The Chaos Controller Manager in Chaos Mesh exposes a GraphQL debugging server without authentication to the entire Kubernetes cluster, which provides an API to kill arbitrary processes in any Kubernetes pod, leading to cluster-wide denial of service.
{ "severity": "HIGH", "cwe_ids": [ "CWE-306" ], "github_reviewed": true, "github_reviewed_at": "2025-09-15T21:06:36Z", "nvd_published_at": "2025-09-15T12:15:33Z" }