Skip to content
Threat Feed
high advisory

TLS Verification Bypass in maclof kubernetes-client

The maclof kubernetes-client library versions 0.17.0 through 0.31.x fails to verify TLS certificates during kubeconfig parsing, enabling on-path attackers to perform MitM attacks to intercept credentials.

CVE search metadata

CVE search record: CVE-2026-105223. Severity: high. CVSS: 7.4. KEV: no. Product: kubernetes-client (0.17.0-0.31.x). Brief: TLS Verification Bypass in maclof kubernetes-client. Brief link: https://feed.craftedsignal.io/briefs/2026-10-105223/

The maclof kubernetes-client library (versions 0.17.0 through 0.31.x) contains a critical security flaw in the parseKubeconfig() and parseKubeconfigFile() functions. When a provided kubeconfig file lacks certificate-authority-data, the library fails to enforce TLS certificate verification, regardless of the insecure-skip-tls-verify setting. This behavior results in the library trusting any certificate presented by a remote server. An on-path attacker, such as a malicious actor on the local network or an upstream ISP, can perform a man-in-the-middle attack to intercept the connection between the application and the Kubernetes API server. This exposure allows for the theft of sensitive Bearer tokens or Basic authentication credentials and facilitates the manipulation of REST API or WebSocket traffic, potentially leading to unauthorized cluster control.

Impact

Successful exploitation allows for the interception of authentication secrets and full compromise of the communication channel between the client application and the Kubernetes API server. This can result in unauthorized access, data exfiltration, or modification of Kubernetes resources depending on the privileges of the compromised credentials.

Recommendation

Update the maclof kubernetes-client library to version 0.32.0 or later immediately to resolve the improper certificate validation logic. Audit all applications utilizing this library to identify existing instances that rely on kubeconfig files lacking certificate-authority-data.


Immediate actions

Upgrade maclof kubernetes-client to version 0.32.0 or later

Development Teams 48h

Mitigations

Upgrade maclof kubernetes-client to 0.32.0

immediate Development Teams

CVE-2026-105223