CVE-2026-4810
A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.0a2) on Python (OSS), Cloud Run, and GKE allows an…
All CVEs associated with "Google Kubernetes Engine". Page 1/1 • 5 CVEs.
A curated feed of “Google Kubernetes Engine”-related CVEs appears below. We currently track 5 CVEs for this tag (all time). In the last 365 days, 2 were published. Average CVSS is 6.4 (all time; 7.4 over 365d), and 40% are rated High/Critical (all time). Top CWEs (last 365 days): CWE-306 - Missing Authentication for Critical Function, CWE-284 - Improper Access Control.
In our taxonomy this topic maps to a MODERATE impact class. Cloud and managed service CVEs involve shared responsibility. Check provider bulletins to confirm tenant actions, limit exposure, and rotate keys if advised. Use the filters below to sort by CVSS, risk and CWE. Each detail page highlights vendor advisories and mitigation tips.
This table shows recent release cycles and their projected end-of-life. Data source: endoflife.date.
| Cycle | Release | Latest | Premier Support | EOL | LTS |
|---|---|---|---|---|---|
| 1.35 | 1.35.5-gke.1057000 | ||||
| 1.34 | 1.34.8-gke.1126000 | Soon | |||
| 1.33 | 1.33.12-gke.1059000 | Soon | |||
| 1.32 | 1.32.13-gke.1592000 | Expired | |||
| 1.31 | 1.31.14-gke.1967000 | Expired | |||
| 1.30 | 1.30.14-gke.2558000 | Expired | |||
| 1.29 | 1.29.15-gke.2725000 | Expired | |||
| 1.28 | 1.28.15-gke.3290000 | Expired | |||
| 1.27 | 1.27.16-gke.2894000 | Expired | |||
| 1.26 | 1.26.15-gke.1469001 | Expired | |||
| 1.25 | 1.25.16-gke.1759000 | Expired | |||
| 1.24 | 1.24.17-gke.2472000 | Expired | |||
| 1.23 | 1.23.17-gke.10700 | Expired | |||
| 1.22 | 1.22.17-gke.14100 | Expired | |||
| 1.21 | 1.21.14-gke.18800 | Expired | |||
| 1.20 | 1.20.15-gke.13700 | Expired | |||
| 1.19 | 1.19.16-gke.15700 | Expired | |||
| 1.18 | 1.18.20-gke.6000 | Expired | |||
| 1.17 | 1.17.17-gke.9100 | Expired |
Maintained Soon (≤ 180 days) Expired
Subscribe lifecycle: RSS · RSS (expired) · ICS
Subscribe CVEs: RSS for “Google Kubernetes Engine” · RSS (High+Critical only)
CVEs tagged with this topic. Filters apply to the whole list (loaded from JSON).
A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.0a2) on Python (OSS), Cloud Run, and GKE allows an…
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.14, 1.18.8, and 1.19.2, Ingress Network Policies are not enforced for traffic from po…
Jenkins Google Kubernetes Engine Plugin 0.8.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.
A missing permission check in Jenkins Google Kubernetes Engine Plugin 0.7.0 and earlier allowed attackers with Overall/Read permission to obtain limited information about the scope of a credential wi…
Jenkins Google Kubernetes Engine Plugin 0.6.2 and earlier created a temporary file containing a temporary access token in the project workspace, where it could be accessed by users with Job/Read perm…