cve 2025 64432

  1. Understanding CVE-2025-64432: KubeVirt Aggregation Layer Auth Bypass

    KubeVirt maintainers published a security advisory this autumn describing an authentication-bypass in the aggregation-layer handling inside the virt-api component that can let an attacker impersonate the Kubernetes API server and bypass RBAC when a small set of preconditions exist. Background /...