GHSA-qr4g-8hrp-c4rw
### Summary A Server-Side Request Forgery (SSRF) vulnerability in Kyverno allows authenticated users to induce the admission controller to send arbitrary HTTP requests to attacker-controlled endpoints. When a `ClusterPolicy` uses `apiCall.service.url` with variable substitution (e.g. `{{request.object.*}}`), user-controlled input can influence the request target. The Kyverno admission controller executes these requests from its privileged network position without enforcing any validation or network restrictions. The issue becomes **non-blind SSRF**, as response data from internal services can be reflected back to the user via admission error messages. --- ### Details Kyverno supports variable substitution in `apiCall.service.url`, a documented feature intended to enable dynamic external lookups during admission control. However, the current implementation lacks fundamental safeguards in the HTTP execution path: #### Missing protections - **No URL validation** User-controlled input is directly embedded into the request URL without validation or normalization. - **No IP filtering** Requests can target: - Loopback (`127.0.0.1`) - Link-local (`169.254.0.0/16`) - Cloud metadata services (e.g. AWS IMDS) - Internal ClusterIP services - **Redirect handling not restricted** The Go HTTP client uses default redirect behavior (`CheckRedirect == nil`), allowing up to 10 redirects without re-validation of the target. - **Response data reflection in admission errors** Response bodies are propagated back to the user in admission responses under certain conditions. #### Non-blind SSRF behavior The vulnerability is **non-blind** through two mechanisms: 1. **Non-2xx responses** Response body is returned in admission error messages (e.g. `executor.go:98-101`) 2. **2xx responses with non-JSON content** Parsing failures (JSON/JMESPath) include response snippets in error output This allows attackers to retrieve data from internal services
Properties
- ghsa_id
- GHSA-qr4g-8hrp-c4rw
- summary
- Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF
- severity
- high
- cvss_score
- 7.7
- cve_id
- GHSA-qr4g-8hrp-c4rw
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
- is_ghsa_only
- true
- ghsa_published
- 2026-04-14T20:05:52Z
- source_url
- https://github.com/advisories/GHSA-qr4g-8hrp-c4rw
- ghsa_updated
- 2026-04-14T20:05:56Z
Related Entities (4)
HAS_WEAKNESS (1)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
Explore deeper with Ninja Signal's threat intelligence graph