CVE-2025-32777

unknown
Published 2025-04-30 · Modified 2026-03-03
CVSS v3
CVSS v2
VIR risk

Description

Volcano Scheduler Denial of Service via Unbounded Response from Elastic Service/extender Plugin in volcano.sh/volcano

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Package impact

EcosystemPackageVulnerableFixed
golang Govolcano.sh/volcano<1.9.11.9.1
golang Govolcano.sh/volcano>=1.10.0-alpha.0,<1.10.21.10.2
golang Govolcano.sh/volcano>=1.11.0-network-topology-preview.0,<1.11.0-network-topology-preview.31.11.0-network-topology-preview.3
golang Govolcano.sh/volcano>=1.11.0,<1.11.21.11.2
golang Govolcano.sh/volcano>=1.12.0-alpha.0,<1.12.0-alpha.21.12.0-alpha.2

References

Verify integrity in audit chain (admin only). AS-IS.