top of page
perceptive_background_267k.jpg

Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url that allows authenticated users to send arbitrary HTTP request…

Published:

1 september 2026 om 00:00:00

Alert date:

1 september 2026 om 15:04:21

Source:

nvd.nist.gov

Click to open the original link from this advisory

Cloud & Virtualization, Web Technologies, Data Breach & Exfiltration

Kyverno versions before 1.18.0 contain a server-side request forgery (SSRF) vulnerability in the apiCall.service.url parameter. Authenticated users can inject user-controlled input through variable substitution to send arbitrary HTTP requests. Attackers can leverage this to target internal services, cloud metadata endpoints (e.g., AWS/GCP/Azure IMDS), and loopback addresses. The vulnerability is particularly dangerous because response data is reflected back in admission error messages, enabling non-blind data exfiltration. This means attackers can read the responses from internal requests, making it a high-impact SSRF. The flaw affects Kubernetes policy engine Kyverno and could be exploited by any authenticated cluster user. Users are advised to upgrade to Kyverno 1.18.0 or later to remediate the issue.

Technical details

Mitigation steps:

Affected products:

Kyverno
Kyverno before 1.18.0

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page