📦 Chaos Mesh

by Chaos Mesh

🔍 What is Chaos Mesh?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-59359

CRITICAL CVSS 9.8 Sep 15, 2025

CVE-2025-59359 is an OS command injection vulnerability in Chaos Controller Manager's cleanTcs mutation that allows unauthenticated attackers within a Kubernetes cluster to execute arbitrary commands....

CVE-2025-59361

CRITICAL CVSS 9.8 Sep 15, 2025

CVE-2025-59361 is an OS command injection vulnerability in Chaos Mesh's cleanIptables mutation that allows unauthenticated attackers within a Kubernetes cluster to execute arbitrary commands. When com...

CVE-2025-59358

HIGH CVSS 7.5 Sep 15, 2025

The Chaos Controller Manager in Chaos Mesh exposes an unauthenticated GraphQL debugging server that allows attackers to kill arbitrary processes in any Kubernetes pod. This leads to cluster-wide denia...

CVE-2024-36538

HIGH CVSS 8.8 Jul 24, 2024

This vulnerability in Chaos Mesh v2.6.3 involves insecure permissions that allow attackers to access service account tokens. Attackers can use these tokens to escalate privileges and access sensitive ...