PT-2026-28434 · Coreos+1 · Flannel+1

CVE-2026-32241

·

Published

2026-03-18

·

Updated

2026-07-30

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Flannel versions prior to 0.28.2
Description Flannel, a network fabric for containers designed for Kubernetes, contains a command injection issue in its experimental Extension backend. An attacker who can set Kubernetes Node annotations can achieve root-level arbitrary command execution on every flannel node in the cluster. The Extension backend’s SubnetAddCommand and SubnetRemoveCommand receive attacker-controlled data via stdin from the flannel.alpha.coreos.com/backend-data Node annotation, which is then piped directly to a shell command without validation. Kubernetes clusters using Flannel with the Extension backend are affected; other backends like vxlan and wireguard are not impacted.
Recommendations Versions prior to 0.28.2 should be updated to version 0.28.2 or later. As a workaround, use Flannel with a different backend such as vxlan or wireguard.

Exploit

Fix

DoS

RCE

Command Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-80972
BDU:2026-07361
CVE-2026-32241
GHSA-VCHX-5PR6-FFX2
GO-2026-4894
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:1205-1

Affected Products

Flannel
Red Os