CVE-2025-64434 - CVE House
Back to Database
Status published Medium CVE-2025-64434

KubeVirt Improper TLS Certificate Management Handling Allows API Identity Spoofing

Vulnerability Description

KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, due to the peer verification logic in virt-handler (via verifyPeerCert), an attacker who compromises a virt-handler instance, could exploit these shared credentials to impersonate virt-api and execute privileged operations against other virt-handler instances potentially compromising the integrity and availability of the VM managed by it. This vulnerability is fixed in 1.5.3 and 1.6.1.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-64434

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

kubevirt
Vulnerable Versions:
< 1.5.3, >= 1.6.0-alpha.0, < 1.6.1

Timeline

Official Publish: November 7th, 2025
Last Modified: November 10th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)