Advisories for Golang/Github.com/Rancher/Stev package

2025

Steve doesn’t verify a server’s certificate and is susceptible to man-in-the-middle (MitM) attacks

A vulnerability has been identified in Steve where by default it was using an insecure option that did not validate the certificate presented by the remote server while performing a TLS connection. This could allow the execution of a man-in-the-middle (MitM) attack against services using Steve. For example, Rancher relies on Steve as a dependency for its user interface (UI) to proxy requests to Kubernetes clusters. Users who have the …