fog-kubevirt allows remote attacker to perform MITM attack due to disabled certificate validation
High severity
GitHub Reviewed
Published
Feb 2, 2026
to the GitHub Advisory Database
•
Updated Mar 26, 2026
Description
Published by the National Vulnerability Database
Feb 2, 2026
Published to the GitHub Advisory Database
Feb 2, 2026
Reviewed
Feb 2, 2026
Last updated
Mar 26, 2026
A flaw was found in fog-kubevirt. This vulnerability allows a remote attacker to perform a Man-in-the-Middle (MITM) attack due to disabled certificate validation. This enables the attacker to intercept and potentially alter sensitive communications between Satellite and OpenShift, resulting in information disclosure and data integrity compromise.
References