{"id":"CVE-2025-64434","aliases":["GHSA-ggp9-c99x-54gp","GO-2025-4107"],"url":"https://o3.security/vulnerability/CVE-2025-64434","summary":"KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing","details":"KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, due to the peer verification logic in virt-handler (via verifyPeerCert), an attacker who compromises a virt-handler instance, could exploit these shared credentials to impersonate virt-api and execute privileged operations against other virt-handler instances potentially compromising the integrity and availability of the VM managed by it. This vulnerability is fixed in 1.5.3 and 1.6.1.","published":"2025-11-07T22:54:04.772Z","modified":"2026-07-31T18:30:19.825354172Z","cvss":{"score":4.7,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"kubevirt.io/kubevirt","fixedVersion":"1.5.3"},{"ecosystem":"Go","name":"kubevirt.io/kubevirt","fixedVersion":"1.6.1"}],"fix":{"url":"https://github.com/kubevirt/kubevirt/commit/231dc69723f331dc02f65a31ab4c3d6869f40d6a","label":"kubevirt/kubevirt@231dc69"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64434.json"},{"type":"ADVISORY","url":"https://github.com/kubevirt/kubevirt/security/advisories/GHSA-ggp9-c99x-54gp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-64434"},{"type":"FIX","url":"https://github.com/kubevirt/kubevirt/commit/231dc69723f331dc02f65a31ab4c3d6869f40d6a"},{"type":"FIX","url":"https://github.com/kubevirt/kubevirt/commit/af2f08a9a186eccc650f87c30ab3e07b669e8b5b"},{"type":"FIX","url":"https://github.com/kubevirt/kubevirt/commit/b9773bc588e6e18ece896a2dad5336ef7a653074"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-31T18:30:19.825354172Z"}}