Get real-time updates on Telegram
CVE-2025-67508: gardenctl before 2.12.0 (exclusive); +1 more affected products
CVE-2025-67508. CVSS 3.1 base score 8.4 (HIGH, NVD). EPSS 0.00244 (percentile 0.14253), scored 2026-10-06.
Affected technology
gardenctl · before 2.12.0 (exclusive)
linuxfoundation
gardenctl-v2 · < 2.12.0
gardener
Component: Not specified by the source
Attack conditions (NVD, CVSS 3.1): Network (remote) · High privileges required · User interaction required
What an attacker can do
The source says when using non‑POSIX shells such as Fish and PowerShell, versions 2.11.0 and below of gardenctl allow an attacker with administrative privileges for a Gardener project to craft malicious credential values. NVD’s CVSS 3.1 assessment (base score 8.4/10) rates confidentiality, integrity and availability impact as high.
- CWE
- CWE-77
- CCR priority
- 33.7 /100 (P4)
- CVSS 3.1
- 8.4 /10 · CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H · NVD
- EPSS
- 0.00244 · percentile 0.14253 · 2026-10-06
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-07 23:02:50.240617+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2025-67508.html