PT-2026-84145 · Kyverno · Kyverno

·

CVE-2025-15613

·

Published

2025-04-15

·

Updated

2026-09-01

CVSS v4.0

7.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
Name of the Vulnerable Software and Affected Versions Kyverno versions prior to 1.13.4
Description Server-side request forgery (SSRF) exists within the Service Call functionality. An attacker with permissions to create Kyverno (Cluster)Policies can specify an external URL in the apiCall/service configuration. While the Service Call is intended for in-cluster services, it also resolves external addresses, enabling requests to be sent to an attacker-controlled server. This allows for the exfiltration of sensitive cluster data, including the contents of Kubernetes resources such as secrets, which are included in the policy context data sent during these requests.
Recommendations Update to version 1.13.4 or later.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-15613
GHSA-459X-Q9HG-4GPQ
GO-2025-3615

Affected Products

Kyverno