{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/maclof/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:maclof:kubernetes-client:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-105223"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["kubernetes-client (0.17.0-0.31.x)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["maclof"],"content_html":"\u003cp\u003eThe maclof kubernetes-client library (versions 0.17.0 through 0.31.x) contains a critical security flaw in the parseKubeconfig() and parseKubeconfigFile() functions. When a provided kubeconfig file lacks certificate-authority-data, the library fails to enforce TLS certificate verification, regardless of the insecure-skip-tls-verify setting. This behavior results in the library trusting any certificate presented by a remote server. An on-path attacker, such as a malicious actor on the local network or an upstream ISP, can perform a man-in-the-middle attack to intercept the connection between the application and the Kubernetes API server. This exposure allows for the theft of sensitive Bearer tokens or Basic authentication credentials and facilitates the manipulation of REST API or WebSocket traffic, potentially leading to unauthorized cluster control.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the interception of authentication secrets and full compromise of the communication channel between the client application and the Kubernetes API server. This can result in unauthorized access, data exfiltration, or modification of Kubernetes resources depending on the privileges of the compromised credentials.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the maclof kubernetes-client library to version 0.32.0 or later immediately to resolve the improper certificate validation logic. Audit all applications utilizing this library to identify existing instances that rely on kubeconfig files lacking certificate-authority-data.\u003c/p\u003e\n","date_modified":"2026-10-05T01:43:32Z","date_published":"2026-10-05T01:43:32Z","id":"https://feed.craftedsignal.io/briefs/2026-10-105223/","summary":"The maclof kubernetes-client library versions 0.17.0 through 0.31.x fails to verify TLS certificates during kubeconfig parsing, enabling on-path attackers to perform MitM attacks to intercept credentials.","title":"TLS Verification Bypass in maclof kubernetes-client","url":"https://feed.craftedsignal.io/briefs/2026-10-105223/"}],"language":"en","title":"CraftedSignal Threat Feed - Maclof","version":"https://jsonfeed.org/version/1.1"}