UNIX Symbolic Link (Symlink) Following Affecting kubevirt.io/kubevirt/pkg/network/cache package, versions >=0.0.0


Severity

Recommended
0.0
low
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.11% (2nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-KUBEVIRTIOKUBEVIRTPKGNETWORKCACHE-17817958
  • published7 Jul 2026
  • disclosed25 Jun 2026
  • creditUnknown

Introduced: 25 Jun 2026

CVE-2026-13218  (opens in a new tab)
CWE-61  (opens in a new tab)

How to fix?

There is no fixed version for kubevirt.io/kubevirt/pkg/network/cache.

Overview

Affected versions of this package are vulnerable to UNIX Symbolic Link (Symlink) Following through the WriteToCachedFile function when handling network cache files in certain configurations. An attacker can overwrite specific host files and change their ownership by planting a symbolic link at the cache file path and obtaining exec access to the virt-launcher container. The written file content is limited to valid JSON following the network cache schema, and arbitrary byte injection is not possible. This is only exploitable if a cluster administrator has pre-configured a NetworkAttachmentDefinition with bridge-type binding and the attacker has exec access to the virt-launcher container.

Workaround

This vulnerability can be mitigated by ensuring virtual machines use the default masquerade network binding mode, restricting pods/exec access on virt-launcher pods to trusted administrators, and reviewing NetworkAttachmentDefinition resources to limit bridge-type network interfaces.

CVSS Base Scores

version 4.0
version 3.1