External risk intelligence

Kubernetes Client TLS Verification Bypass Affects Authentication and Traffic Integrity

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-105223

This vulnerability exists within a developer-focused Kubernetes client library. It is used by applications to interact with Kubernetes APIs, typically in internal automation, build-time processes, or backend service-to-service communication. It is not an internet-facing service or appliance, and standard deployments of such client libraries do not expose this functionality to the public internet.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory addresses a security flaw in a Kubernetes client library that could allow attackers to impersonate the Kubernetes API server. This allows them to intercept sensitive credentials and tamper with traffic, potentially impacting the confidentiality and integrity of communications with your Kubernetes environment.

  • Client flaw bypasses security checks.
  • Attackers can steal credentials and alter data.
  • Confirm relevance to your Kubernetes interactions.

Attack Path

How an attacker could exploit the issue

An attacker on the same network could impersonate the Kubernetes API server by exploiting a flaw in how the Kubernetes client handles TLS certificate verification. This allows the attacker to intercept and tamper with sensitive traffic, potentially capturing authentication tokens or credentials.

  • Network access is required.
  • TLS verification is skipped.
  • Token theft and traffic tampering.

Live Threat

Current exploitation, exposure, and threat context

On-path attackers can impersonate the Kubernetes API server when TLS certificate verification is improperly disabled in the `maclof/kubernetes-client` library. This could allow them to intercept sensitive authentication credentials, such as Bearer tokens or Basic credentials, and potentially tamper with API traffic.

  • Kubernetes API server traffic.
  • Attackers can intercept credentials.
  • Sensitive data exposure and traffic tampering.

Operational Fix

Recommended remediation, mitigation, and detection steps

Teams responsible for applications using the Kubernetes client library should investigate its presence and identify accountable owners. The first practical step is to locate where this library is deployed, determine its reachability and criticality, and then plan remediation based on the assessed risk, potentially involving vendor coordination or temporary risk reduction measures.

  • Application owners should own this issue.
  • Verify library usage and exposure.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is maclof kubernetes-client?

It is a software library for PHP developers designed to simplify interactions with the Kubernetes API. By using this tool, applications can programmatically manage cluster resources, deploy services, or automate infrastructure tasks. It acts as a bridge between your custom application code and the Kubernetes control plane, handling the underlying network requests and authentication protocols required to send commands to a cluster.

What does CVE-2026-105223 mean for TLS security?

This vulnerability involves a flaw in how the library validates digital certificates, classified as Improper Certificate Validation (CWE-295). When specific configuration data is missing, the library fails to verify the identity of the server it is connecting to. This removes the security guardrails that typically prevent a system from trusting a malicious or fraudulent server, essentially allowing an attacker to pose as the legitimate Kubernetes API server.

How does an attacker trigger this vulnerability?

An attacker must be positioned on the same network path between the client application and the Kubernetes API server. This is commonly known as an on-path or man-in-the-middle position. It is important to note that simply having the library installed does not trigger the flaw; the bug only manifests when the application uses a kubeconfig file that specifically lacks a certificate authority data field.

Is my application at risk according to Halo Surface Signal?

Halo Surface Signal indicates that this risk is very unlikely to be internet-facing. Because this is a developer library embedded within applications, it typically operates inside private backend systems, internal automation, or build pipelines rather than serving public web traffic. You should focus your investigation on internal services that manage or communicate with your Kubernetes clusters.

Do I need to update my software to fix this?

The first step is to perform an inventory of your applications to identify which services rely on the affected library. Once identified, evaluate the risk based on where those applications run and what credentials they handle. Remediation involves coordinating with your development teams to update to version 0.32.0 or later, which restores the necessary TLS security verification checks.

References