← Back to overview

Kyverno versions before 1.18.0 contain a server-side request forgery (SSRF) vulnerability in the apiCall.service.url parameter. Authenticated users can inject user-controlled input through variable substitution to send arbitrary HTTP requests. Attackers can leverage this to target internal services, cloud metadata endpoints (e.g., AWS/GCP/Azure IMDS), and loopback addresses. The vulnerability is particularly dangerous because response data is reflected back in admission error messages, enabling non-blind data exfiltration. This means attackers can read the responses from internal requests, making it a high-impact SSRF. The flaw affects Kubernetes policy engine Kyverno and could be exploited by any authenticated cluster user. Users are advised to upgrade to Kyverno 1.18.0 or later to remediate the issue.

Affected products

  • Kyverno
  • Kyverno before 1.18.0

Related CVE's

  • CVE-2026-84196

Categories

  • Cloud & Virtualization
  • Data Breach & Exfiltration
  • Web Technologies