PatchSiren cyber security CVE debrief
CVE-2026-62370 kubeedge CVE debrief
CVE-2026-62370 is a vulnerability in KubeEdge, an open-source system for extending native containerized application orchestration capabilities to hosts at Edge. From versions 1.0.0 until 1.21.2, 1.22.2, and 1.23.1, an authenticated malicious or compromised edge peer can repeatedly send crafted headers with excessive declared lengths, causing memory exhaustion, CloudHub process termination or restart loops, and temporary disruption of cloud-edge communication.
- Vendor
- kubeedge
- Product
- Unknown
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-21
- Original CVE updated
- 2026-09-29
- Advisory published
- 2026-09-21
- Advisory updated
- 2026-09-29
Who should care
Edge computing environments using KubeEdge, security teams responsible for monitoring and patching vulnerabilities in edge devices, and administrators of cloud-edge infrastructure.
Why it matters
CVE-2026-62370 is a medium-severity vulnerability in KubeEdge that can lead to denial-of-service conditions. Edge computing environments using KubeEdge should assess exposure and prioritize remediation to prevent potential exploitation.
- Potential denial-of-service conditions through memory exhaustion and CloudHub process termination or restart loops.
- Temporary disruption of cloud-edge communication.
- Need for verification of KubeEdge versions and exposure in edge computing environments.
- Priority for patching or updating to fixed versions to prevent potential exploitation.
Technical summary
The vulnerability exists in the Reader.Read function of pkg/viaduct/pkg/packer, which trusts the 32-bit PackageHeader.PayloadLen received through the CloudHub viaduct message-processing path and allocates that amount of memory before validating an upper bound. This can lead to memory exhaustion and disruption of cloud-edge communication. Edge computing environments using KubeEdge should prioritize assessment and remediation of this vulnerability to prevent potential denial-of-service conditions. Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Defensive priority
Edge computing environments using KubeEdge should prioritize assessment and remediation of this vulnerability to prevent potential denial-of-service conditions.
Recommended defensive actions
- Assess exposure by reviewing KubeEdge versions in use and verifying if they are within the affected range.
- Apply patches or updates to versions 1.21.2, 1.22.2, or 1.23.1, or later.
- Monitor CloudHub process stability and logs for signs of potential exploitation attempts.
- Implement additional security measures, such as authentication and authorization checks, for edge peers.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its description, affected versions, and fixed versions. However, the corpus does not establish versions for all deployments or confirm exploitation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-62370 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-62370
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-62370 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-62370
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/kubeedge/kubeedge/blob/master/CHANGELOG/CHANGELOG-1.21.md
-
Source reference
Unverified legacy reference
URL: https://github.com/kubeedge/kubeedge/blob/master/CHANGELOG/CHANGELOG-1.22.md
-
Source reference
Unverified legacy reference
URL: https://github.com/kubeedge/kubeedge/blob/master/CHANGELOG/CHANGELOG-1.23.md
-
Source reference
Unverified legacy reference
URL: https://github.com/kubeedge/kubeedge/commit/0fe1ea18e5d7fde29633286ddf1c7e71cb39606f
-
Source reference
Unverified legacy reference
URL: https://github.com/kubeedge/kubeedge/commit/725a73ca35a65d91aa6338e52b8faaab6058f528
-
Source reference
Unverified legacy reference
URL: https://github.com/kubeedge/kubeedge/commit/cc79621943fff9d3f62638d9403ef0cfeda3d0e7
-
Source reference
Unverified legacy reference
URL: https://github.com/kubeedge/kubeedge/pull/7028
-
Source reference
Unverified legacy reference
URL: https://github.com/kubeedge/kubeedge/pull/7029
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.