Web Hack List

Preliminary research

Kubernetes Remote Code Execution Via Nodes/Proxy GET Permission

AI-collected research leads through 2 October 2026, including bounded month-by-month reviews of selected social and community sources from January through September. Unranked, incomplete, not community-vetted, and subject to change.

Shows that Kubernetes `nodes/proxy` GET permission can authorize a WebSocket upgrade to the kubelet `/exec` endpoint without a corresponding create check. The study demonstrates commands in reachable pods, missing API audit visibility and 69 affected Helm charts.

Record

Researcher
Graham Helton
Published by
Graham Helton

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Graham Helton, first published at the original source. Preserved copies are kept so the citation survives its host.