The Chaos Controller Manager in Chaos Mesh exposes a GraphQL debugging server without authentication to the entire Kubernetes cluster, which provides an API to kill arbitrary processes in any Kubernetes pod, leading to cluster-wide denial of service.
{
"nvd_published_at": "2025-09-15T12:15:33Z",
"cwe_ids": [
"CWE-306"
],
"severity": "HIGH",
"github_reviewed_at": "2025-09-15T21:06:36Z",
"github_reviewed": true
}