Sceawere

Vulnerability Detail

CVE-2026-105223UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Insecure TLS Validation in maclof/kubernetes-client

Vulnerability Metadata

Severity
High
Score / CVSS
7.4
Creation Date
17h ago
Vendor
maclof
Product
kubernetes-client
Attack Type
Improper Certificate Validation
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data, ignoring insecure-skip-tls-verify. On-path attackers can impersonate the Kubernetes API server to capture Bearer tokens or Basic credentials and tamper with WebSocket or REST API traffic.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.4",
  "pubDate": "2026-10-05T01:16:28.480Z",
  "pubdate": "2026-10-05T01:16:28.480Z",
  "executiveSummary": "The maclof kubernetes-client library is susceptible to a critical TLS verification bypass vulnerability. This flaw arises when the library parses kubeconfig files that omit the 'certificate-authority-data' field, causing the client to implicitly disable TLS certificate validation regardless of the 'insecure-skip-tls-verify' configuration setting.\nThe vulnerability affects versions 0.17.0 through 0.32.0. By failing to authenticate the API server's identity, the client becomes vulnerable to man-in-the-middle (MITM) attacks where an on-path adversary can intercept and manipulate communication.\nSuccessful exploitation allows an attacker to impersonate the Kubernetes API server, facilitating the exfiltration of sensitive credentials, including Bearer tokens and Basic authentication headers. Furthermore, an attacker can perform unauthorized REST API operations or tamper with established WebSocket connections.\nThis vulnerability poses a significant risk to the integrity and confidentiality of Kubernetes cluster management activities, as it effectively removes the transport layer security guarantees required for safe administrative communication. No special authentication is required for an attacker to initiate this exploitation if they possess network positioning to intercept traffic between the client and the API server.",
  "technicalDetails": "The vulnerability is located within the parsing logic of the maclof kubernetes-client library, specifically within the 'parseKubeconfig()' and 'parseKubeconfigFile()' functions. The root cause is a flaw in the TLS configuration initialization sequence. When the library encounters a kubeconfig file that lacks the 'certificate-authority-data' parameter, it defaults to a state where TLS certificate verification is entirely disabled.\nCrucially, this insecure default behavior overrides the user's intent as expressed by the 'insecure-skip-tls-verify' flag. Even if a user explicitly intends for verification to be enabled or remains unaware of the missing configuration, the library proceeds without validating the authenticity of the server's X.509 certificate.\nThe attack flow relies on an on-path position, such as a malicious proxy, compromised router, or ARP poisoning within the network segment connecting the client to the Kubernetes API server. When the victim client attempts to connect, the attacker presents a self-signed or fraudulent certificate for the Kubernetes API endpoint. Because the library fails to perform proper validation, it accepts the attacker's certificate without error or warning.\nOnce the encrypted tunnel is established with the attacker rather than the legitimate API server, the adversary can inspect the decrypted traffic. This allows for the capture of sensitive authentication materials, including Bearer tokens used for authentication and Authorization headers containing Basic credentials. The attacker can then utilize these credentials to authenticate against the legitimate API server with the victim's privileges.\nFurthermore, the attacker can facilitate protocol-level tampering. By proxying the traffic, the attacker can inject malicious payloads into REST API requests or manipulate WebSocket data streams (e.g., executing arbitrary commands in 'exec' or 'attach' sessions). This results in full compromise of the client-side session, enabling the attacker to perform arbitrary cluster operations or deploy malicious workloads. The vulnerability exists until the affected versions are remediated, and it is independent of the server-side configuration, as the failure occurs entirely within the client-side implementation of the TLS handshake procedure."
}
CVE-2026-105223: Insecure TLS Validation in maclof/kubernetes-client (HIGH Severity, CVSS: 7.4) | Sceawere