Executive brief
Kyverno is a policy engine that enforces security rules in Kubernetes clusters. A flaw in how it handles policy configuration allows attackers with policy authoring rights to force Kyverno to make arbitrary outbound network requests to internal systems and cloud metadata services, potentially exposing cloud credentials and allowing access to internal infrastructure that should be protected.
Technical details
The legacy apiCall service executor and GlobalContextEntry external-API path bypass SSRF protections (egress blocklist for 169.254.169.254, metadata services, and loopback) that were only applied to the newer CEL http library. An attacker who can author a ClusterPolicy or GlobalContextEntry—or submit resources templated with a service URL—can cause Kyverno's net/http client to reach arbitrary hosts and leak Kyverno's projected ServiceAccount token to attacker-controlled destinations, with no egress filtering or URL validation in place.
Affected products
- Kyverno Kyverno before 1.19.1
Timeline
- 2026-09-26: disclosed
- 2026-09-26: patched: Version 1.19.1