GHSA-2gg8-85m5-8r2p
GitHub Security Advisory
Chaos Mesh's Chaos Controller Manager is Missing Authentication for Critical Function
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
The Chaos Controller Manager in Chaos Mesh exposes a GraphQL debugging server without authentication to the entire Kubernetes cluster, which provides an API to kill arbitrary processes in any Kubernetes pod, leading to cluster-wide denial of service.
Affected Packages
Go
github.com/chaos-mesh/chaos-mesh
Affected versions:
0
(fixed in 2.7.3)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: October 5, 2025 6:32 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.