


Perceptive Security
SOC/SIEM Consultancy

Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url that allows authenticated users to send arbitrary HTTP request…
Published:
1 september 2026 om 00:00:00
Alert date:
1 september 2026 om 15:04:21
Source:
nvd.nist.gov
Cloud & Virtualization, Web Technologies, Data Breach & Exfiltration
Kyverno versions before 1.18.0 contain a server-side request forgery (SSRF) vulnerability in the apiCall.service.url parameter. Authenticated users can inject user-controlled input through variable substitution to send arbitrary HTTP requests. Attackers can leverage this to target internal services, cloud metadata endpoints (e.g., AWS/GCP/Azure IMDS), and loopback addresses. The vulnerability is particularly dangerous because response data is reflected back in admission error messages, enabling non-blind data exfiltration. This means attackers can read the responses from internal requests, making it a high-impact SSRF. The flaw affects Kubernetes policy engine Kyverno and could be exploited by any authenticated cluster user. Users are advised to upgrade to Kyverno 1.18.0 or later to remediate the issue.
Technical details
Mitigation steps:
Affected products:
Kyverno
Kyverno before 1.18.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-84196
https://github.com/kyverno/kyverno/security/advisories/GHSA-qr4g-8hrp-c4rw
https://www.vulncheck.com/advisories/kyverno-before-1.18.0-server-side-request-forgery-via-apicall
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
