CVE-2026-55108
Last modified
CVE-2026-55108 is a high-severity vulnerability rated 8.5/10 on the CVSS scale. KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.11.0-alpha.1 until 1.11.0-alpha.4, the Terraform remote configuration loader in pkg/controller/utils/capability.go, GetTerraformConfigurationFromRemote, clones a repository supplied through a core.oam.dev/v1beta1 ComponentDefinition and follows repository-controlled variables.tf or main.tf symlinks. EPSS estimates a 0.57% chance of exploitation in the next 30 days.
Description
KubeVela is an open source application delivery platform. Prior to 1.9.14, from 1.10.0-alpha.1 until 1.10.9, and from 1.11.0-alpha.1 until 1.11.0-alpha.4, the Terraform remote configuration loader in pkg/controller/utils/capability.go, GetTerraformConfigurationFromRemote, clones a repository supplied through a core.oam.dev/v1beta1 ComponentDefinition and follows repository-controlled variables.tf or main.tf symlinks. A user with permission to create or update ComponentDefinition objects can point variables.tf to /dev/zero through terraform.path, after which os.Stat and os.ReadFile follow the link and read an unbounded stream before ParseTerraformVariables or HCL parsing can reject the content. The read can exhaust memory, OOM-kill the cluster-wide vela-core controller, cause repeated Pod restarts, and pressure node memory when no effective container limit is configured. This issue is fixed in versions 1.9.14, 1.10.9, and 1.11.0-alpha.4.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| kubevela | kubevela | < 1.9.14; >= 1.10.0-alpha.1, < 1.10.9; >= 1.11.0-alpha.1, < 1.11.0-alpha.4 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-55108?
How severe is CVE-2026-55108?
How do I fix CVE-2026-55108?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-55099icalendar is an RFC 5545 compatible parser and generator of …7.5
- CVE-2026-5510The GiveWP – Donation Plugin and Fundraising Platform plugin…6.4
- CVE-2026-55100hashi-vault-js is a Node.js module for interacting with the …8.7
- CVE-2026-55102hashi-vault-js is a Node.js module for interacting with the …5.8
- CVE-2026-55105Joplin is an open source note-taking and to-do application t…7.7
- CVE-2026-55106authentik is an open-source identity provider. Prior to 2026…5.3
- CVE-2026-5511In the web management interface of Archer AX72 (SG) v1, the …2.7
- CVE-2026-55110A malicious actor who lures an authenticated user to a malic…6.1
- CVE-2026-55111A malicious actor with access to the network could exploit a…7.5
- CVE-2026-55112A malicious actor with access to the network and low privile…8.8
- CVE-2026-55113A malicious actor with access to the network could exploit a…7.5
- CVE-2026-55114A malicious actor with access to the network and low privile…8.8
Are you affected by CVE-2026-55108?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
