aws / aws/eks-distro

K8s Security: [Security Advisory] CVE-2025-9708: Kubernetes C# Client: improper certificate validation in custom CA mode may lead to man-in-the-middle attacks

Open
#4,107 0 comments 0 reactions 0 assignees View on GitHub
external kubernetes on-call security
Dominant language
Shell
Stars
1.5k
Forks
198
Avg merge
10h 46m
Merged PRs (30d)
28

Description

Go to [the Kubernetes group](https://groups.google.com/g/kubernetes-security-announce) to view the announcement.

Follow the on-call runbook to backport fixes to all supported versions.

Contributor guide

Open the contributing guide

Research direction

Start with the Kubernetes security announcement linked in the issue and the on-call runbook. Determine the required backport fixes for all supported versions; done means those backports are completed across every supported version.

Written by the indexing model from the issue text.

Assessment

Tech stack
csharp, kubernetes
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.