PT-2026-99376 · Kyverno · Kyverno
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Kyverno versions prior to 1.19.1
Description
An issue exists where the legacy
apiCall service executor (pkg/engine/apicall/executor.go) and the GlobalContextEntry external-API path do not apply the default egress blocklist or scoped-token controls. These paths utilize a plain net/http client without egress filtering or validation of the configured service URL. Consequently, an author of a ClusterPolicy or GlobalContextEntry, or a lower-privileged resource submitter when a policy templates the service URL from the admission resource, can trigger GET/POST requests to arbitrary hosts. This includes cloud metadata endpoints, loopback addresses, and internal cluster services, potentially allowing the retrieval of cloud instance credentials. Additionally, the executor unconditionally attaches Kyverno's projected ServiceAccount token to the destination, although the token is audience-scoped.Recommendations
Update to version 1.19.1.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kyverno