CVE-2025-59358
15.09.2025, 12:15
The Chaos Controller Manager in Chaos Mesh exposes a GraphQL debugging server without authentication to the entire Kubernetes cluster, which provides an API to kill arbitrary processes in any Kubernetes pod, leading to cluster-wide denial of service.Enginsight
| Vendor | Product | Version | 
|---|---|---|
| chaos-mesh | chaos_mesh | 𝑥 < 2.7.3 | 
𝑥
= Vulnerable software versions
Common Weakness Enumeration