CVE-2025-9708 describes a medium-severity vulnerability in the Kubernetes C# client, where improper certificate validation allows acceptance of forged certificates from any CA. This flaw enables potential man-in-the-middle attacks and API impersonation against the Kubernetes API server. The attack requires high complexity and user interaction, but could lead to high confidentiality and integrity impacts. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Kubernetes | Kubernetes CSharp Client | >= 0, <= 17.0.13CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Kubernetes C# client accepts certificates from any CA without properly verifying the trust chain
Sep 17, 2025Kubernetes C# Client: improper certificate validation in custom CA mode may lead to man-in-the-middle attacks
Kubernetes C# Client: improper certificate validation in custom CA mode may lead to man-in-the-middle attacks
Kubernetes C# Client: improper certificate validation in custom CA mode may lead to man-in-the-middle attacks
Kubernetes C# Client: improper certificate validation in custom CA mode may lead to man-in-the-middle attacks