This document describes security bulletins for Google Kubernetes Engine (GKE).
For dates prior to June 1, 2026, this document also describes security bulletins for Distributed Cloud (software only) for VMware and bare metal, and for GKE on AWS and GKE on Azure. To view more recent security bulletins and vulnerability fixes for these products, see the following documents:
Vulnerabilities are often kept secret under embargo until affected parties have had a chance to address them. In these cases, the release notes refer to "security updates" until the embargo is lifted. After the embargo ends, the release notes are updated to reflect the vulnerability the patch addressed.
When GKE issues a security bulletin that directly correlates to
your cluster configuration or version, we might send you a
SecurityBulletinEvent cluster notification
that provides information about the vulnerability and actions that you can take,
if applicable.
GKE platforms don't use components such as ingress-nginx and
the CRI-O container runtime, and are unaffected by any vulnerabilities in those
components. If you install components from other sources, refer to the security
updates and patching advice of those components at the source. For example,
starting in March 2026,
Ingress NGINX is retired.
If you use Ingress NGINX, you should migrate to an alternative system as soon
as possible.
For more information on how Google manages security vulnerabilities and patches for GKE, see Security patching.
Use this XML feed to subscribe to security bulletins for this page.
GCP-2026-061
Published: 2026-09-09
Reference:
GHSA-p7v4-vr35-mj6f
| Description | Severity |
|---|---|
|
A security vulnerability GHSA-p7v4-vr35-mj6f (CVE assignment pending) in containerd's CRI implementation allows a container restored from an untrusted checkpoint through the GKE clusters are not vulnerable by default. GKE node images do not include the Additionally, Pod snapshots in GKE do not exercise the vulnerable implicit restore codepath. In updated containerd versions (2.3.4 and later, or 2.2.7 and later), implicit restore is disabled by default through the What should I do?Because GKE does not include the If you install custom runtime software or node tools on your nodes that include the
|
Medium |
GCP-2026-058
Published: 2026-09-02
| Description | Severity |
|---|---|
|
A missing project permission check in GKE Multi-Cloud
We have verified that there was no exploitation of this vulnerability. This issue was reported through our Vulnerability Reward Program. What should I do?All GKE clusters were patched by adding the missing authorization check to the server. No action is required. |
Critical |
GCP-2026-037
Published: 2026-06-18
Updated: 2026-06-20
Reference: CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, CVE-2026-47262
2026-06-20 Update: Added GKE patch versions containing the fixes for Container-Optimized OS node images for minor versions 1.35 and 1.36. Patches for Ubuntu node images are still pending and in progress.
2026-06-19 Update: Added GKE patch versions containing the fixes for Container-Optimized OS node images for minor versions from 1.30 to 1.34. Patches for Ubuntu node images and for minor version 1.35 and 1.36 for Container-Optimized OS node images are in progress.
| Description | Severity |
|---|---|
|
The following vulnerabilities have been discovered in containerd (the GKE container runtime). These vulnerabilities allow attackers with permissions to create Pods to bypass Kubernetes security boundaries and perform host compromise, cache poisoning, and denial of service. While these vulnerabilities are critical in the context of containerd, the requirement to have cluster privileges to create Pods to exploit them means they are considered High according to GKE vulnerability classification.
These vulnerabilities affect all GKE configurations using Container-Optimized OS and Ubuntu node images, including GKE Standard and GKE Autopilot clusters. What should I do?2026-06-20 Update: The following GKE patch versions contain the fixes for Container-Optimized OS node images for minor versions from 1.30 to 1.36. Upgrade your Container-Optimized OS node pools to the following versions or later:
Patches for Ubuntu node images are in progress. Until patch versions are available, use the following mitigation guidelines:
|
High |
GCP-2026-033
Published: 2026-05-14
Updated: 2026-07-16
Reference:
CVE-2026-46300
2026-07-16 Update: The following versions of GKE are updated with code to fix this vulnerability on Ubuntu. Upgrade your Ubuntu node pools to the following versions or later:
- 1.30.14-gke.2710000
- 1.31.14-gke.2116000
- 1.32.13-gke.1829000
- 1.33.13-gke.1011000
- 1.34.9-gke.1131000
- 1.35.6-gke.1127000
- 1.36.2-gke.1346000
GKE
Updated: 2026-07-16
| Description | Severity |
|---|---|
|
A container breakout vulnerability CVE-2026-46300 has been found in the Linux kernel, known as Fragnesia. It allows an unprivileged local attacker to escalate to root on the host. GKE Standard clusters with Ubuntu nodes are impacted. GKE Standard clusters with Container-Optimized OS nodes are not impacted. GKE Autopilot is not impacted. Clusters using GKE Sandbox aren't impacted. What should I do?Upstream kernel patches have only recently been released. Those patches are being built into GKE releases and this bulletin will be updated when they are available. In the interim, partial mitigations are available below. Containers do not provide a robust security boundary, as container breakout vulnerabilities pose a significant risk. For secure workload isolation, we recommend using GKE Sandbox. If possible, migrate your workloads to run as non-root. If your container needs to be root, consider setting the |
Medium |
GDC (VMware)
Updated: 2026-07-16
| Description | Severity |
|---|---|
|
A container breakout vulnerability CVE-2026-46300 has been found in the Linux kernel, known as Fragnesia. It allows an unprivileged local attacker to escalate to root on the host. What should I do? |
Medium |
GKE on AWS
Updated: 2026-07-16
| Description | Severity |
|---|---|
|
A container breakout vulnerability CVE-2026-46300 has been found in the Linux kernel, known as Fragnesia. It allows an unprivileged local attacker to escalate to root on the host. What should I do? |
Medium |
GKE on Azure
Updated: 2026-07-16
| Description | Severity |
|---|---|
|
A container breakout vulnerability CVE-2026-46300 has been found in the Linux kernel, known as Fragnesia. It allows an unprivileged local attacker to escalate to root on the host. What should I do? |
Medium |
GDC (bare metal)
Updated: 2026-07-16
| Description | Severity |
|---|---|
|
A container breakout vulnerability CVE-2026-46300 has been found in the Linux kernel, known as Fragnesia. It allows an unprivileged local attacker to escalate to root on the host. What should I do? |
Medium |
GCP-2026-030
Published: 2026-05-11
Updated: 2026-06-24
Reference:
CVE-2026-43284, CVE-2026-43500
2026-06-24 Update: Added patch versions for GKE.
2026-05-20 Update: Added CVE-2026-43500 and added CVE IDs to exploit paths.
GKE
Updated: 2026-06-24
| Description | Severity |
|---|---|
|
Container breakout vulnerabilities CVE-2026-43284 and CVE-2026-43500 have been found in the Linux kernel, known as DirtyFrag. They allow an unprivileged local attacker to escalate to root on the host. There are two exploit paths. rxrpc exploit path (CVE-2026-43500): Container-Optimized OS is not vulnerable because the vulnerable module is not compiled in. Ubuntu nodes are vulnerable. esp4 exploit path (CVE-2026-43284): Both Container-Optimized OS and Ubuntu are vulnerable, but the GKE default seccomp profile provides a mitigation that protects all Autopilot clusters and Standard clusters with Autopilot-managed node pools. The esp4 exploit path requires the user to have the ability to make the unshare syscall to obtain CAP_NET_ADMIN. Containers that use the Containers using GKE Sandbox are not impacted. What should I do?2026-06-24 Update: The following versions of GKE are updated with code to fix this vulnerability on Container-Optimized OS. Upgrade your Container-Optimized OS node pools to the following versions or later:
Upstream kernel patches have only recently been released. Those patches are being built into GKE releases and this bulletin will be updated when they are available. In the interim, partial mitigations are available below. We do not recommend relying on containers as a security boundary, container breakout vulnerabilities are very common. Use GKE Sandbox instead. If possible, migrate your workloads to run as non-root. If your container needs to be root, consider setting the |
Medium |
GDC (VMware)
Updated: 2026-05-20
| Description | Severity |
|---|---|
|
Container breakout vulnerabilities CVE-2026-43284 and CVE-2026-43500 have been found in the Linux kernel, known as DirtyFrag. They allow an unprivileged local attacker to escalate to root on the host. What should I do? |
Pending |
GKE on AWS
Updated: 2026-05-20
| Description | Severity |
|---|---|
|
Container breakout vulnerabilities CVE-2026-43284 and CVE-2026-43500 have been found in the Linux kernel, known as DirtyFrag. They allow an unprivileged local attacker to escalate to root on the host. What should I do? |
Pending |
GKE on Azure
Updated: 2026-05-20
| Description | Severity |
|---|---|
|
Container breakout vulnerabilities CVE-2026-43284 and CVE-2026-43500 have been found in the Linux kernel, known as DirtyFrag. They allow an unprivileged local attacker to escalate to root on the host. What should I do? |
Pending |
GDC (bare metal)
Updated: 2026-05-20
| Description | Severity |
|---|---|
|
Container breakout vulnerabilities CVE-22026-43284 and CVE-2026-43500 have been found in the Linux kernel, known as DirtyFrag. They allow an unprivileged local attacker to escalate to root on the host. What should I do?There is no action required. GDC software for bare metal isn't affected as it does not bundle an operating system in its distribution. |
None |
GCP-2026-027
Published: 2026-05-01
Reference:
CVE-2026-23351
GKE
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
GKE Standard clusters are impacted. GKE Autopilot clusters in the default configuration are not impacted, but might be vulnerable if you explicitly set the seccomp Clusters using GKE Sandbox aren't impacted. What should I do?The following minor versions are affected. Upgrade your Container-Optimized OS node pools to one of the following patch versions or later:
You can apply patch versions from newer release channels if your cluster runs the same minor version in its own release channel. This feature lets you secure your nodes until the patch version becomes the default in your release channel. For details, see Run patch versions from a newer channel. |
High |
GDC (VMware)
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
What should I do? |
Pending |
GKE on AWS
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
What should I do? |
Pending |
GKE on Azure
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
What should I do? |
Pending |
GDC (bare metal)
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
What should I do?There is no action required. GDC software for bare metal isn't affected as it does not bundle an operating system in its distribution. |
None |
GCP-2026-026
Published: 2026-04-30
Updated: 2026-05-04
Reference:
CVE-2026-31431
2026-05-04 Update: Added patch versions for GKE.
GKE
Updated: 2026-05-04
| Description | Severity |
|---|---|
|
A vulnerability in the Linux kernel (CVE-2026-31431) allows an unprivileged local attacker to write to the system page cache, potentially leading to local privilege escalation and container escape. GKE Standard and Autopilot clusters are affected. Containers using GKE Sandbox are not impacted. What should I do?2026-05-04 Update: The following versions of GKE are updated with code to fix this vulnerability on Container-Optimized OS. Upgrade your Container-Optimized OS node pools to the following versions or later:
If you don't see these versions in the Google Cloud console, then use the
Upstream kernel patches have only recently been released. Those patches are being built into GKE releases and this bulletin will be updated when they are available. In the interim, mitigations are available below. We do not recommend relying on containers as a security boundary, container breakout vulnerabilities are very common. Use GKE Sandbox instead. For immediate protection, mitigation advice here. What vulnerabilities are being addressed?The vulnerability, CVE-2026-31431, is a logic flaw in the Linux kernel's |
High |
GDC (VMware)
| Description | Severity |
|---|---|
|
A vulnerability in the Linux kernel (CVE-2026-31431) allows an unprivileged local attacker to write to the system page cache, potentially leading to local privilege escalation and container escape. What should I do?Upstream kernel patches have only recently been released. Those patches are being built into GKE releases and this bulletin will be updated when they are available. In the interim, mitigations are available below. We do not recommend relying on containers as a security boundary, container breakout vulnerabilities are very common. Use GKE Sandbox instead. For immediate protection, mitigation advice here. What vulnerabilities are being addressed?The vulnerability, CVE-2026-31431, is a logic flaw in the Linux kernel's |
High |
GKE on AWS
| Description | Severity |
|---|---|
|
A vulnerability in the Linux kernel (CVE-2026-31431) allows an unprivileged local attacker to write to the system page cache, potentially leading to local privilege escalation and container escape. What should I do?Upstream kernel patches have only recently been released. Those patches are being built into GKE releases and this bulletin will be updated when they are available. In the interim, mitigations are available below. We do not recommend relying on containers as a security boundary, container breakout vulnerabilities are very common. Use GKE Sandbox instead. For immediate protection, mitigation advice here. What vulnerabilities are being addressed?The vulnerability, CVE-2026-31431, is a logic flaw in the Linux kernel's |
High |
GKE on Azure
| Description | Severity |
|---|---|
|
A vulnerability in the Linux kernel (CVE-2026-31431) allows an unprivileged local attacker to write to the system page cache, potentially leading to local privilege escalation and container escape. What should I do?Upstream kernel patches have only recently been released. Those patches are being built into GKE releases and this bulletin will be updated when they are available. In the interim, mitigations are available below. We do not recommend relying on containers as a security boundary, container breakout vulnerabilities are very common. Use GKE Sandbox instead. For immediate protection, mitigation advice here. What vulnerabilities are being addressed?The vulnerability, CVE-2026-31431, is a logic flaw in the Linux kernel's |
High |
GDC (bare metal)
| Description | Severity |
|---|---|
|
A vulnerability in the Linux kernel (CVE-2026-31431) allows an unprivileged local attacker to write to the system page cache, potentially leading to local privilege escalation and container escape. What should I do?GDC software for bare metal does not bundle an operating system in its distribution. Customers are responsible for installing and maintaining a supported Linux distribution on physical hardware. To protect your cluster, check with your OS vendor to see if your underlying Linux distribution is affected, and apply the appropriate kernel updates. As an immediate mitigation, mitigation advice here. What vulnerabilities are being addressed?The vulnerability, CVE-2026-31431, is a logic flaw in the Linux kernel's |
High |
GCP-2026-025
Published: 2026-04-30
Reference:
CVE-2026-23274
GKE
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
GKE Standard clusters are impacted. GKE Autopilot clusters in the default configuration are not impacted, but might be vulnerable if you explicitly set the seccomp Clusters using GKE Sandbox aren't impacted. What should I do?The following minor versions are affected. Upgrade your Container-Optimized OS node pools to one of the following patch versions or later:
You can apply patch versions from newer release channels if your cluster runs the same minor version in its own release channel. This feature lets you secure your nodes until the patch version becomes the default in your release channel. For details, see Run patch versions from a newer channel. |
High |
GDC (VMware)
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
What should I do? |
Pending |
GKE on AWS
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
What should I do? |
Pending |
GKE on Azure
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
What should I do? |
Pending |
GDC (bare metal)
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
What should I do?There is no action required. GDC software for bare metal isn't affected as it does not bundle an operating system in its distribution. |
None |
GCP-2026-024
Published: 2026-04-28
Reference:
CVE-2025-38248
GKE
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes:
GKE Standard clusters are impacted. GKE Autopilot clusters in the default configuration are not impacted, but might be vulnerable if you explicitly set the seccomp Clusters using GKE Sandbox aren't impacted. What should I do?The following minor versions are affected. Upgrade your Container-Optimized OS node pools to one of the following patch versions or later:
The following minor versions are affected. Upgrade your Ubuntu node pools to one of the following patch versions or later:
You can apply patch versions from newer release channels if your cluster runs the same minor version in its own release channel. This feature lets you secure your nodes until the patch version becomes the default in your release channel. For details, see Run patch versions from a newer channel. |
High |
GDC (VMware)
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes:
What should I do? |
Pending |
GKE on AWS
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes:
What should I do? |
Pending |
GKE on Azure
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes:
What should I do? |
Pending |
GDC (bare metal)
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS and Ubuntu nodes:
What should I do?There is no action required. GDC software for bare metal isn't affected as it does not bundle an operating system in its distribution. |
None |
GCP-2026-023
Published: 2026-04-28
Updated: 2026-05-07
Reference:
CVE-2026-23074
2026-05-07 Update: Added patch versions for Ubuntu node pools on GKE.
GKE
Updated: 2026-05-07
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
GKE Standard clusters are impacted. GKE Autopilot clusters in the default configuration are not impacted, but might be vulnerable if you explicitly set the seccomp Clusters using GKE Sandbox aren't impacted. What should I do?2026-05-07 Update: The following versions of GKE are updated with code to fix this vulnerability on Ubuntu. Upgrade your Ubuntu node pools to the following versions or later:
The following minor versions are affected. Upgrade your Container-Optimized OS node pools to one of the following patch versions or later:
You can apply patch versions from newer release channels if your cluster runs the same minor version in its own release channel. This feature lets you secure your nodes until the patch version becomes the default in your release channel. For details, see Run patch versions from a newer channel. |
High |
GDC (VMware)
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
What should I do? |
Pending |
GKE on AWS
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
What should I do? |
Pending |
GKE on Azure
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
What should I do? |
Pending |
GDC (bare metal)
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
What should I do?There is no action required. GDC software for bare metal isn't affected as it does not bundle an operating system in its distribution. |
None |
GCP-2026-022
Published: 2026-04-16
Reference:
CVE-2026-23209
GKE
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
GKE Standard clusters are impacted. GKE Autopilot clusters in the default configuration are not impacted, but might be vulnerable if you explicitly set the seccomp Clusters using GKE Sandbox aren't impacted. What should I do?The following minor versions are affected. Upgrade your Container-Optimized OS node pools to one of the following patch versions or later:
You can apply patch versions from newer release channels if your cluster runs the same minor version in its own release channel. This feature lets you secure your nodes until the patch version becomes the default in your release channel. For details, see Run patch versions from a newer channel. |
High |
GDC (VMware)
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
What should I do? |
Pending |
GKE on AWS
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
What should I do? |
Pending |
GKE on Azure
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
What should I do? |
Pending |
GDC (bare metal)
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
What should I do?There is no action required. GDC software for bare metal isn't affected as it does not bundle an operating system in its distribution. |
None |
GCP-2026-020
Published: 2026-04-14
Reference:
CVE-2026-23231
GKE
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
GKE Standard clusters are impacted. GKE Autopilot clusters in the default configuration are not impacted, but might be vulnerable if you explicitly set the seccomp Clusters using GKE Sandbox aren't impacted. What should I do?The following minor versions are affected. Upgrade your Container-Optimized OS node pools to one of the following patch versions or later:
You can apply patch versions from newer release channels if your cluster runs the same minor version in its own release channel. This feature lets you secure your nodes until the patch version becomes the default in your release channel. For details, see Run patch versions from a newer channel. |
High |
GDC (VMware)
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
What should I do? |
Pending |
GKE on AWS
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
What should I do? |
Pending |
GKE on Azure
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
What should I do? |
Pending |
GDC (bare metal)
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
What should I do?There is no action required. GDC software for bare metal isn't affected as it does not bundle an operating system in its distribution. |
None |
GCP-2026-018
Published: 2026-04-07
Updated: 2026-04-15
Reference:
CVE-2026-23111
2026-04-15 Update: Added patch versions for Ubuntu nodes with GKE.