PT-2026-84159 · Kyverno · Kyverno

·

CVE-2026-84196

·

Published

2026-04-14

·

Updated

2026-09-01

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Kyverno versions prior to 1.18.0
Description An issue exists where authenticated users can perform server-side request forgery (SSRF)—a technique used to induce a server to make requests to an unintended location—by injecting user-controlled input through variable substitution in the apiCall.service.url parameter. This allows attackers to target loopback addresses, cloud metadata endpoints, and internal services. Because response data is reflected in admission error messages, non-blind data exfiltration is possible.
Recommendations Update to version 1.18.0 or later. Restrict the use of the apiCall.service.url parameter to minimize the risk of exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84196
GHSA-QR4G-8HRP-C4RW
GO-2026-5594

Affected Products

Kyverno