CVE-2025-61726: cAdvisor vulnerability analysis and mitigation
The net/url package does not set a limit on the number of query parameters in a query. While the maximum size of query parameters in URLs is generally limited by the maximum request header size, the net/http.Request.ParseForm method can parse large URL-encoded forms. Parsing a large form containing many unique query parameters can cause excessive memory consumption.
Source: NVD
Related cAdvisor vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-33186
CRITICAL
9.1
cAdvisor
amazon-cloudwatch-agent-fips
No
Yes
Mar 20, 2026
CVE-2026-34040
HIGH
8.8
cAdvisor
apko
No
Yes
Mar 31, 2026
CVE-2026-33997
MEDIUM
6.8
cAdvisor
github.com/moby/moby/v2
No
Yes
Mar 31, 2026
CVE-2026-27142
MEDIUM
6.1
cAdvisor
karpenter-fips-0.36
No
Yes
Mar 06, 2026
CVE-2026-27139
LOW
2.5
cAdvisor
newrelic-k8s-metadata-injection
No
Yes
Mar 06, 2026
Free Vulnerability Assessment
Benchmark your Cloud Security Posture
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.