CVE-2026-105223
Received Received - Intake

TLS Certificate Verification Bypass in kubernetes-client

Vulnerability report for CVE-2026-105223, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: VulnCheck

Description

maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data, ignoring insecure-skip-tls-verify. On-path attackers can impersonate the Kubernetes API server to capture Bearer tokens or Basic credentials and tamper with WebSocket or REST API traffic.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
maclof kubernetes-client to 0.32.0 (exc)
maclof kubernetes-client 0.32.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the maclof kubernetes-client library versions 0.17.0 to 0.31.0. When a kubeconfig file lacks certificate-authority-data, the library disables TLS certificate verification in WebSocket connections. This allows on-path attackers to impersonate the Kubernetes API server, intercept credentials like Bearer tokens or Basic Auth, and manipulate API traffic.

Detection Guidance

Check if your kubernetes-client library version is between 0.17.0 and 0.31.0. Inspect kubeconfig files for missing certificate-authority-data fields. Monitor network traffic for unencrypted or unverified TLS connections during WebSocket operations like exec, attach, or logs.

Impact Analysis

Attackers can capture sensitive credentials such as Bearer tokens or Basic Auth details during WebSocket operations like exec, attach, port-forward, logs, and cp. They can also tamper with API traffic, leading to unauthorized actions within the Kubernetes cluster. Regular HTTP API calls remain unaffected.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements for data protection such as GDPR and HIPAA. Exposure of credentials and data interception may result in non-compliance with security and privacy standards.

Mitigation Strategies

Upgrade the kubernetes-client library to version 0.32.0 or later. Ensure all kubeconfig files include certificate-authority-data or explicitly set insecure-skip-tls-verify to false. Review and update any configurations relying on automatic TLS verification fallback.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105223. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart