返回列表

CVE-2019-11253: Kubernetes API Server - YAML Parsing DoS (Billion Laughs)

PoC
2026-01-08

影响软件

Kubernetes API Server

关联产品

漏洞描述

The Kubernetes API server is vulnerable to a denial of service attack via YAML/JSON parsing. An attacker can send a specially crafted YAML/JSON payload that causes exponential memory consumption (Billion Laughs attack), leading to API server crash.

PoC / 利用代码

登录后可查看 PoC 内容

查看原文