https://seclists.org/oss-sec/2025/q3/169: [kubernetes] CVE-2025-9708: Kubernetes C# Client: improper certificate validation in custom CA mode may lead to man-in-the-middle attacks
Published Sep 16, 2025
·Updated
Affected Software
1 affected component
Kubernetes C# Client<next release
Frequently Asked Questions
1
What is the severity of CVE-2025-9708?
The severity of CVE-2025-9708 is classified as high due to the potential for man-in-the-middle attacks.
2
How do I fix CVE-2025-9708?
To fix CVE-2025-9708, ensure that proper certificate validation is implemented within the Kubernetes C# client.
3
What impact does CVE-2025-9708 have on security?
CVE-2025-9708 can lead to unauthorized access and data interception due to improper certificate validation.
4
Is there a patch available for CVE-2025-9708?
Yes, a patch for CVE-2025-9708 should be available in the latest release of the Kubernetes C# client.
5
Who is affected by CVE-2025-9708?
Users of the Kubernetes C# client utilizing custom CA mode are affected by CVE-2025-9708.