.Unmarshal(body, &review) For comparison, the OPA filter has a body size limit: // filters/openpolicyagent/openpolicyagent.go:68-70 const DefaultMaxRequestBodySize = 1 << 20 // 1MB // OPA uses a bufferedBodyReader with size limits Attack Path 1. Attacker identifies the admission webhook endpoint (default: :9443/admission or configured path) 2. Attacker sends: POST /admission HTTP/1.1, Content-Type: application/json with a multi-GB request body 3. io.ReadAll(r.Body) allocates unbounded memory for the entire body 4. Skipper process is OOM-killed by the Kubernetes kubelet Permission Boundary Analysis - Attacker: Any client with network access to the admission webhook port within the Kubernetes cluster - Boundary crossed: Memory safety — unbounded allocation from attacker-controlled input - Preconditions: Admission webhook endpoint must be network-reachable (default Kubernetes deployment exposes it within cluster network) - Comparison: OPA filter has DefaultMaxRequestBodySize (1MB) and semaphore-based memory limit; admission handler has neither Evidence | File | Lines | Description | |------|-------|-------------| | dataclients/kubernetes/admission/admission.go | 76 | io.ReadAll(r.Body) without size limit | | filters/openpolicyagent/openpolicyagent.go | 68-70 |

⚡ Watch CVE-2026-54247

Get an email if CVE-2026-54247 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-54247

CVE.org record

Embed the live status

CVE-2026-54247 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-54247 status](https://www.csirts.com/badge/CVE-2026-54247)](https://www.csirts.com/cve/CVE-2026-54247)