Database/Container, Kubernetes & orchestration
Kubernetes C# client: Improper certificate validation in custom-CA mode enables MITM on the Kubernetes API connection
CVSS 6.8CVE-2025-9708Container, Kubernetes & orchestrationcurated
Impact
Improper certificate validation in custom-CA mode enables MITM on the Kubernetes API connection
Who can reach it
Unauthenticated network in a MITM position
What to do
Upgrade any internal tooling built on the C# client
References
Related entries
- regclient: registry credentials can leak to an attacker-controlled blob host via foreign blob URLsCVE-2026-49349 · regclient (foreign blob handling, external registry URLs)Medium
- containerd: CRI ExecSync I/O drain never times out, leaking goroutines until the OOM killer takes the runtimeCVE-2026-53495 · containerd CRI plugin (ExecSync I/O drain in container_execsync.go)Medium
- Kubernetes (kube-apiserver): A node can delete itself, and cascade-delete other objects, by adding an OwnerReferenceCVE-2025-5187 · Kubernetes (kube-apiserver)Medium
- JFrog Artifactory Helm chart: generated TLS private keys retained in rendered manifestsCVE-2026-66016 · JFrog Artifactory self-hosted Helm deployment (generated TLS private keys)Medium
- Kubernetes (kube-apiserver): Node address not verified when proxyingCVE-2022-3294 · Kubernetes (kube-apiserver)Medium
- Argo CD (Helm OCI repository credential logging): CREDENTIAL DISCLOSURE THROUGH THE LOG PIPELINE: Argo CD wrote theNCVD-2021-016-argo-cd-helm-oci-repository-cred · Argo CD (Helm OCI repository credential logging)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.