Kubernetes fixes CVE-2026-2270: StatefulSet controller could create pods in other namespaces
On September 23 Kubernetes shipped patches for CVE-2026-2270, a confused deputy bug in the StatefulSet controller. A user with write access to StatefulSets and ControllerRevisions in one namespace could make the cluster create a pod in another namespace. The fix restores only the spec field from ControllerRevisions.
- Patched versions released September 23: v1.34.12, v1.35.9, v1.36.5 and v1.37.1
- The vulnerability has a CVSS score of 5.9 (medium)
- Keeping the pod alive required the UID of a real StatefulSet in the victim namespace
- No confirmed exploitation has been reported
Read next
Security