GHSA-w7r3-mgwf-4mqq
GitHub Security Advisory
Kubernetes C# client accepts certificates from any CA without properly verifying the trust chain
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
A vulnerability exists in the Kubernetes C# client where the certificate validation logic accepts properly constructed certificates from any Certificate Authority (CA) without properly verifying the trust chain. This flaw allows a malicious actor to present a forged certificate and potentially intercept or manipulate communication with the Kubernetes API server, leading to possible man-in-the-middle attacks and API impersonation.
Affected Packages
NuGet
KubernetesClient
Affected versions:
0
(fixed in 17.0.14)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 18, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.