CVE-2020-8561: Kubernetes Webhook Redirect Flaw in AKS

🟡 Medium | Source: Microsoft Security Response Center CVE-2020-8561 is a vulnerability in the Kubernetes API server (kube-apiserver) that allows an attacker to redirect webhook traffic, potentially enabling server-side request forgery (SSRF) against internal network resources. By manipulating admission webhook configurations, a malicious actor could cause the API server to make requests to arbitrary internal endpoints, bypassing network controls. This affects Azure Kubernetes Service (AKS) and any Kubernetes environment where untrusted users can modify webhook configurations. ...

3 June 2026 · ZX Cloud Security