{"schema_version":"1.7.3","id":"GHSA-4x4m-3c2p-qppc","published":"2025-08-27T18:31:55Z","modified":"2026-02-04T03:04:10.443325Z","aliases":["CVE-2025-5187","GO-2025-3915"],"related":["CGA-27qc-3f8h-hx6p"],"summary":"Kubernetes Nodes can delete themselves by adding an OwnerReference","details":"A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete their corresponding node object by patching themselves with an OwnerReference to a cluster-scoped resource. If the OwnerReference resource does not exist or is subsequently deleted, the given node object will be deleted via garbage collection.","affected":[{"package":{"name":"k8s.io/kubernetes","ecosystem":"Go","purl":"pkg:golang/k8s.io/kubernetes"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.31.12"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-4x4m-3c2p-qppc/GHSA-4x4m-3c2p-qppc.json"}},{"package":{"name":"k8s.io/kubernetes","ecosystem":"Go","purl":"pkg:golang/k8s.io/kubernetes"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.32.0-alpha.0"},{"fixed":"1.32.8"}]}],"database_specific":{"last_known_affected_version_range":"< 1.32.7","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-4x4m-3c2p-qppc/GHSA-4x4m-3c2p-qppc.json"}},{"package":{"name":"k8s.io/kubernetes","ecosystem":"Go","purl":"pkg:golang/k8s.io/kubernetes"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.33.0-alpha.0"},{"fixed":"1.33.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-4x4m-3c2p-qppc/GHSA-4x4m-3c2p-qppc.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-5187"},{"type":"WEB","url":"https://github.com/kubernetes/kubernetes/issues/133471"},{"type":"WEB","url":"https://github.com/kubernetes/kubernetes/commit/a2d98cac56a0c5cb2d8abc4d087fc00846b3bc0f"},{"type":"PACKAGE","url":"https://github.com/kubernetes/kubernetes"},{"type":"WEB","url":"https://groups.google.com/g/kubernetes-security-announce/c/znSNY7XCztE"}],"database_specific":{"cwe_ids":["CWE-863"],"github_reviewed":true,"github_reviewed_at":"2025-08-27T19:20:29Z","nvd_published_at":"2025-08-27T17:15:48Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L"}]}