Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-29175 | Chaos Mesh's Chaos Controller Manager is Missing Authentication for Critical Function |
Github GHSA |
GHSA-2gg8-85m5-8r2p | Chaos Mesh's Chaos Controller Manager is Missing Authentication for Critical Function |
Tue, 14 Oct 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chaos-mesh chaos Mesh
|
|
| CPEs | cpe:2.3:a:chaos-mesh:chaos_mesh:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Chaos-mesh chaos Mesh
|
Wed, 17 Sep 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chaos-mesh
Chaos-mesh chaos-mesh |
|
| Vendors & Products |
Chaos-mesh
Chaos-mesh chaos-mesh |
Mon, 15 Sep 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Sep 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Chaos Controller Manager in Chaos Mesh exposes a GraphQL debugging server without authentication to the entire Kubernetes cluster, which provides an API to kill arbitrary processes in any Kubernetes pod, leading to cluster-wide denial of service. | |
| Title | Denial of Service via Unauthorized Access to Chaos Mesh debugging server | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: JFROG
Published:
Updated: 2025-09-15T11:57:48.343Z
Reserved: 2025-09-12T17:59:19.914Z
Link: CVE-2025-59358
Updated: 2025-09-15T11:57:43.282Z
Status : Analyzed
Published: 2025-09-15T12:15:33.470
Modified: 2025-10-14T14:42:44.847
Link: CVE-2025-59358
No data.
OpenCVE Enrichment
Updated: 2025-09-17T10:08:37Z
EUVD
Github GHSA