{"id":"CVE-2026-105223","summary":"maclof kubernetes-client 0.17.0 before 0.32.0 Disabled TLS Certificate Verification","details":"maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data, ignoring insecure-skip-tls-verify. On-path attackers can impersonate the Kubernetes API server to capture Bearer tokens or Basic credentials and tamper with WebSocket or REST API traffic.","modified":"2026-10-06T02:47:20.980645105Z","published":"2026-10-05T00:44:17.374Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105223.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-295"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105223.json"},{"type":"ADVISORY","url":"https://github.com/maclof/kubernetes-client/releases/tag/0.32.0"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105223"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/maclof-kubernetes-client-0.17.0-before-0.32.0-disabled-tls-certificate-verification"},{"type":"REPORT","url":"https://github.com/maclof/kubernetes-client/issues/135"},{"type":"FIX","url":"https://github.com/maclof/kubernetes-client/commit/924c0b935fa538ed6b4b0948127609e99d0e6f34"},{"type":"PACKAGE","url":"https://github.com/maclof/kubernetes-client"},{"type":"ARTICLE","url":"https://github.com/maclof/kubernetes-client/blob/0.31.0/src/Client.php#L309-L312"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/maclof/kubernetes-client","events":[{"introduced":"029ad9d2e64380241af1069324e401e38741c0bc"},{"fixed":"924c0b935fa538ed6b4b0948127609e99d0e6f34"}],"database_specific":{"source":["AFFECTED_FIELD","DESCRIPTION","REFERENCES"],"extracted_events":[{"introduced":"0.17.0"},{"fixed":"0.32.0"}]}}],"versions":["0.31.0","0.30.0","0.29.0","0.28.0","0.27.0","0.26.0","0.25.0","0.24.0","0.23.0","0.22.0","0.21.0","0.20.0","0.19.0","0.18.3","0.18.2","0.18.1","0.18.0","0.17.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105223.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}