If you run Kubernetes and haven’t yet stopped everything else you’re doing and paid attention, now is the time.
CVE-2025-1974 ain’t messing around, folks. There’s a reason this was scored CVSS 9.8.

In the default Kubernetes installation, the controller can access all Secrets cluster-wide.

What are you doing still reading this? If you’re affected, go patch your clusters!

Comments