PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105223 maclof CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-10-05T01:16:28.480Z and has not been modified since then. The vulnerability affects Kubernetes client deployments using versions between 0.17.0 and 0.32.0. On-path attackers can impersonate the Kubernetes API server to capture Bearer tokens or Basic credentials and tamper with WebSocket or REST API traffic due to disabled TLS certificate verification in certain scenarios. Defenders should assess their exposure and verify if TLS certificate verification is enforced in their configurations.

Vendor
maclof
Product
kubernetes-client
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-05
Original CVE updated
2026-10-05
Advisory published
2026-10-05
Advisory updated
2026-10-05

Who should care

Defenders responsible for Kubernetes client deployments, especially those using versions between 0.17.0 and 0.32.0, should assess their exposure and verify if TLS certificate verification is enforced in their configurations.

Why it matters

CVE-2026-105223 allows on-path attackers to impersonate the Kubernetes API server due to disabled TLS certificate verification in certain scenarios, impacting confidentiality and integrity.

  • On-path attackers can capture Bearer tokens or Basic credentials.
  • On-path attackers can tamper with WebSocket or REST API traffic.
  • Defenders need to verify exposure in Kubernetes client deployments.
  • Remediation priority is high for deployments using affected versions.

Technical summary

The maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data, ignoring insecure-skip-tls-verify. This allows on-path attackers to impersonate the Kubernetes API server, potentially capturing sensitive credentials and tampering with API traffic. Defenders should prioritize verifying exposure in Kubernetes client deployments, especially where TLS certificate verification is not enforced, and consider upgrading to version 0.32.0 or later.

Defensive priority

Defenders should prioritize verifying exposure in Kubernetes client deployments, especially where TLS certificate verification is not enforced.

Recommended defensive actions

  • Verify if Kubernetes client deployments in your environment use versions between 0.17.0 and 0.32.0.
  • Assess if TLS certificate verification is enforced in your Kubernetes client configurations.
  • Consider upgrading to version 0.32.0 or later of the Kubernetes client.
  • Review and update kubeconfig files to ensure certificate-authority-data is present.
  • Perform vulnerability scanning to identify potentially exposed assets.
  • Review monitoring and detection capabilities for signs of exploitation.
  • Document and track remediation progress for auditing purposes.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in maclof kubernetes-client 0.17.0 before 0.32.0, which disables TLS certificate verification under certain conditions. The vulnerability allows on-path attackers to impersonate the Kubernetes API server. Source confidence is based on official CVE and NVD records. Defenders should verify exposure in Kubernetes client deployments and review kubeconfig files to ensure certificate-authority-data is present. Evidence is limited to public CVE and NVD records.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105223 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105223

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105223 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105223

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.