Releases: kubecost/kubecost
Release list
v3.2.3
Release Notes
Cherry-picked a change that was missed in the 3.2.2 release. Without this change, the helm chart values .Values.frontend.bufferConfig and .Values.frontend.extraServerConfig are not deduplicated, meaning that if these configuration blocks apply any overlapping directives, the frontend pod will fail to start. For example:
frontend:
bufferConfig:
proxy_busy_buffers_size: "512k"
extraServerConfig:
proxy_busy_buffers_size: "1024k"Will cause nginx to crash. After the changes applied to 3.2.3, the keys are deduped and priority is given to values in extraServerConfig.
v3.2.2
Release Notes
Frontend
- Improved the speed at which totals rows load for very large numbers of items
- Added a missing parameter (
includeCount) to cloud cost API calls - Fix issues in rendering hardware capacity in the Capacity Planning graph
Aggregator
- Added missing database connection closures, which may fix an issue with APIs not returning due to connection starvation
- Fixed an issue where the Assets API would fail to return data if the recorded active minutes of the asset were
0 - Fixed an issue where the API powering the Assets page graphs were missing item names when aggregated by label
- Added the first stage of support for the new Kubemodel pipeline (see the Opencost section for details on Kubemodel)
- Update "totals" endpoints to use a memory-cheap approximate count when there are more than 4,096 items (see second item in Frontend)
- Enhanced enterprise custom pricing so that the "version" field of a pricing spec is no longer case-sensitive
- Fix an issue where RBAC users that had both Admin and Editor roles applied would be treated as Editors
- Updated the
/model/savings/requestSizingV2API endpoint to correctly return a400 Bad Requestwhen given invalid parameters- Previously returned
500 Internal Server Error
- Previously returned
Opencost
- Added first stage of support for the new Kubemodel pipeline: opencost/opencost#3875
Kubecost (Helm chart)
- Added new default nginx buffer sizes to allow larger request/response bodies: #4712
- Added common Kubecost labels to two templates so that Operators can manage manifests more effectively: #4729
Helm Chart Comparison Report
Before Chart: kubecost/kubecost@v3.2.1
After Chart: kubecost/kubecost@v3.2.2
CVE by Severity
| Severity | Count | Prev Count | Difference |
|---|---|---|---|
| critical | 0 | 0 | +0 |
| high | 30 | 69 | -39 |
| medium | 315 | 400 | -85 |
| low | 221 | 274 | -53 |
Unchanged CVEs
High
| CVE ID | Severity | Affected Images |
|---|---|---|
| CVE-2026-11352 | high | frontend, network-costs, cost-model, modeling |
| CVE-2026-11586 | high | network-costs, cost-model, modeling, frontend |
| CVE-2026-33630 | high | curl |
| CVE-2026-39822 | high | cost-model |
| CVE-2026-45447 | high | curl |
| CVE-2026-46600 | high | cost-model, cluster-controller |
| CVE-2026-56852 | high | cost-model, cluster-controller |
| CVE-2026-8286 | high | cost-model, modeling, frontend, network-costs |
| CVE-2026-8925 | high | cost-model, modeling, frontend, network-costs |
| CVE-2026-9547 | high | modeling, frontend, network-costs, cost-model |
| GHSA-hrxh-6v49-42gf | high | cost-model |
Medium
| CVE ID | Severity | Affected Images |
|---|---|---|
| CVE-2023-30571 | medium | cost-model, modeling, frontend, network-costs |
| CVE-2023-45803 | medium | cost-model |
| CVE-2024-29040 | medium | cost-model |
| CVE-2025-11468 | medium | cost-model, modeling |
| CVE-2025-12781 | medium | cost-model, modeling |
| CVE-2025-13034 | medium | cost-model, modeling, frontend, network-costs |
| CVE-2025-13837 | medium | cost-model |
| CVE-2025-14017 | medium | cost-model, modeling, frontend, curl, network-costs |
| CVE-2025-15282 | medium | cost-model |
| CVE-2025-4516 | medium | cost-model, modeling |
| CVE-2025-50181 | medium | cost-model, modeling |
| CVE-2025-50182 | medium | cost-model, modeling |
| CVE-2025-6069 | medium | modeling |
| CVE-2025-60753 | medium | cost-model, modeling, frontend, network-costs |
| CVE-2025-68972 | medium | modeling, frontend, network-costs, cost-model |
| CVE-2026-0672 | medium | cost-model |
| CVE-2026-0990 | medium | modeling, frontend, network-costs, cost-model |
| CVE-2026-11850 | medium | cost-model, modeling, frontend, network-costs |
| CVE-2026-11856 | medium | modeling, frontend, network-costs, cost-model |
| CVE-2026-11972 | medium | cost-model, modeling |
| CVE-2026-11979 | medium | cost-model, modeling, frontend, network-costs |
| CVE-2026-12610 | medium | frontend, network-costs, cost-model |
| CVE-2026-13595 | medium | cost-model, modeling, frontend, network-costs |
| CVE-2026-1484 | medium | network-costs, cost-model, modeling, frontend |
| CVE-2026-1489 | medium | frontend, network-costs, cost-model, modeling |
| CVE-2026-1502 | medium | cost-model |
| CVE-2026-15588 | medium | cost-model, modeling, frontend, network-costs |
| CVE-2026-16118 | medium | cost-model, modeling, frontend, network-costs |
| CVE-2026-16730 | medium | cost-model, frontend, network-costs |
| CVE-2026-1757 | medium | network-costs, cost-model, modeling, frontend |
| CVE-2026-1965 | medium | cost-model, modeling, frontend, curl, network-costs |
| CVE-2026-22185 | medium | frontend, network-costs, cost-model, modeling |
| CVE-2026-25645 | medium | cost-model, modeling |
| CVE-2026-2673 | medium | cost-model, modeling, frontend, network-costs |
| CVE-2026-27456 | medium | modeling, frontend, network-costs, cost-model |
| CVE-2026-28755 | medium | frontend |
| CVE-2026-32284 | medium | cost-model, modeling |
| CVE-2026-3276 | medium | cost-model, modeling |
| CVE-2026-32776 | medium | cost-model, modeling, frontend, network-costs |
| CVE-2026-32777 | medium | cost-model, modeling, frontend, network-costs |
| CVE-2026-32778 | medium | frontend, network-costs, cost-model, modeling |
| CVE-2026-34182 | medium | curl |
| CVE-2026-34183 | medium | curl |
| CVE-2026-34743 | medium | cost-model, modeling, frontend, network-costs |
| CVE-2026-3644 | medium | cost-model |
| CVE-2026-3783 | medium | cost-model, modeling, frontend, curl, network-costs |
| CVE-2026-3784 | medium | network-costs, cost-model, modeling, frontend, curl |
| CVE-2026-3805 | medium | curl |
| CVE-2026-40460 | medium | frontend |
| CVE-2026-40701 | medium | frontend |
| CVE-2026-4105 | medium | cost-model, modeling, frontend, network-costs |
| CVE-2026-41991 | medium | network-costs, cost-model, frontend |
| CVE-2026-4224 | medium | cost-model |
| CVE-2026-42250 | medium | cost-model, modeling, frontend, network-costs |
| CVE-2026-42308 | medium | cost-model, modeling |
| CVE-2026-42505 | medium | cost-model |
| CVE-2026-42533 | medium | frontend |
| CVE-2026-42764 | medium | curl |
| CVE-2026-42934 | medium | frontend |
| CVE-2026-42946 | medium | frontend |
| CVE-2026-4426 | medium | frontend, network-costs, cost-model, modeling |
| CVE-2026-44604 | medium | cost-model, modeling, frontend, network-costs |
| CVE-2026-45409 | medium | cost-model, modeling |
| CVE-2026-45445 | medium | curl |
| CVE-2026-48142 | medium | frontend |
| CVE-2026-4873 | medium | frontend, curl, network-costs, cost-model, modeling |
| CVE-2026-50219 | medium | frontend, network-costs, cost-model, modeling |
| CVE-2026-54371 | medium | agent, cost-model, cluster-controller, modeling, frontend, network-costs |
| CVE-2026-54411 | medium | network-costs, cost-model, frontend |
| CVE-2026-5545 | medium | network-costs, cost-model, modeling, frontend, curl |
| CVE-2026-56132 | medium | cost-model, modeling, frontend, network-costs |
| CVE-2026-56391 | medium | modeling, frontend, network-costs, agent, cost-model, cluster-controller |
| CVE-2026-56392 | medium | network-costs, agent, cost-model, cluster-controller, modeling, frontend |
| CVE-2026-56403 | medium | modeling, frontend, network-costs, cost-model |
| CVE-2026-56405 | medium | cost-model, modeling, frontend, network-costs |
| CVE-2026-56406 | medium | network-costs, cost-model, modeling, frontend |
| CVE-2026-56412 | medium | cost-model, modeling, frontend, network-costs |
| CVE-2026-5713 | medium | cost-model, modeling |
| CVE-2026-5745 | medium | cost-model, modeling, frontend, network-costs |
| CVE-2026-5773 | medium | cost-model, modeling, frontend, curl, network-costs |
| CVE-2026-58010 | medium | frontend, network-costs, cost-model, modeling |
| CVE-2026-58011 | medium | cost-model, modeling, frontend, network-costs |
| CVE-2026-58012 | medium | modeling, frontend, network-costs, cost-model |
| CVE-2026-58013 | medium | modeling, frontend, network-costs, cost-model |
| CVE-2026-58014 | medium | network-costs, cost-model, modeling, frontend |
| CVE-2026-58015 | medium | frontend, network-costs, cost-model, modeling |
| CVE-2026-58055 | medium | cost-model, modeling, frontend, network-costs |
| CVE-2026-5958 | medium | network-costs, cost-model, modeling, frontend |
| CVE-2026-59890 | medium | modeling |
| CVE-2026-6019 | medium | cost-model, modeling |
| CVE-2026-6253 | medium | cost-model, modeling, frontend, curl, network-costs |
| CVE-2026-6429 | medium | network-costs, cost-model, modeling, frontend, curl |
| CVE-2026-6653 | medium | cost-model, modeling, frontend, network-costs |
| CVE-2026-6732 | medium | network-costs, cost-model, modeling, frontend |
| CVE-2026-7009 | medium | curl |
| CVE-2026-7168 | medium | cost-model, modeling, frontend, curl, network-costs |
| CVE-2026-7210 | medium | modeling, cost-model |
| CVE-2026-8924 | medium | cost-model, modeling, frontend, network-costs |
| CVE-2026-8926 | medium | frontend, network-costs, cost-model, modeling |
| CVE-2026-9149 | medium | frontend, network-costs, cost-model, modeling |
| CVE-2026-9150 | medium | cost-model, modeling, frontend, network-costs |
Low
| CVE ID | Severity | Affected Images |
|---|---|---|
| CVE-2021-3572 | low | cost-model |
| CVE-2021-46195 | low | agent, cost-model, cluster-controller, modeling, frontend, network-costs |
| CVE-2022-27943 | low | agent, cost-model, cluster-controller, modeling, frontend, network-costs |
| CVE-2022-3219 | low | cost-model, modeling, frontend, network-costs |
| CVE-2022-41409 | low | agent, cost... |
v2.9.7
What's Changed
- Enhance v2.9 error messages by @thomasvn in #4561
- Default all Kubecost images to ICR by @thomasvn in #4613
- Bump in-code version for 2.9.7 by @cliffcolvin in #4721
- Bump images and chart version for 2.9.7 by @ErikTorres1998 in #4724
Full Changelog: v2.9.6...v2.9.7
v2.8.7
What's Changed
- Default all Kubecost images to ICR (v2.8) by @thomasvn in #4615
- Bump in-code version for 2.8.7 by @cliffcolvin in #4716
Full Changelog: v2.8.6...v2.8.7
v3.2.1
Security patch release
Removal of deprecated execution path
The legacyMode option for cluster-controller has been removed from the Helm chart, along with the execution mode that it enabled. This mode has been deprecated since the release of Kubecost 3.0.0, and depended on very old versions of libraries in which CVEs had begun to appear.
Dependency upgrades
Base images, system libraries, and code libraries received version bumps across the board to resolve vulnerabilities.
Other bug fixes
- Fixed an issue where updating the Budgets configmap would erroneously fail with a "duplicate name" error.
- Removed an overly-noisy ECP log
- Fixed an issue with ECP retroactive pricing in RBAC Teams
Image list
icr.io/ibm-finops/agent:v1.0.20
icr.io/kubecost/cluster-controller:v0.16.37
icr.io/kubecost/cost-model:3.2.1
icr.io/kubecost/frontend:3.2.1
icr.io/kubecost/modeling:v0.1.36
icr.io/kubecost/network-costs:v0.19.0
v3.2.0
Major
- (Enterprise) Resource Quota rightsizing has been integrated with the container rightsizing Action. Customers can now orchestrate the resizing process of both containers and Kubernetes Resource Quotas from a single job using custom profiles and dedicated lookback windows.
- The return of free Actions! Kubecost 3.2 brings back container resizing actions for users of the free edition. Actions are limited to a single cluster and do not include the Resource Quota rightsizing integration. Some manual setup steps are required so be sure to read the documentation.
- An all-new Audit Log is available for Actions with separate tables for the Kubernetes resource types, a comprehensive click-in experience, column manager, the ability to download log entries as JSON, and more.
- (Enterprise) Enterprise Custom Pricing (ECP) has a new UI under the Settings page which allows customers to manage the entire lifecycle of CSV-based custom pricing from the UI including adding, updating, and removing custom pricing specifications. A new (optional) v2 spec provides the ability to supply up to three (3) total labels for greater flexibility in node matching. The UI provides helpful guidance on which row(s) may result in retroactive pricing adjustments along with timelines. And validation has been greatly expanded and improved to ensure the pricing specs provided are accurate.
Minor
- Resource Quota custom profiles can now be named and saved similar to container resizing profiles. Profiles are accessible to both the Resource Quota Rightsizing card on the Savings Insights page as well as the container resizing Action on the Savings Actions page.
- (Enterprise) Kubecost Teams RBAC now supports the Resource Quota Rightsizing page in Savings Insights allowing you to construct roles for your users with the same filters found on that page.
- The Kubecost Health Alert has been enhanced to now include health status changes of your cloud integrations.
- A couple of new banners are present, one reminding you how and where to set up cloud integrations, and a second allowing you to tell us about your experiences in exchange for a gift card.
- The Container Request Rightsizing page now supports downloading a PDF in addition to CSV.
- The Diagnostics page now includes the configured cloud integrations making easier to see health status of your Kubecost estate in one page.
- Carbon emissions equivalents can now be seen in the Allocation Details view.
- Added new diagnostic visualizations for secondary agent heartbeats overtime, and agent CPU and RAM usage on secondary clusters.
- Added a new API to return a summary of the actions dispatched as part of a scheduled run.
- Added account filter support to Allocations.
- (Cluster Controller) A new environment variable
MIN_NAMESPACE_AGEcan be used to configure the minimum age that a namespace must have before it can be deleted by namespace turndown. Default4h. - (Cluster Controller) A new environment variable
ACTION_TTLcan be used to tell Actions executors to ignore Actions messages older than the TTL. Defaults to1h. - (UI) Added the ability to Edit an existing Cloud Integration via the UI.
- (UI) Added orchestrator diagnostics and ECP diagnostics to the Bug Report export.
- (UI) Added Cloud Provider integrations as a sub-navigation item of the Settings nav item.
- (UI) Added a dismissible banner to the Overview page prompting setup of a Cloud Integration when none are present.
- (UI) Removed broken "Cluster Turndown" option from the Actions menu.
- (UI) Added new visualizations for Cluster Diagnostics.
- (UI) Added carbon costs to the Allocation Details page.
- (UI) Added a date tooltip to the Cluster List "Last Seen" field. I.e., mousing over "1 month ago" will show the precise date of last data reported.
- (UI) Added a link to a form for user feedback - link lives in the Settings page.
- FinOps agent is updated to 1.0.19.
- Cluster Controller is updated to v0.16.35.
- Network Costs is updated to v0.18.3.
- Forecasting is updated to v0.1.35.
- (Helm) Added persistent storage to cloud costs.
- (Helm) Added a flag to disable showing of cloud costs in the UI.
- (Helm) Added annotations to PVCs.
- (Helm) Added a rate limiter value for use in cluster controller.
- (Helm) Added a log level env var to cloud costs and set imagePullPolicy.
- (Helm) Added the release namespace to all remaining Helm templates.
- (Helm) Added a method to run aggregator without a persistent volume (not recommended!).
- (Helm) Added a storage lookback value for diagnostics and heartbeat.
- Standardized base image on ubi9-minimal:latest.
Fixes
- (Important) The same fix we put in place in Kubecost 3.1.8 which improves cost accuracy in some cases has been incorporated into Kubecost 3.2.0 as well. Whether you upgrade from 3.1.8 or an earlier version, rest assured you’ll get the fix.
- Fix an issue where Efficiency views would send the wrong
?idle=parameter in some cases. - Fix an issue where navigating to request sizing from the Allocations page would pass parameter “filters” instead of “filter”
- (Helm) Fix a typing issue in the value
aggregator.dbConcurrentIngestionCount. - (Helm) Fix an issue with disabling of diagnostics and heartbeats.
- Fixed/improved response of budgets API.
- Fixed an issue with a panic when global config was enabled but health alert was not.
- Fixed adding Resource Quota savings amounts to savings cache.
- Fixed handling of null values in webhooks in budget actions.
- Fixed an issue where unauthed monitoring endpoints would fail to work when RBAC teams was enabled.
- Fixed cluster status API showing cluster name with resource group.
- Fixed an issue where users with Editor permissions in RBAC/Teams setups could not create/edit Budgets.
- Fixed an issue which could cause excessive file build-up from heartbeats and diagnostics.
- Fixed an issue where shared costs will now behave correctly when filtering by a namespace and sharing another namespace, with idle enabled/separate.
- Fixed an issue which would allow duplicate role names upon editing.
- Fixed an issue where downloading a CSV/PDF from Collections didn't use the display currency but always USD.
- Fixed an issue in the actions scheduler where if the logic was "Run everywhere EXCEPT at this time" with nothing selected the action would not run.
- Fixed an issue in the container request rightsizing API where when quantileOfMaxes algorithm had qCPU and qRAM set to 1.0 it would not equal max but instead 99%.
- Fixed an issue where core counts would divide by zero which resulted in a query failure.
- Fixed an issue where the "Test Cloud Integration" functionality would erroneously show a failure on success.
- Defunct Settings fields have been removed from the Settings page.
- Fixed issues with Settings page failing to save.
- Fixed an error in fetching / deleting RBAC teams when the team name contained special characters.
- Fixed an issue in allocation PDF downloads where filters were not applied correctly.
- Fixed an issue where the browser's Back button did not work on Teams and Diagnostics pages.
- Fixed an issue where CSV report downloads would repeat the report title twice in the file name.
- Fixed an issue where "Upgrade" prompts could show up in installs that already used a v2 enterprise license.
- Fixed a bug where tooltip content could not be clicked because mousing onto the tooltip caused it to close.
- Fixed a bug where global behavior for
idlecould default toShare By Clusterinstead ofSeparate. - Fixed a bug where a new Action with the same name would overwrite the existing same-named Action (due to using names as IDs).
Helm Chart Comparison Report
After Chart: kubecost/kubecost@3.2.0
Before Chart: kubecost/kubecost@3.1.8
CVE by Severity
| Severity | Count | Prev Count | Difference |
|---|---|---|---|
| critical | 0 | 0 | +0 |
| high | 49 | 64 | -15 |
| medium | 267 | 330 | -63 |
| low | 207 | 250 | -43 |
Unchanged CVEs
High
| CVE ID | Severity | Affected Images |
|---|---|---|
| CVE-2025-59375 | high | modeling |
| CVE-2026-23949 | high | modeling |
| CVE-2026-24049 | high | modeling |
| CVE-2026-27135 | high | network-costs, modeling |
| CVE-2026-33845 | high | frontend, network-costs, cost-model, modeling |
| CVE-2026-33846 | high | network-costs, cost-model, modeling, frontend |
| CVE-2026-40356 | high | modeling, network-costs |
| CVE-2026-4111 | high | network-costs |
| CVE-2026-42009 | high | network-costs, cost-model, modeling, frontend |
| CVE-2026-42010 | high | cost-model, modeling, frontend, network-costs |
| CVE-2026-4424 | high | network-costs, modeling |
| CVE-2026-44431 | high | modeling |
| CVE-2026-44432 | high | modeling |
| CVE-2026-45186 | high | modeling, frontend, network-costs, cost-model |
| CVE-2026-4519 | high | modeling |
| CVE-2026-46680 | high | cluster-controller |
| CVE-2026-4786 | high | modeling |
| CVE-2026-4878 | high | network-costs, cluster-controller, modeling |
| CVE-2026-6100 | high | modeling |
Medium
| CVE ID | Severity | Affected Images |
|---|---|---|
| CVE-2023-30571 | medium | network-costs, cost-model, modeling, frontend |
| CVE-2023-45803 | medium | cost-model |
| CVE-2024-29040 | medium | cost-model |
| CVE-2025-11468 | medium | cost-model, modeling |
| CVE-2025-12781 | medium | cost-model, modeling |
| CVE-2025-13034 | medium | network-costs, cost-model, modeling, frontend |
| CVE-2025-13837 | medium | cost-model, modeling |
| CVE-2025-14017 | medium | network-costs, cost-model, modeling, frontend, curl |
| CVE-2025-14087 | medium | network-costs, modeling |
| CVE-2025-14512 | ... |
v3.1.8
Important Notice
Kubecost 3.1.8 includes a significant patch for the agent that will need to be upgraded on all clusters.
This patch should improve cost accuracy in large clusters and in clusters under significant load.
What's Changed
- Fix: Enterprise Custom Pricing bug that would cause incorrect/$0 costs by @nik-kc
- Fix: service monitor indentations in 3.1 by @jessegoodier in #4658
- Fix agent: Improve metric quality that could cause negative usage/costs by @mbolt35 in opencost/opencost#3787
- Fix agent: increase default scrape interval to 60s (up from 30s) to improve cost accuracy caused by incomplete metrics when using intervals that are too short by @jessegoodier in #4660
- Fix: reduce CVE with dependency bumps. Details below. Shout out to @thomasvn!
Helm Chart Comparison Report
Before Chart: kubecost/kubecost@3.1.7
After Chart: kubecost/kubecost@3.1.8
CVE by Severity
| Severity | Count | Prev Count | Difference |
|---|---|---|---|
| critical | 0 | 3 | -3 |
| high | 61 | 99 | -38 |
| medium | 298 | 321 | -23 |
| low | 251 | 253 | -2 |
Unchanged CVEs
High
| CVE ID | Severity | Affected Images |
|---|---|---|
| CVE-2025-59375 | high | modeling |
| CVE-2026-23949 | high | modeling |
| CVE-2026-24049 | high | modeling |
| CVE-2026-27135 | high | network-costs, modeling |
| CVE-2026-29181 | high | cluster-controller |
| CVE-2026-32280 | high | cluster-controller |
| CVE-2026-32281 | high | cluster-controller |
| CVE-2026-32283 | high | cluster-controller |
| CVE-2026-33810 | high | cluster-controller |
| CVE-2026-33811 | high | cluster-controller |
| CVE-2026-33814 | high | cluster-controller |
| CVE-2026-33845 | high | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-33846 | high | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-34986 | high | cluster-controller |
| CVE-2026-39820 | high | cluster-controller |
| CVE-2026-39836 | high | cluster-controller |
| CVE-2026-39883 | high | cluster-controller |
| CVE-2026-40356 | high | network-costs, agent, cost-model, modeling, frontend |
| CVE-2026-4111 | high | network-costs |
| CVE-2026-42009 | high | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-42010 | high | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-42499 | high | cluster-controller |
| CVE-2026-4424 | high | modeling, network-costs |
| CVE-2026-44431 | high | modeling |
| CVE-2026-44432 | high | modeling |
| CVE-2026-45186 | high | frontend, network-costs, cost-model, modeling |
| CVE-2026-4519 | high | modeling |
| CVE-2026-46680 | high | cluster-controller |
| CVE-2026-4786 | high | modeling |
| CVE-2026-4878 | high | cost-model, cluster-controller, modeling, frontend, network-costs, agent |
| CVE-2026-6100 | high | modeling |
Medium
| CVE ID | Severity | Affected Images |
|---|---|---|
| CVE-2023-30571 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2023-45803 | medium | cost-model |
| CVE-2024-29040 | medium | cost-model |
| CVE-2025-11468 | medium | cost-model, modeling |
| CVE-2025-12781 | medium | cost-model, modeling |
| CVE-2025-13034 | medium | cost-model, modeling, frontend, network-costs, agent |
| CVE-2025-13837 | medium | cost-model, modeling |
| CVE-2025-14017 | medium | frontend, curl, network-costs, agent, cost-model, modeling |
| CVE-2025-14087 | medium | cost-model, modeling, frontend, network-costs, agent |
| CVE-2025-14512 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2025-15282 | medium | cost-model, modeling |
| CVE-2025-23419 | medium | frontend |
| CVE-2025-4516 | medium | cost-model, modeling |
| CVE-2025-50181 | medium | cost-model, modeling |
| CVE-2025-50182 | medium | cost-model, modeling |
| CVE-2025-5278 | medium | frontend, network-costs, agent, cost-model, cluster-controller, modeling |
| CVE-2025-6069 | medium | modeling |
| CVE-2025-60753 | medium | cost-model, modeling, frontend, network-costs, agent |
| CVE-2025-68972 | medium | agent, cost-model, modeling, frontend, network-costs |
| CVE-2026-0672 | medium | cost-model, modeling |
| CVE-2026-0865 | medium | modeling |
| CVE-2026-0990 | medium | agent, cost-model, modeling, frontend, network-costs |
| CVE-2026-1484 | medium | cost-model, modeling, frontend, network-costs, agent |
| CVE-2026-1489 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-1502 | medium | cost-model, modeling |
| CVE-2026-1757 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-1965 | medium | network-costs, agent, cost-model, modeling, frontend, curl |
| CVE-2026-2100 | medium | agent, modeling, network-costs |
| CVE-2026-22185 | medium | agent, cost-model, modeling, frontend, network-costs |
| CVE-2026-25645 | medium | cost-model, modeling |
| CVE-2026-2673 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-27456 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-28386 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-28390 | medium | cost-model, modeling, frontend, network-costs, agent |
| CVE-2026-28684 | medium | modeling |
| CVE-2026-29111 | medium | network-costs, agent, modeling |
| CVE-2026-31790 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-32282 | medium | cluster-controller |
| CVE-2026-32284 | medium | cost-model, modeling |
| CVE-2026-32288 | medium | cluster-controller |
| CVE-2026-32289 | medium | cluster-controller |
| CVE-2026-32776 | medium | modeling, frontend, network-costs, cost-model |
| CVE-2026-32777 | medium | frontend, network-costs, cost-model, modeling |
| CVE-2026-32778 | medium | frontend, network-costs, cost-model, modeling |
| CVE-2026-34743 | medium | agent, cost-model, modeling, frontend, network-costs |
| CVE-2026-35206 | medium | cluster-controller |
| CVE-2026-3644 | medium | cost-model, modeling |
| CVE-2026-3783 | medium | curl, network-costs, agent, cost-model, modeling, frontend |
| CVE-2026-3784 | medium | frontend, curl, network-costs, agent, cost-model, modeling |
| CVE-2026-3805 | medium | frontend, curl, network-costs, agent, cost-model, modeling |
| CVE-2026-3833 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-39823 | medium | cluster-controller |
| CVE-2026-39825 | medium | cluster-controller |
| CVE-2026-39826 | medium | cluster-controller |
| CVE-2026-40355 | medium | modeling, frontend, network-costs, agent, cost-model |
| CVE-2026-4046 | medium | network-costs, agent, cost-model, cluster-controller, modeling, frontend |
| CVE-2026-4105 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-41989 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-42011 | medium | modeling, frontend, network-costs, agent, cost-model |
| CVE-2026-4224 | medium | modeling, cost-model |
| CVE-2026-42308 | medium | cost-model, modeling |
| CVE-2026-4426 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-4437 | medium | agent, cost-model, cluster-controller, modeling, frontend, network-costs |
| CVE-2026-45409 | medium | modeling |
| CVE-2026-4873 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-5121 | medium | network-costs, modeling |
| CVE-2026-5435 | medium | cost-model, cluster-controller, modeling, frontend, network-costs, agent |
| CVE-2026-5450 | medium | modeling, frontend, network-costs, agent, cost-model, cluster-controller |
| CVE-2026-5545 | medium | modeling, frontend, network-costs, agent, cost-model |
| CVE-2026-5713 | medium | modeling, cost-model |
| CVE-2026-5745 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-5773 | medium | cost-model, modeling, frontend, network-costs, agent |
| CVE-2026-5928 | medium | agent, cost-model, cluster-controller, modeling, frontend, network-costs |
| CVE-2026-6019 | medium | cost-model, modeling |
| CVE-2026-6253 | medium | cost-model, modeling, frontend, network-costs, agent |
| CVE-2026-6429 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-6732 | medium | network-costs, agent, cost-model, modeling, frontend |
| CVE-2026-7168 | medium | cost-model, modeling, frontend, network-costs, agent |
| CVE-2026-9149 | medium | agent, cost-model, modeling, frontend, network-costs |
| CVE-2026-9150 | medium | frontend, network-costs, agent, cost-model, modeling |
| GHSA-xmrv-pmrh-hhx2 | medium | cost-model |
Low
| CVE ID | Severity | Affected Images |
|---|---|---|
| CVE-2021-3572 | low | cost-model |
| CVE-2022-27943 | low | network-costs, agent, cost-model, cluster-controller, modeling, frontend |
| CVE-2022-3219 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2022-41409 | low | network-costs, agent, cost-model, cluster-controller, modeling, frontend |
| CVE-2023-32636 | low | network-costs, agent, cost-model, modeling, frontend |
| CVE-2023-4156 | low | modeling, frontend, network-costs, agent, cost-model |
| CVE-2023-45322 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2023-50495 | low | network-costs, agent, cost-model, cluster-controller, modeling, frontend |
| CVE-2023-5752 | low | cost-model |
| CVE-2024-0232 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2024-11053 | low | network-costs, agent, cost-model, modeling, frontend |
| CVE-2024-13176 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2024-25260 | low | cost-model |
| CVE-2024-34459 | low | frontend, network-costs, agent, cost-model, modeling ... |
v3.1.7
Kubecost 3.1.7 resolves cost calculation accuracy issues affecting environments with undersized agents experiencing frequent restarts. While overall cost reporting remained directionally accurate, some users observed intermittent negative cost values in their reports.
Additional Detail
What to expect upon upgrade
Upon upgrading to 3.1.7, Kubecost automatically recalculates historical cost data to correct affected calculations. The system remains fully operational during this process, with a green status indicator displayed during recalculation. No manual intervention is required.
Validation
Fixes were validated across diverse cluster configurations and datasets to ensure consistent behavior across all environments.
Performance enhancements
This release includes backend optimizations for improved stability during data processing and query-intensive operations:
- Dynamic concurrency management
- Enhanced retry logic for ingestion and derivation
- Database query optimizations
What's Changed
- 🍒 Service Monitor Debugging to v3.1 by @github-actions[bot] in #4636
Full Changelog: v3.1.6...v3.1.7
Helm Chart Comparison Report
After Chart: kubecost/kubecost@3.1.7
Before Chart: kubecost/kubecost@3.1.6
CVE by Severity
| Severity | Count | Prev Count | Difference |
|---|---|---|---|
| critical | 3 | 3 | +0 |
| high | 62 | 73 | -11 |
| medium | 276 | 279 | -3 |
| low | 261 | 261 | +0 |
Unchanged CVEs
Critical
| CVE ID | Severity | Affected Images |
|---|---|---|
| CVE-2025-68121 | critical | cost-model |
| CVE-2026-33186 | critical | agent, cost-model |
High
| CVE ID | Severity | Affected Images |
|---|---|---|
| CVE-2025-61726 | high | cost-model |
| CVE-2025-61728 | high | cost-model |
| CVE-2026-23949 | high | modeling |
| CVE-2026-24049 | high | modeling |
| CVE-2026-24051 | high | agent |
| CVE-2026-25679 | high | cost-model |
| CVE-2026-27135 | high | network-costs, agent, modeling |
| CVE-2026-27896 | high | cost-model |
| CVE-2026-29181 | high | agent, cluster-controller |
| CVE-2026-32280 | high | cost-model, cluster-controller, agent |
| CVE-2026-32281 | high | agent, cost-model, cluster-controller |
| CVE-2026-32283 | high | agent, cost-model, cluster-controller |
| CVE-2026-33252 | high | cost-model |
| CVE-2026-33487 | high | cost-model |
| CVE-2026-33810 | high | agent, cluster-controller |
| CVE-2026-33845 | high | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-33846 | high | agent, cost-model, modeling, frontend, network-costs |
| CVE-2026-34742 | high | cost-model |
| CVE-2026-34986 | high | agent, cost-model, cluster-controller |
| CVE-2026-39883 | high | cost-model, cluster-controller, agent |
| CVE-2026-40356 | high | modeling, frontend, network-costs, agent, cost-model |
| CVE-2026-4111 | high | network-costs, agent |
| CVE-2026-4424 | high | network-costs, agent, modeling |
| CVE-2026-4519 | high | modeling |
| CVE-2026-4786 | high | modeling |
| CVE-2026-4878 | high | network-costs, agent, cluster-controller, modeling |
| CVE-2026-6100 | high | modeling |
| GHSA-hwqm-qvj9-4jr2 | high | cost-model |
| GHSA-pcgw-qcv5-h8ch | high | cost-model |
| GHSA-q382-vc8q-7jhj | high | cost-model |
Medium
| CVE ID | Severity | Affected Images |
|---|---|---|
| CVE-2023-30571 | medium | modeling, frontend, network-costs, agent, cost-model |
| CVE-2023-45803 | medium | cost-model |
| CVE-2024-29040 | medium | cost-model |
| CVE-2025-11468 | medium | modeling, cost-model |
| CVE-2025-12781 | medium | modeling, cost-model |
| CVE-2025-13034 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2025-13837 | medium | cost-model, modeling |
| CVE-2025-14017 | medium | agent, cost-model, modeling, frontend, network-costs |
| CVE-2025-14087 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2025-14512 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2025-14831 | medium | agent |
| CVE-2025-15282 | medium | cost-model, modeling |
| CVE-2025-23419 | medium | frontend |
| CVE-2025-4516 | medium | cost-model, modeling |
| CVE-2025-50181 | medium | cost-model, modeling |
| CVE-2025-50182 | medium | cost-model, modeling |
| CVE-2025-5278 | medium | network-costs, agent, cost-model, cluster-controller, modeling, frontend |
| CVE-2025-6069 | medium | modeling |
| CVE-2025-60753 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2025-61730 | medium | cost-model |
| CVE-2025-68972 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-0672 | medium | cost-model, modeling |
| CVE-2026-0865 | medium | modeling |
| CVE-2026-0990 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-1484 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-1489 | medium | network-costs, agent, cost-model, modeling, frontend |
| CVE-2026-1502 | medium | modeling, cost-model |
| CVE-2026-1757 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-1965 | medium | agent, cost-model, modeling, frontend, network-costs |
| CVE-2026-2100 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-22185 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-25645 | medium | cost-model, modeling |
| CVE-2026-27142 | medium | cost-model |
| CVE-2026-27456 | medium | agent, cost-model, modeling, frontend, network-costs |
| CVE-2026-28386 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-28390 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-28684 | medium | modeling |
| CVE-2026-29111 | medium | network-costs, agent, cost-model, modeling |
| CVE-2026-31790 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-32282 | medium | agent, cost-model, cluster-controller |
| CVE-2026-32284 | medium | cost-model, modeling |
| CVE-2026-32288 | medium | agent, cost-model, cluster-controller |
| CVE-2026-32289 | medium | cluster-controller, agent, cost-model |
| CVE-2026-32776 | medium | modeling, frontend, network-costs, cost-model |
| CVE-2026-32777 | medium | frontend, network-costs, cost-model, modeling |
| CVE-2026-32778 | medium | cost-model, modeling, frontend, network-costs |
| CVE-2026-34743 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-35206 | medium | cluster-controller |
| CVE-2026-3644 | medium | cost-model, modeling |
| CVE-2026-3783 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-3784 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-3805 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-3833 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-40355 | medium | agent, cost-model, modeling, frontend, network-costs |
| CVE-2026-4046 | medium | agent, cost-model, cluster-controller, modeling, frontend, network-costs |
| CVE-2026-4105 | medium | agent, cost-model, modeling, frontend, network-costs |
| CVE-2026-41989 | medium | agent, cost-model, modeling, frontend, network-costs |
| CVE-2026-4224 | medium | cost-model, modeling |
| CVE-2026-4426 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-4437 | medium | frontend, network-costs, agent, cost-model, cluster-controller, modeling |
| CVE-2026-4873 | medium | modeling, frontend, network-costs, agent, cost-model |
| CVE-2026-5121 | medium | agent, modeling, network-costs |
| CVE-2026-5435 | medium | frontend, network-costs, agent, cost-model, cluster-controller, modeling |
| CVE-2026-5450 | medium | frontend, network-costs, agent, cost-model, cluster-controller, modeling |
| CVE-2026-5545 | medium | cost-model, modeling, frontend, network-costs, agent |
| CVE-2026-5713 | medium | cost-model, modeling |
| CVE-2026-5745 | medium | modeling, frontend, network-costs, agent, cost-model |
| CVE-2026-5773 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-5928 | medium | agent, cost-model, cluster-controller, modeling, frontend, network-costs |
| CVE-2026-6019 | medium | cost-model, modeling |
| CVE-2026-6253 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-6429 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-6732 | medium | frontend, network-costs, agent, cost-model, modeling |
| GHSA-xmrv-pmrh-hhx2 | medium | agent, cost-model |
Low
| CVE ID | Severity | Affected Images |
|---|---|---|
| CVE-2021-3572 | low | cost-model |
| CVE-2022-27943 | low | frontend, network-costs, agent, cost-model, cluster-controller, modeling |
| CVE-2022-3219 | low | agent, cost-model, modeling, frontend, network-costs |
| CVE-2022-41409 | low | frontend, network-costs, agent, cost-model, cluster-controller, modeling |
| CVE-2023-32636 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2023-4156 | low | modeling, frontend, network-costs, agent, cost-model |
| CVE-2023-45322 | low | agent, cost-model, modeling, frontend, network-costs |
| CVE-2023-50495 | low | agent, cost-model, cluster-controller, modeling, frontend, network-costs |
| CVE-2023-5752 | low | cost-model |
| CVE-2024-0232 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2024-11053 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2024-13176 | low | network-costs, agent, cost-model, modeling, frontend |
| CVE-2024-25260 | low | cost-model |
| CVE-2024-34459 | low | frontend, network-costs, agent, cost-m... |
v3.1.6
UI fixes
-
Fix an issue where calls to
/model/multi-cluster-diagnostics-enabledwhich returned errors were not handled. Error response are now assumed to mean “not enabled”, preventing further wasted API calls. -
Fixed an issue where the wrong variable name for a piece of config was being used, causing several widgets on the Overview page and the entire Allocation Details page to simply not render.
-
Restored the presence of “Save” and “Test Connection” controls when creating a new Cloud Provider Integration. These had been erroneously removed when the ability to edit cloud providers did not ship.
Helm Chart Updates
-
Bump default version of the network-costs image referenced in Helm chart, eliminating CVEs that were discovered in the base image after it was published. v0.18.2 -> v0.18.3
-
Bump the default version of the cluster-controller image referenced in the Helm chart, eliminating CVEs that were discovered in the base image after it was published. v0.16.32 -> v0.16.34
-
Bump the default version of the kubecost-modeling image referenced in the Helm chart, eliminating CVEs that were discovered in the base image after it was published. v0.1.34 -> v0.1.35
-
Bump default version of the ibm-finops-agent Helm chart v1.0.14 -> 1.0.15.
Known caveats
(Added approximately 20 minutes post-release)
While the target version of network-costs (v0.18.3) does resolve a number of CVEs, it still contains two which are rated HIGH by NIST. Namely:
CVE-2026-27135 is present in the latest version of our upstream base image and we're working on a resolution. CVE-2026-4111 has been resolved in a newer version of the upstream base image, but it is replaced by CVE-2026-4424 in the same library, which holds an equivalent severity rating.
We will publish a patch with resolutions to these issues when we are able.
Image List
- icr.io/kubecost/network-costs:v0.18.3
- icr.io/ibm-finops/agent:v1.0.15
- icr.io/kubecost/cost-model:3.1.6
- icr.io/kubecost/cluster-controller:v0.16.34
- icr.io/kubecost/modeling:v0.1.35
- icr.io/kubecost/frontend:3.1.6
- docker.io/alpine/curl:8.17.0
Helm Chart Security Comparison: v3.1.5 to v3.1.6
CVE by Severity
| Severity | Count | Prev Count | Difference |
|---|---|---|---|
| critical | 3 | 6 | -3 |
| high | 28 | 42 | -14 |
| medium | 157 | 197 | -40 |
| low | 202 | 236 | -34 |
Unchanged CVEs
Critical
| CVE ID | Severity | Affected Images |
|---|---|---|
| CVE-2025-68121 | critical | cost-model |
| CVE-2026-33186 | critical | agent, cost-model |
High
| CVE ID | Severity | Affected Images |
|---|---|---|
| CVE-2025-61726 | high | cost-model |
| CVE-2025-61728 | high | cost-model |
| CVE-2026-23949 | high | modeling |
| CVE-2026-24049 | high | modeling |
| CVE-2026-24051 | high | agent, cost-model |
| CVE-2026-25679 | high | cost-model |
| CVE-2026-27135 | high | modeling, frontend, network-costs, agent, cost-model |
| CVE-2026-27896 | high | cost-model |
| CVE-2026-33252 | high | cost-model |
| CVE-2026-33487 | high | cost-model |
| CVE-2026-4111 | high | network-costs, agent |
| CVE-2026-4424 | high | network-costs, agent, cost-model, modeling, frontend |
| CVE-2026-4519 | high | cost-model, modeling |
| GHSA-hwqm-qvj9-4jr2 | high | cost-model |
| GHSA-pcgw-qcv5-h8ch | high | cost-model |
| GHSA-q382-vc8q-7jhj | high | cost-model |
Medium
| CVE ID | Severity | Affected Images |
|---|---|---|
| CVE-2023-30571 | medium | modeling, frontend, network-costs, agent, cost-model |
| CVE-2023-45803 | medium | cost-model |
| CVE-2024-29040 | medium | cost-model |
| CVE-2025-11468 | medium | cost-model, modeling |
| CVE-2025-12781 | medium | cost-model, modeling |
| CVE-2025-13837 | medium | modeling, cost-model |
| CVE-2025-14017 | medium | network-costs, agent, cost-model, modeling, frontend |
| CVE-2025-14087 | medium | cost-model, modeling, frontend, network-costs, agent |
| CVE-2025-14512 | medium | agent, cost-model, modeling, frontend, network-costs |
| CVE-2025-14831 | medium | agent |
| CVE-2025-15282 | medium | cost-model, modeling |
| CVE-2025-23419 | medium | frontend |
| CVE-2025-4516 | medium | cost-model, modeling |
| CVE-2025-50181 | medium | cost-model, modeling |
| CVE-2025-50182 | medium | modeling, cost-model |
| CVE-2025-5278 | medium | cost-model, cluster-controller, modeling, frontend, network-costs, agent |
| CVE-2025-6069 | medium | modeling |
| CVE-2025-60753 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2025-61730 | medium | cost-model |
| CVE-2025-68972 | medium | network-costs, agent, cost-model, modeling, frontend |
| CVE-2026-0672 | medium | cost-model, modeling |
| CVE-2026-0865 | medium | modeling |
| CVE-2026-0990 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-1484 | medium | network-costs, agent, cost-model, modeling, frontend |
| CVE-2026-1489 | medium | agent, cost-model, modeling, frontend, network-costs |
| CVE-2026-1757 | medium | cost-model, modeling, frontend, network-costs, agent |
| CVE-2026-1965 | medium | network-costs, agent, cost-model, modeling, frontend |
| CVE-2026-2100 | medium | agent, cost-model, modeling, frontend, network-costs |
| CVE-2026-22185 | medium | network-costs, agent, cost-model, modeling, frontend |
| CVE-2026-25645 | medium | modeling, cost-model |
| CVE-2026-27142 | medium | cost-model |
| CVE-2026-29111 | medium | modeling, frontend, network-costs, agent, cost-model |
| CVE-2026-32284 | medium | cost-model, modeling |
| CVE-2026-32776 | medium | network-costs, cost-model, modeling, frontend |
| CVE-2026-32777 | medium | network-costs, cost-model, modeling, frontend |
| CVE-2026-32778 | medium | modeling, frontend, network-costs, cost-model |
| CVE-2026-3644 | medium | cost-model, modeling |
| CVE-2026-3783 | medium | network-costs, agent, cost-model, modeling, frontend |
| CVE-2026-3784 | medium | network-costs, agent, cost-model, modeling, frontend |
| CVE-2026-3805 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-4105 | medium | cost-model, modeling, frontend, network-costs, agent |
| CVE-2026-4224 | medium | cost-model, modeling |
| CVE-2026-4426 | medium | cost-model, modeling, frontend, network-costs, agent |
| CVE-2026-4437 | medium | cluster-controller, modeling, frontend, network-costs, agent, cost-model |
| CVE-2026-5121 | medium | cost-model, modeling, frontend, network-costs, agent |
Low
| CVE ID | Severity | Affected Images |
|---|---|---|
| CVE-2021-3572 | low | cost-model |
| CVE-2022-27943 | low | modeling, frontend, network-costs, agent, cost-model, cluster-controller |
| CVE-2022-3219 | low | network-costs, agent, cost-model, modeling, frontend |
| CVE-2022-41409 | low | frontend, network-costs, agent, cost-model, cluster-controller, modeling |
| CVE-2023-32636 | low | network-costs, agent, cost-model, modeling, frontend |
| CVE-2023-4156 | low | network-costs, agent, cost-model, modeling, frontend |
| CVE-2023-45322 | low | network-costs, agent, cost-model, modeling, frontend |
| CVE-2023-50495 | low | cost-model, cluster-controller, modeling, frontend, network-costs, agent |
| CVE-2023-5752 | low | cost-model |
| CVE-2024-0232 | low | network-costs, agent, cost-model, modeling, frontend |
| CVE-2024-11053 | low | network-costs, agent, cost-model, modeling, frontend |
| CVE-2024-13176 | low | network-costs, agent, cost-model, modeling, frontend |
| CVE-2024-25260 | low | cost-model |
| CVE-2024-34459 | low | network-costs, agent, cost-model, modeling, frontend |
| CVE-2024-41996 | low | network-costs, agent, cost-model, modeling, frontend |
| CVE-2024-7264 | low | network-costs, agent, cost-model, modeling, frontend |
| CVE-2024-9681 | low | network-costs, agent, cost-model, modeling, frontend |
| CVE-2025-13151 | low | cost-model, modeling, frontend, network-costs, agent |
| CVE-2025-1371 | low | cost-model |
| CVE-2025-1376 | low | cost-model |
| CVE-2025-1377 | low | cost-model |
| CVE-2025-1632 | low | network-costs, agent, cost-model, modeling, frontend |
| CVE-2025-1795 | low | cost-model |
| CVE-2025-27113 | low | network-costs, agent, cost-model, modeling, frontend |
| CVE-2025-30258 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2025-3360 | low | network-costs, agent, cost-model, modeling, frontend |
| CVE-2025-53859 | low | frontend |
| CVE-2025-5915 | low | cost-model, modeling, frontend, network-costs, agent |
| CVE-2025-5916 | low | network-costs, agent, cost-model, modeling, frontend |
| CVE-2025-5917 | low | network-costs, agent, cost-model, modeling, frontend |
| CVE-2025-5918 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2025-6075 | low | modeling |
| CVE-2025-6170 | low | cost-model, modeling, frontend, network-costs, agent |
| CVE-2025-66382 | low | network-costs, cost-model, modeling, frontend |
| CVE-2025-7039 | low | network-costs, agent, cost-model, modeling, frontend |
| CVE-2025-70873 | low | cost-model, modeling, frontend, network-costs, agent |
| CVE-2025-9232 | low | network-costs, agent, cost-model, modeling, frontend |
| CVE-2025-9820 | low | agent |
| CVE-2026-0988 | low | modeling, frontend, network-costs, agent, cost-model |
| CVE-2026-0989 | low | network-costs, agent, cost-model, modeling, frontend |
| CVE-2026-0992 | low | network-costs, agent, c... |
v3.1.5
What's Changed
- Add storage lookback time for heartbeat and diagnostics files to speed up initial ingestion
Image List
- icr.io/kubecost/network-costs:v0.18.2
- icr.io/ibm-finops/agent:v1.0.14
- icr.io/kubecost/cost-model:3.1.5
- icr.io/kubecost/cluster-controller:v0.16.32
- icr.io/kubecost/modeling:v0.1.34
- icr.io/kubecost/frontend:3.1.5
- docker.io/alpine/curl:8.14.1
Helm Chart Security Comparison: v3.1.4 to v3.1.5
CVE by Severity
| Severity | Count | Prev Count | Difference |
|---|---|---|---|
| critical | 3 | 3 | +0 |
| high | 16 | 16 | +0 |
| medium | 124 | 124 | +0 |
| low | 212 | 212 | +0 |
Unchanged CVEs
Critical
| CVE ID | Severity | Affected Images |
|---|---|---|
| CVE-2025-68121 | critical | cost-model, cluster-controller |
High
| CVE ID | Severity | Affected Images |
|---|---|---|
| CVE-2025-15467 | high | modeling, curl, network-costs |
| CVE-2025-61726 | high | cluster-controller, cost-model |
| CVE-2025-61728 | high | cost-model, cluster-controller |
| CVE-2025-68973 | high | network-costs, modeling |
| CVE-2025-69419 | high | network-costs, modeling, curl |
| CVE-2026-23949 | high | modeling |
| CVE-2026-24049 | high | modeling |
| CVE-2026-24051 | high | agent, cost-model, cluster-controller |
| CVE-2026-27896 | high | cost-model |
Medium
| CVE ID | Severity | Affected Images |
|---|---|---|
| CVE-2023-30571 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2023-45803 | medium | cost-model |
| CVE-2024-29040 | medium | cost-model |
| CVE-2024-58251 | medium | curl |
| CVE-2025-11187 | medium | modeling, curl, network-costs |
| CVE-2025-11468 | medium | cost-model, modeling |
| CVE-2025-12084 | medium | modeling |
| CVE-2025-12781 | medium | cost-model, modeling |
| CVE-2025-13601 | medium | network-costs, modeling |
| CVE-2025-13836 | medium | modeling |
| CVE-2025-13837 | medium | cost-model, modeling |
| CVE-2025-14017 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2025-14087 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2025-14104 | medium | cost-model, modeling, frontend, network-costs, agent |
| CVE-2025-14512 | medium | network-costs, agent, cost-model, modeling, frontend |
| CVE-2025-15282 | medium | cost-model, modeling |
| CVE-2025-15366 | medium | modeling, cost-model |
| CVE-2025-15367 | medium | cost-model, modeling |
| CVE-2025-23419 | medium | frontend |
| CVE-2025-4516 | medium | modeling, cost-model |
| CVE-2025-50181 | medium | cost-model, modeling |
| CVE-2025-50182 | medium | cost-model, modeling |
| CVE-2025-5278 | medium | agent, cost-model, cluster-controller, modeling, frontend, network-costs |
| CVE-2025-6069 | medium | modeling |
| CVE-2025-60753 | medium | agent, cost-model, modeling, frontend, network-costs |
| CVE-2025-61730 | medium | cost-model, cluster-controller |
| CVE-2025-62408 | medium | curl |
| CVE-2025-68972 | medium | modeling, frontend, network-costs, agent, cost-model |
| CVE-2025-9086 | medium | network-costs, modeling |
| CVE-2026-0672 | medium | cost-model, modeling |
| CVE-2026-0865 | medium | cost-model, modeling |
| CVE-2026-0915 | medium | agent, cost-model, cluster-controller, modeling, frontend, network-costs |
| CVE-2026-0990 | medium | modeling, frontend, network-costs, agent, cost-model |
| CVE-2026-1299 | medium | cost-model, modeling |
| CVE-2026-1484 | medium | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-1489 | medium | cost-model, modeling, frontend, network-costs, agent |
| CVE-2026-1757 | medium | cost-model, modeling, frontend, network-costs, agent |
| CVE-2026-22185 | medium | modeling, frontend, network-costs, agent, cost-model |
| CVE-2026-27199 | medium | modeling |
Low
| CVE ID | Severity | Affected Images |
|---|---|---|
| CVE-2021-3572 | low | cost-model |
| CVE-2022-27943 | low | frontend, network-costs, agent, cost-model, cluster-controller, modeling |
| CVE-2022-3219 | low | network-costs, agent, cost-model, modeling, frontend |
| CVE-2022-41409 | low | frontend, network-costs, agent, cost-model, cluster-controller, modeling |
| CVE-2023-32636 | low | modeling, frontend, network-costs, agent, cost-model |
| CVE-2023-4156 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2023-45322 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2023-50495 | low | agent, cost-model, cluster-controller, modeling, frontend, network-costs |
| CVE-2023-5752 | low | cost-model |
| CVE-2024-0232 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2024-11053 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2024-13176 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2024-25260 | low | cost-model |
| CVE-2024-34459 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2024-41996 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2024-7264 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2024-9681 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2025-13151 | low | agent, cost-model, modeling, frontend, network-costs |
| CVE-2025-1371 | low | cost-model |
| CVE-2025-1376 | low | cost-model |
| CVE-2025-1377 | low | cost-model |
| CVE-2025-15281 | low | frontend, network-costs, agent, cost-model, cluster-controller, modeling |
| CVE-2025-15468 | low | curl, network-costs, modeling |
| CVE-2025-15469 | low | modeling, curl, network-costs |
| CVE-2025-1632 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2025-1795 | low | cost-model |
| CVE-2025-27113 | low | modeling, frontend, network-costs, agent, cost-model |
| CVE-2025-30258 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2025-3360 | low | agent, cost-model, modeling, frontend, network-costs |
| CVE-2025-46394 | low | curl |
| CVE-2025-53859 | low | frontend |
| CVE-2025-5915 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2025-5916 | low | agent, cost-model, modeling, frontend, network-costs |
| CVE-2025-5917 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2025-5918 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2025-6075 | low | modeling |
| CVE-2025-6170 | low | agent, cost-model, modeling, frontend, network-costs |
| CVE-2025-66199 | low | curl, network-costs, modeling |
| CVE-2025-66382 | low | network-costs, cost-model, modeling, frontend |
| CVE-2025-68160 | low | curl, network-costs, modeling |
| CVE-2025-69418 | low | modeling, curl, network-costs |
| CVE-2025-69420 | low | curl, network-costs, modeling |
| CVE-2025-69421 | low | curl, network-costs, modeling |
| CVE-2025-7039 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2025-9232 | low | modeling, frontend, network-costs, agent, cost-model |
| CVE-2025-9820 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-0861 | low | cluster-controller, modeling, frontend, network-costs, agent, cost-model |
| CVE-2026-0988 | low | cost-model, modeling, frontend, network-costs, agent |
| CVE-2026-0989 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-0992 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-1485 | low | agent, cost-model, modeling, frontend, network-costs |
| CVE-2026-22795 | low | curl, network-costs, modeling |
| CVE-2026-22796 | low | curl, network-costs, modeling |
| CVE-2026-24515 | low | frontend, network-costs, cost-model, modeling |
| CVE-2026-24883 | low | frontend, network-costs, agent, cost-model, modeling |
| CVE-2026-27205 | low | modeling |
Added CVEs
No new vulnerabilities found.
Removed CVEs
No removed vulnerabilities found.
Full Changelog: v3.1.4...v3.1.5