Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability
Published Sep 2, 2025
9.8
CRITICALCVSS 3.0
EPSS 0.65%
Description
Cockroach Labs cockroach-k8s-request-cert Empty Root Password Authentication Bypass Vulnerability. This vulnerability could allow remote attackers to bypass authentication on systems that use the affected version of the Cockroach Labs cockroach-k8s-request-cert container image.
The specific flaw exists within the configuration of the system shadow file. The issue results from a blank password setting for the root user. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-22195.
Affected products
-
Affected
- cockroachdb/cockroach-k8s-request-cert:latest
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Cockroach Labs | Cockroach-K8s-Request-Cert | unknown | Affected
|
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-26436 Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-25-855/ x_research-advisoryMitigationVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-26436 | Advisory | |
| https://www.zerodayinitiative.com/advisories/ZDI-25-855/ | x_research-advisoryMitigationVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data