CVE-2025-9708
MediumAdvisory
Published 17 Sept 2025In the index since 8 Sept 2026
- Severity
- Medium
- worst across findings
- CVSS
- 6.8
- base score, highest
- EPSS
- 0.003
- 24th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 7
- of 17,781 indexed, latest versions
- Container images
- 7
- deployed by those charts
- Fix available
- 1 of 1
- affected package
Kubernetes C# client accepts certificates from any CA without properly verifying the trust chain
Carried by container images the latest versions of 7 of 17,781 indexed charts deploy, on 7 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| KubernetesClientnuget | 4.0.26, 6.0.1, 10.0.31, 11.0.44+1 more | 17.0.14 | 7 |
- OSV records
- GHSA-w7r3-mgwf-4mqq
Charts affected
7 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| nethermindchronicleVerified publisher | 0.0.13 | 1 of 1See more | 2,031 |
| kubernetes-azure-keyvault-secret-operatorbtungutVerified publisher | 1.7.0 | 1 of 1See more | 584 |
| nethermindethersphereVerified publisher | 0.2.1 | 1 of 1See more | 4,920 |
| faasnetfaasnet | 0.0.4 | 1 of 5See more | 7,617 |
| innago-vault-k8s-role-operatorinnagoVerified publisher | 2.0.5 | 1 of 1See more | 1,052 |
| zileank8s-home-lab-repo | 1.0.1 | 1 of 1See more | 2,025 |
| nethermindstakewise | 2.8.2 | 1 of 3See more | 2,031 |
Container images carrying it
7 by charts deploying them
A fixed version is listed for 1 of the 1 affected package.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| btungut/ | 4a072e2edf71 | KubernetesClient | 17.0.14 | 1 |
| nethermind/ | 15517708c3b6 | KubernetesClient | 17.0.14 | 1 |
| nethermind/ | 93e57917371a | KubernetesClient | 17.0.14 | 1 |
| nethermind/ | aeca3b55bda5 | KubernetesClient | 17.0.14 | 1 |
| simpleidserver/ | 9007e742dd48 | KubernetesClient | 17.0.14 | 1 |
| ghcr.io/ | ed1c3fd04057 | KubernetesClient | 17.0.14 | 1 |
| ghcr.io/ | bce6aca0f6ca | KubernetesClient | 17.0.14 | 1 |