PT-2026-84159 · Kyverno · Kyverno
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Kyverno versions prior to 1.18.0
Description
An issue exists where authenticated users can perform server-side request forgery (SSRF)—a technique used to induce a server to make requests to an unintended location—by injecting user-controlled input through variable substitution in the
apiCall.service.url parameter. This allows attackers to target loopback addresses, cloud metadata endpoints, and internal services. Because response data is reflected in admission error messages, non-blind data exfiltration is possible.Recommendations
Update to version 1.18.0 or later.
Restrict the use of the
apiCall.service.url parameter to minimize the risk of exploitation.Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kyverno