Kubernetes C# Client: improper certificate validation in custom CA mode may lead to man-in-the-middle attacks
Published Sep 16, 2025
6.8
MEDIUMCVSS 3.1
EPSS 0.31%
Description
A vulnerability exists in the Kubernetes C# client where the certificate validation logic accepts properly constructed certificates from any Certificate Authority (CA) without properly verifying the trust chain. This flaw allows a malicious actor to present a forged certificate and potentially intercept or manipulate communication with the Kubernetes API server, leading to possible man-in-the-middle attacks and API impersonation.
Affected products
-
- Version 0StatusaffectedConstraints<=17.0.13
- Version 17.0.14StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Kubernetes | Kubernetes CSharp Client | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Deploy the patch version of the Kubernetes C# client as soon as possible. Alternatively, move the CA certificates into the system trust store instead of specifying them in the kubeconfig file. Note: This approach may introduce new risks, as all processes on the system will begin to trust certificates signed by that CA. If you must use an affected version, you can disable custom CA and add the CA to the machine's trusted root.
References (5)
- http://www.openwall.com/lists/oss-security/2025/09/16/1
- https://github.com/advisories/GHSA-w7r3-mgwf-4mqq Advisory
- https://github.com/kubernetes/kubernetes/issues/134063 issue-tracking
- https://groups.google.com/g/kubernetes-security-announce/c/rLopt2Msvbw/m/rK6XeNw2CgAJ mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2025-9708
Change history (0)
No recorded changes yet.