GPU VulnDB

Database/Container, Kubernetes & orchestration

maclof kubernetes-client: kubeconfig without CA data silently disables API server certificate verification

CVSS 9.1CVE-2026-105223Container, Kubernetes & orchestrationcurated

Impact

Any tooling built on this PHP Kubernetes client that loads a kubeconfig lacking certificate-authority-data ends up with certificate verification off, and the explicit insecure-skip-tls-verify setting is ignored - so an operator who believes they configured strict verification does not get it. An on-path attacker between the tool and the API server can impersonate the apiserver, capture the Bearer token or Basic credentials the client presents, and tamper with REST and WebSocket traffic. Those credentials are usually a service account or admin context for the cluster that schedules GPU work, so the payoff is cluster-level, not tool-level. Exploitation needs a position on the network path, which is why the vector is scored high attack complexity.

Who can reach it

Network attacker in an on-path position between the client and the Kubernetes API server. No authentication needed; the client itself hands over its credentials to whatever certificate is presented.

What to do

Upgrade the maclof/kubernetes-client dependency to 0.32.0 or later and redeploy the consuming service. Also audit kubeconfigs used by that tooling for missing certificate-authority-data, since that is the condition that triggers the unsafe path. This is an application dependency bump and restart - no node or cluster maintenance window.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.