The Chaos Controller Manager in Chaos Mesh exposes a GraphQL debugging server without authentication to the entire Kubernetes cluster, which provides an API to kill arbitrary processes in any Kubernetes pod, leading to cluster-wide denial of service.
References
| Link | Resource |
|---|---|
| https://github.com/chaos-mesh/chaos-mesh/pull/4702 | Issue Tracking Patch |
| https://jfrog.com/blog/chaotic-deputy-critical-vulnerabilities-in-chaos-mesh-lead-to-kubernetes-cluster-takeover | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2025-09-15 12:15
Updated : 2025-10-14 14:42
NVD link : CVE-2025-59358
Mitre link : CVE-2025-59358
CVE.ORG link : CVE-2025-59358
JSON object : View
Products Affected
chaos-mesh
- chaos_mesh
CWE
CWE-306
Missing Authentication for Critical Function
