major vulnerability· requires attention
Unauthenticated libvirt RPC exposure across tenants via TLS-disabled migration listener; enables VM memory reads, state changes, or destruction.
Cloud
CVE-2026-13325
8.5
High
EPSS n/aJun 26, 2026
KubeVirt TLS-disabled migration listener exposes unauthenticated RPC to all tenants.
This CVE has been withdrawn. NVD marks this identifier as Rejected, which means it was a duplicate or turned out not to be a vulnerability. The analysis below is kept for reference only — do not act on it.
executive summary
technical analysis
affected
KubeVirt
impact
Cluster pod can reach 0.0.0.0 listener and issue libvirt RPC to other tenants’ VMs: read memory, modify state, or destroy VMs.
action required
Patch when possible
how to fix
Remediation steps are tailored for users whose stack is affected. Add this technology to your stack to see the fix checklist.
references