CVE-2025-64434 is a medium-severity vulnerability affecting KubeVirt versions prior to 1.5.3 and 1.6.1, a virtual machine management add-on for Kubernetes. An attacker who compromises a virt-handler instance can exploit shared credentials to impersonate virt-api, enabling privileged operations against other virt-handler instances. This could compromise the integrity and availability of managed VMs. The attack requires local access and high attack complexity, but can lead to high impact on integrity and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion beyond a single security update notice.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.3CPE matchmatch criteria | cpe:2.3:a:kubevirt:kubevirt:*:*:*:*:*:kubernetes:*:* | ||
1.6.0CPE matchmatch criteria | cpe:2.3:a:kubevirt:kubevirt:1.6.0:*:*:*:*:kubernetes:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing
Nov 11, 2025kubevirt: KubeVirt: API Identity Spoofing Vulnerability
Nov 7, 2025KubeVirt's Improper TLS Certificate Management Handling Allows API Identity Spoofing
Nov 6, 2025