CVE-2025-59358

HIGH7.5EPSS 0.50%

Chaos Mesh's Chaos Controller Manager is Missing Authentication for Critical Function

Published: 9/15/2025Modified: 9/17/2025
Also known as:GHSA-2gg8-85m5-8r2pGO-2025-3951

Description

The Chaos Controller Manager in Chaos Mesh exposes a GraphQL debugging server without authentication to the entire Kubernetes cluster, which provides an API to kill arbitrary processes in any Kubernetes pod, leading to cluster-wide denial of service.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References (6)