Critical Vulnerability Information Vulnerability Description Type: Terraform Code Injection Impact: When using Terraformer for infrastructure configuration, it may allow users with management privileges to control the seed cluster of a Gardener project. Severity CVSS v3 Base Metrics: - Attack Vector: Network - Attack Complexity: Low - Required Privileges: Low - User Interaction: None - Scope: Changed - Confidentiality: High - Integrity: High - Availability: High CVSS Score: 9.9/10 (Critical) CVE ID CVE-2025-59823 Affected Components gardener-extension-provider-gcp gardener-extension-provider-azure gardener-extension-provider-openstack gardener-extension-provider-aws Affected Versions gardener-extension-provider-gcp = v1.46.0 gardener-extension-provider-azure >= v1.55.0 gardener-extension-provider-openstack >= v1.49.0 gardener-extension-provider-aws >= v1.64.0 Mitigation Upgrade to the fixed versions.