# CVE-2025-0426: Unauthenticated Kubelet Checkpoint API Could Lead to Node DoS

DevFeed: [CVE-2025-0426: Unauthenticated Kubelet Checkpoint API Could Lead to Node DoS](<https://devfeed.tech/articles/cve-2025-0426-unauthenticated-kubelet-checkpoint-api-could-lead-to-node-dos-14.md>)

Original publisher: [Read original article](<https://blog.abhimanyu-saharan.com/posts/cve-2025-0426-unauthenticated-kubelet-checkpoint-api-could-lead-to-node-dos>)

Author: Abhimanyu Saharan

Published: 2025-05-23T00:00:00Z

Content type: article

Language: en

Sources: [Abhimanyu Saharan](<https://devfeed.tech/sources/abhimanyu-s-blog.md>)

Topics: [bug](<https://devfeed.tech/topics/bug.md>), [API](<https://devfeed.tech/topics/api.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [api](<https://devfeed.tech/tags/api.md>), [bug](<https://devfeed.tech/tags/bug.md>), [cve](<https://devfeed.tech/tags/cve.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

This article describes CVE-2025-0426, a critical kubelet bug involving an unauthenticated /checkpoint API that could cause node denial of service. It covers detection, mitigation, and patching.

## Source excerpt

A critical kubelet bug exposes a DoS risk via the unauthenticated /checkpoint API. Learn how to detect, mitigate, and patch CVE-2025-0426.