Skip to content
major vulnerability· requires attention

Unauthenticated libvirt RPC exposure across tenants via TLS-disabled migration listener; enables VM memory reads, state changes, or destruction.

Cloud

CVE-2026-13325

8.5
High
EPSS n/aJun 26, 2026

KubeVirt TLS-disabled migration listener exposes unauthenticated RPC to all tenants.

This CVE has been withdrawn. NVD marks this identifier as Rejected, which means it was a duplicate or turned out not to be a vulnerability. The analysis below is kept for reference only — do not act on it.

executive summary
technical analysis
affected
KubeVirt
impact

Cluster pod can reach 0.0.0.0 listener and issue libvirt RPC to other tenants’ VMs: read memory, modify state, or destroy VMs.

action required

Patch when possible

how to fix
Remediation steps are tailored for users whose stack is affected. Add this technology to your stack to see the fix checklist.
references
get alerted

Track only the vulnerabilities that affect your infrastructure.

start for free