Description

A vulnerability exists in the Kubernetes C# client where the certificate validation logic accepts properly constructed certificates from any Certificate Authority (CA) without properly verifying the trust chain. This flaw allows a malicious actor to present a forged certificate and potentially intercept or manipulate communication with the Kubernetes API server, leading to possible man-in-the-middle attacks and API impersonation.

INFO

Published Date :

2025-09-16T21:08:05.189Z

Last Modified :

2025-11-04T21:15:23.948Z

Source :

kubernetes
AFFECTED PRODUCTS

The following products are affected by CVE-2025-9708 vulnerability.

Vendors Products
Kubernetes
  • Kubernetes

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact