logo

The Unpatched Kyverno SSRF Flaw That Turns Policies Into Cluster-Wide Backdoors

ID: 711a9fd1-986b-532c-9ba5-a0cd5503615a

STIX ID: report--711a9fd1-986b-532c-9ba5-a0cd5503615a

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-03-31

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical SSRF vulnerability (CVE-2026-4789) in Kyverno's CEL HTTP functions (Get/Post) allows an attacker with namespace-level permissions to cause the Kyverno admission controller to issue arbitrary HTTP requests, potentially exposing cloud provider metadata and internal cluster services; CERT/CC could not reach the vendor and no patch is currently available, so administrators are advised to apply URL validation, restrict outbound destinations, and enforce default-deny network policies as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.