CVE & Vulnerabilities · October 7, 2026
CVE-2026-105223 affects versions of the maclof kubernetes-client library before 0.32.0, where kubeconfig files missing certificate-authority-data cause TLS verification to silently fall back to insecure mode. That lets an attacker positioned on the network path pose as the Kubernetes API server, intercepting Bearer tokens or credentials and potentially altering REST or WebSocket traffic. Projects relying on this client should update promptly and audit their kubeconfig files for the missing field.
// source: nvd.nist.gov ↗