Loading HuntDB...

GHSA-w7r3-mgwf-4mqq

GitHub Security Advisory

Kubernetes C# client accepts certificates from any CA without properly verifying the trust chain

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

A vulnerability exists in the Kubernetes C# client where the certificate validation logic accepts properly constructed certificates from any Certificate Authority (CA) without properly verifying the trust chain. This flaw allows a malicious actor to present a forged certificate and potentially intercept or manipulate communication with the Kubernetes API server, leading to possible man-in-the-middle attacks and API impersonation.

Affected Packages

NuGet KubernetesClient
Affected versions: 0 (fixed in 17.0.14)

Related CVEs

Key Information

GHSA ID
GHSA-w7r3-mgwf-4mqq
Published
September 17, 2025 12:31 AM
Last Modified
September 17, 2025 7:07 PM
CVSS Score
5.0 /10
Primary Ecosystem
NuGet
Primary Package
KubernetesClient
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 18, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.