VDB
Sign up
—

GO-2026-5653

kube-router: GoBGP gRPC Admin Port Exposed on Node Primary IP Without Authentication, Allowing Cluster-Wide BGP Route Injection in github.com/cloudnativelabs/kube-router

Quick fix

GO-2026-5653 — github.com/cloudnativelabs/kube-router/v2: upgrade to the fixed version with the command below.

go get github.com/cloudnativelabs/kube-router/v2@v2.9.0

Details

kube-router: GoBGP gRPC Admin Port Exposed on Node Primary IP Without Authentication, Allowing Cluster-Wide BGP Route Injection in github.com/cloudnativelabs/kube-router

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/cloudnativelabs/kube-router
Introduced in: 0

No fixed version published yet for github.com/cloudnativelabs/kube-router (go modules). Pin to a known-safe version or switch to an alternative.

Go/github.com/cloudnativelabs/kube-router/v2
Introduced in: 0Fixed in: 2.9.0
Fixgo get github.com/cloudnativelabs/kube-router/v2@v2.9.0

References