<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Google Kubernetes Engine</title>
  <link>https://cvedaily.com/pages/tags/google-kubernetes-engine.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/google-kubernetes-engine.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Google Kubernetes Engine</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:56 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2026-4810 – A Code Injection and Missing Authentication vulnerability in Google Agent Develo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4810</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4810</guid>
    <pubDate>Mon, 13 Apr 2026 09:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-4810</strong></p>
  <p>A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.0a2) on Python (OSS), Cloud Run, and GKE allows an unauthenticated remote attacker to execute arbitrary code on the server hosting the ADK instance.  This vulnerability was patched in versions 1.28.1 and 2.0.0a2.   Customers need to redeploy the upgr…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4810">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33726 – Cilium is a networking, observability, and security solution with an eBPF-based ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33726</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33726</guid>
    <pubDate>Fri, 27 Mar 2026 01:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33726</strong></p>
  <p>Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.14, 1.18.8, and 1.19.2, Ingress Network Policies are not enforced for traffic from pods to L7 Services (Envoy, GAMMA) with a local backend on the same node, when Per-Endpoint Routing is enabled and BPF Host Routing is disabled. Per-Endpoint Routing is disabled by default, but is autom…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33726">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-2121 – Jenkins Google Kubernetes Engine Plugin 0.8.0 and earlier does not configure its...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-2121</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-2121</guid>
    <pubDate>Wed, 12 Feb 2020 15:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-2121</strong></p>
  <p>Jenkins Google Kubernetes Engine Plugin 0.8.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-2121">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-10445 – A missing permission check in Jenkins Google Kubernetes Engine Plugin 0.7.0 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10445</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10445</guid>
    <pubDate>Wed, 16 Oct 2019 14:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-10445</strong></p>
  <p>A missing permission check in Jenkins Google Kubernetes Engine Plugin 0.7.0 and earlier allowed attackers with Overall/Read permission to obtain limited information about the scope of a credential with an attacker-specified credentials ID.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10445">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-10365 – Jenkins Google Kubernetes Engine Plugin 0.6.2 and earlier created a temporary fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-10365</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-10365</guid>
    <pubDate>Wed, 31 Jul 2019 13:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-10365</strong></p>
  <p>Jenkins Google Kubernetes Engine Plugin 0.6.2 and earlier created a temporary file containing a temporary access token in the project workspace, where it could be accessed by users with Job/Read permission.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-10365">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
