{"id":"CVE-2025-46599","aliases":["GHSA-864f-7xjm-2jp2","GO-2025-3646"],"url":"https://o3.security/vulnerability/CVE-2025-46599","summary":"CNCF K3s Kubernetes kubelet configuration exposes credentials","details":"CNCF K3s 1.32 before 1.32.4-rc1+k3s1 has a Kubernetes kubelet configuration change with the unintended consequence that, in some situations, ReadOnlyPort is set to 10255. For example, the default behavior of a K3s online installation might allow unauthenticated access to this port, exposing credentials.","published":"2025-04-25T00:00:00Z","modified":"2026-08-12T03:51:47.251975618Z","cvss":{"score":6.8,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/k3s-io/k3s","fixedVersion":"1.32.4-rc1"}],"fix":{"url":"https://github.com/k3s-io/k3s/commit/097b63e588e3c844cdf9b967bcd0a69f4fc0aa0a","label":"k3s-io/k3s@097b63e"},"references":[{"type":"WEB","url":"https://cloud.google.com/kubernetes-engine/docs/how-to/disable-kubelet-readonly-port"},{"type":"WEB","url":"https://github.com/k3s-io/k3s/compare/v1.32.3+k3s1...v1.32.4-rc1+k3s1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/46xxx/CVE-2025-46599.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-46599"},{"type":"REPORT","url":"https://github.com/f1veT/BUG/issues/2"},{"type":"REPORT","url":"https://github.com/k3s-io/k3s/issues/12164"},{"type":"FIX","url":"https://github.com/k3s-io/k3s/commit/097b63e588e3c844cdf9b967bcd0a69f4fc0aa0a"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:47.251975618Z"}}