CVE-2025-64171: 3scale-Sre MARIN3R
High severity, CVSS 8.7. EPSS: 0.2% chance of exploitation in the next 30 days.
MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-namespace secret access vulnerability in the project's DiscoveryServiceCertificate which allows users to bypass RBAC and access secrets in unauthorized namespaces. This issue is fixed in version 0.13.4.
Affected products
- 3scale-Sre MARIN3R: before 0.13.4 (fixed in 0.13.4)
Published 2025-11-06. Last modified 2026-06-17.