CVE WATCH / VULNERABILITY DETAIL
CVE-2026-105223
HIGHCVSS 7.4NVD feed
Published 5 October 2026 · tracked since 5 October 2026
Description
maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data, ignoring insecure-skip-tls-verify. On-path attackers can impersonate the Kubernetes API server to capture Bearer toke
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-84169
- CVE-2026-13607
- CVE-2026-78371
- CVE-2026-105231 HIGH 7.3
- CVE-2026-105232 HIGH 7.3
- CVE-2026-105233 MEDIUM 6.3
- CVE-2026-105230 HIGH 7.3
- CVE-2026-105226 MEDIUM 4.7
- CVE-2026-105229 HIGH 7.3
- CVE-2026-105188 LOW 3.5