


Perceptive Security
SOC/SIEM Consultancy

In KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF vulnerability when processing the chartURL field of ResourceComposition …
Published:
29 maart 2026 om 22:00:00
Alert date:
30 maart 2026 om 20:03:04
Source:
nvd.nist.gov
Cloud & Virtualization, Web Technologies
CVE-2026-29954 affects KubePlus 4.1.4, specifically the mutating webhook and kubeconfiggenerator components. The vulnerability stems from improper validation of the chartURL field in ResourceComposition resources, leading to Server-Side Request Forgery (SSRF). The chartURL field is only URL-encoded without target address validation. More critically, the kubeconfiggenerator component directly concatenates the chartURL into wget commands without sanitization, enabling command injection attacks. Attackers can inject wget's --header option to achieve arbitrary HTTP header injection, potentially leading to further exploitation.
Technical details
Mitigation steps:
Affected products:
KubePlus
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-29954
https://gist.github.com/b0b0haha/33baea60fd2a847f11f1fb02e43c64c0
https://github.com/b0b0haha/CVE-2026-29954/blob/main/README.md
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
