<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – KEDA (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/keda.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/keda-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – KEDA (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:03 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2025-68476 – KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68476</guid>
    <pubDate>Mon, 22 Dec 2025 22:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68476</strong></p>
  <p>KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to versions 2.17.3 and 2.18.3, an Arbitrary File Read vulnerability has been identified in KEDA, potentially affecting any KEDA resource that uses TriggerAuthentication to configure HashiCorp Vault authentication. The vulnerability stems from an incorrect or insufficient path validation when loading the Service Account Token spe…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68476">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
