Description
maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data, ignoring insecure-skip-tls-verify. On-path attackers can impersonate the Kubernetes API server to capture Bearer tokens or Basic credentials and tamper with WebSocket or REST API traffic.
Published: 2026-10-05
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: Credential Theft
Action: Immediate Patch
AI Analysis

Impact

The maclof kubernetes-client library versions 0.17.0 through 0.31.99 disable TLS certificate verification in its kubeconfig parsing routines when the configuration lacks the certificate-authority-data field, and they also ignore the insecure-skip-tls-verify flag. This flaw allows an attacker who can observe or influence network traffic to impersonate the Kubernetes API server, tricking the client into trusting an invalid or malicious TLS certificate. The client will then authenticate with the API server and transmit bearer tokens or Basic credentials, which the attacker can capture. With those credentials, the attacker can read, write, or tamper with REST and WebSocket API traffic, effectively gaining the same permissions as the compromised token.

Affected Systems

The vulnerability affects the maclof:kubernetes-client package in all releases before 0.32.0, including version 0.17.0 up to 0.31.99. The client is used by any application or script that communicates with a Kubernetes cluster through this library, so any such application may be vulnerable if it relies on the affected package and a kubeconfig lacking a CA data field. All systems that import the library and use kubeconfigs that do not contain certificate-authority-data or that depend on the insecure-skip-tls-verify setting are at risk.

Risk and Exploitability

The CVSS score of 9.1 signals a high severity vulnerability. Because an EPSS score is not provided and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog, it does not appear to be actively exploited at this time. Nevertheless, the attack requires an on‑path or network intruder who can present a rogue TLS certificate or substitute the Kubernetes API server. Once this precondition is met, no user interaction is needed; the client will automatically trust the counterfeit server and supply credentials, giving the attacker full access to the cluster resources protected by those credentials. The combination of a high threat score and the low effort required to set up a man‑in‑the‑middle attack in environments where network segmentation is weak means the risk to affected systems is significant, especially in production clusters.

Generated by OpenCVE AI on October 5, 2026 at 02:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the kubernetes-client library to version 0.32.0 or newer, which restores proper TLS certificate verification in both parseKubeconfig() and parseKubeconfigFile()
  • Apply the upstream patch commit 924c0b9 locally or merge it into your codebase if an immediate library upgrade is not possible, ensuring the client aborts connections to untrusted TLS endpoints
  • Verify that all kubeconfig files used by the client contain a valid certificate-authority-data field and remove any insecure-skip-tls-verify configuration entries to enforce certificate validation

Generated by OpenCVE AI on October 5, 2026 at 02:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 01:00:00 +0000

Type Values Removed Values Added
Description maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data, ignoring insecure-skip-tls-verify. On-path attackers can impersonate the Kubernetes API server to capture Bearer tokens or Basic credentials and tamper with WebSocket or REST API traffic.
Title maclof kubernetes-client 0.17.0 before 0.32.0 Disabled TLS Certificate Verification
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.1, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-05T00:47:08.567Z

Reserved: 2026-10-04T13:04:00.479Z

Link: CVE-2026-105223

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T01:16:28.480

Modified: 2026-10-05T01:16:28.480

Link: CVE-2026-105223

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T03:00:14Z

Weaknesses
  • CWE-295

    Improper Certificate Validation