The Unpatched Kyverno SSRF Flaw That Turns Policies Into Cluster-Wide Backdoors
ID: 711a9fd1-986b-532c-9ba5-a0cd5503615a
STIX ID: report--711a9fd1-986b-532c-9ba5-a0cd5503615a
Feed Name: securityonline.info
A critical SSRF vulnerability (CVE-2026-4789) in Kyverno's CEL HTTP functions (Get/Post) allows an attacker with namespace-level permissions to cause the Kyverno admission controller to issue arbitrary HTTP requests, potentially exposing cloud provider metadata and internal cluster services; CERT/CC could not reach the vendor and no patch is currently available, so administrators are advised to apply URL validation, restrict outbound destinations, and enforce default-deny network policies as mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
