The Chaos Controller Manager in Chaos Mesh exposes a GraphQL debugging server without authentication to the entire Kubernetes cluster, which provides an API to kill arbitrary processes in any Kubernetes pod, leading to cluster-wide denial of service.
References
Link | Resource |
---|---|
https://github.com/chaos-mesh/chaos-mesh/pull/4702 | Issue Tracking Patch |
https://jfrog.com/blog/chaotic-deputy-critical-vulnerabilities-in-chaos-mesh-lead-to-kubernetes-cluster-takeover | Exploit Third Party Advisory |
Configurations
History
14 Oct 2025, 14:42
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:chaos-mesh:chaos_mesh:*:*:*:*:*:*:*:* | |
First Time |
Chaos-mesh
Chaos-mesh chaos Mesh |
|
References | () https://github.com/chaos-mesh/chaos-mesh/pull/4702 - Issue Tracking, Patch | |
References | () https://jfrog.com/blog/chaotic-deputy-critical-vulnerabilities-in-chaos-mesh-lead-to-kubernetes-cluster-takeover - Exploit, Third Party Advisory |
15 Sep 2025, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-15 12:15
Updated : 2025-10-14 14:42
NVD link : CVE-2025-59358
Mitre link : CVE-2025-59358
CVE.ORG link : CVE-2025-59358
JSON object : View
Products Affected
chaos-mesh
- chaos_mesh
CWE
CWE-306
Missing Authentication for Critical Function