Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v8j7-hp7c-738f | Kubetail has a Cross-Site WebSocket Hijacking issue that allows attacker to read Kubernetes logs from authenticated users |
Sun, 17 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kubetail-org
Kubetail-org cli Kubetail-org dashboard Kubetail-org kubetail |
|
| Vendors & Products |
Kubetail-org
Kubetail-org cli Kubetail-org dashboard Kubetail-org kubetail |
Sat, 16 May 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 14 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kubetail is a real-time logging dashboard for Kubernetes. Prior to 0.14.0, Kubetail's dashboard exposes WebSocket endpoints that did not adequately validate the Origin header on connection upgrade. A malicious web page visited by a user with an active Kubetail session could open a WebSocket to the user's dashboard and read their Kubernetes logs in real time. This is a Cross-Site WebSocket Hijacking (CSWSH) vulnerability and affects both the desktop deployment (default http://localhost:7500) and cluster deployments (typically behind an Ingress with HTTP basic auth). This vulnerability is fixed in 0.14.0. | |
| Title | Kubetail: Cross-Site WebSocket Hijacking allows attacker to read Kubernetes logs from authenticated users | |
| Weaknesses | CWE-1385 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-16T00:39:44.628Z
Reserved: 2026-05-06T18:28:20.887Z
Link: CVE-2026-44514
Updated: 2026-05-16T00:39:39.075Z
Status : Deferred
Published: 2026-05-14T17:16:23.043
Modified: 2026-06-17T10:50:44.773
Link: CVE-2026-44514
No data.
OpenCVE Enrichment
Updated: 2026-05-17T17:09:11Z
Github GHSA