Junglewise Threat Intelligence

CVE-2026-100705: Kyverno server-side request forgery in apiCall executor

CVE-2026-100705 · Severity: high · CVSS 7.6 · Published 2026-09-26

Technologies: Kyverno. Vendors: Kyverno.

Executive brief

Kyverno is a policy engine that enforces security rules in Kubernetes clusters. A flaw in how it handles policy configuration allows attackers with policy authoring rights to force Kyverno to make arbitrary outbound network requests to internal systems and cloud metadata services, potentially exposing cloud credentials and allowing access to internal infrastructure that should be protected.

Technical details

The legacy apiCall service executor and GlobalContextEntry external-API path bypass SSRF protections (egress blocklist for 169.254.169.254, metadata services, and loopback) that were only applied to the newer CEL http library. An attacker who can author a ClusterPolicy or GlobalContextEntry—or submit resources templated with a service URL—can cause Kyverno's net/http client to reach arbitrary hosts and leak Kyverno's projected ServiceAccount token to attacker-controlled destinations, with no egress filtering or URL validation in place.

Affected products

  • Kyverno Kyverno before 1.19.1

Timeline

  • 2026-09-26: disclosed
  • 2026-09-26: patched: Version 1.19.1

References

Related threats