PT-2026-99376 · Kyverno · Kyverno

·

CVE-2026-100705

·

Published

2026-09-26

·

Updated

2026-09-26

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Kyverno versions prior to 1.19.1
Description An issue exists where the legacy apiCall service executor (pkg/engine/apicall/executor.go) and the GlobalContextEntry external-API path do not apply the default egress blocklist or scoped-token controls. These paths utilize a plain net/http client without egress filtering or validation of the configured service URL. Consequently, an author of a ClusterPolicy or GlobalContextEntry, or a lower-privileged resource submitter when a policy templates the service URL from the admission resource, can trigger GET/POST requests to arbitrary hosts. This includes cloud metadata endpoints, loopback addresses, and internal cluster services, potentially allowing the retrieval of cloud instance credentials. Additionally, the executor unconditionally attaches Kyverno's projected ServiceAccount token to the destination, although the token is audience-scoped.
Recommendations Update to version 1.19.1.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100705
GHSA-Q825-P383-R9V5

Affected Products

Kyverno