AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-11254

MEDIUM · CVSS 6.5 EPSS 2.36% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-04-01 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2019-11254
Severity
MEDIUM
CVSS
6.5
EPSS
2.36%
Kubernetes

Original NVD Description

The Kubernetes API Server component in versions 1.1-1.14, and versions prior to 1.15.10, 1.16.7 and 1.17.3 allows an authorized user who sends malicious YAML payloads to cause the kube-apiserver to consume excessive CPU cycles while parsing YAML.