KubeCon + CloudNativeCon Europe

Why Isn't the Fix in My Container? Tracking CVE Propagation Across... Mor Weinberger & Lior Kaplan

25:07 · 23 Mar 2026 – 26 Mar 2026 · YouTube

About this talk

This talk covers the analysis of CVE remediation patterns across 10,000 open source projects, highlighting the significant delays in fixed vulnerabilities reaching downstream containers. The speakers, Mor Weinberger from Echo Security and Lior Kaplan from Kaplan Open Source, discuss how these delays create substantial security risks in Kubernetes environments. They present real metrics on the flow of CVE fixes across various ecosystem layers and the compounding effects of layered dependencies. The session also offers practical solutions, including automated patch backporting and in-place image patching with tools like Copa, equipping attendees with workflows to reduce mean time to resolution and enhance their vulnerability management strategies.