Miggo Logo

CVE-2025-9708: Kubernetes C# client accepts certificates from any CA without properly verifying the trust chain

6.8

CVSS Score
3.1

Basic Information

EPSS Score
0.0052%
Published
9/17/2025
Updated
9/17/2025
KEV Status
No
Technology
TechnologyC#

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
KubernetesClientnuget< 17.0.1417.0.14

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

* vuln*r**ility *xists in t** Ku**rn*t*s *# *li*nt w**r* t** **rti*i**t* v*li**tion lo*i* ****pts prop*rly *onstru*t** **rti*i**t*s *rom *ny **rti*i**t* *ut*ority (**) wit*out prop*rly v*ri*yin* t** trust ***in. T*is *l*w *llows * m*li*ious **tor to

Reasoning

No *n*lysis *v*il**l*