PT-2026-39242 · Volano · Volcano

Bugbunny-Research

·

Published

2026-05-08

·

Updated

2026-05-28

·

CVE-2026-44247

CVSS v3.1

6.8

Medium

VectorAV:A/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Volcano versions prior to 1.14.2 Volcano versions prior to 1.13.3 Volcano versions prior to 1.12.4
Description The Volcano webhook server fails to enforce a size limit on incoming HTTP request bodies. This allows any in-cluster pod capable of reaching the webhook endpoint to send an arbitrarily large request body, which may lead to the server being terminated due to Out-of-Memory (OOM), a condition where the system exhausts its available RAM and the operating system kills the process to recover.
Recommendations Upgrade to version 1.14.2. Upgrade to version 1.13.3. Upgrade to version 1.12.4.

Fix

Allocation of Resources Without Limits

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2026-44247
GHSA-8WXP-XXP2-RCGX

Affected Products

Volcano