CVE-2026-105223
CRITICAL
9,1
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH
7,4
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: none
Description
AI Translation Available
maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data, ignoring insecure-skip-tls-verify. On-path attackers can impersonate the Kubernetes API server to capture Bearer tokens or Basic credentials and tamper with WebSocket or REST API traffic.
295
Improper Certificate Validation
DraftCommon Consequences
Security Scopes Affected:
Integrity
Authentication
Potential Impacts:
Bypass Protection Mechanism
Gain Privileges Or Assume Identity
Applicable Platforms
Technologies:
Not Technology-Specific, Web Based, Mobile
https://github.com/maclof/kubernetes-client
https://github.com/maclof/kubernetes-client/blob/0.31.0/src/Client.php#L309-L312
https://github.com/maclof/kubernetes-client/commit/924c0b935fa538ed6b4b09481276…
https://github.com/maclof/kubernetes-client/issues/135
https://github.com/maclof/kubernetes-client/releases/tag/0.32.0
https://www.vulncheck.com/advisories/maclof-kubernetes-client-0.17.0-before-0.3…