highCVSS 7.7Vulnerability

GHSA-qr4g-8hrp-c4rw

### Summary A Server-Side Request Forgery (SSRF) vulnerability in Kyverno allows authenticated users to induce the admission controller to send arbitrary HTTP requests to attacker-controlled endpoints. When a `ClusterPolicy` uses `apiCall.service.url` with variable substitution (e.g. `{{request.object.*}}`), user-controlled input can influence the request target. The Kyverno admission controller executes these requests from its privileged network position without enforcing any validation or network restrictions. The issue becomes **non-blind SSRF**, as response data from internal services can be reflected back to the user via admission error messages. --- ### Details Kyverno supports variable substitution in `apiCall.service.url`, a documented feature intended to enable dynamic external lookups during admission control. However, the current implementation lacks fundamental safeguards in the HTTP execution path: #### Missing protections - **No URL validation** User-controlled input is directly embedded into the request URL without validation or normalization. - **No IP filtering** Requests can target: - Loopback (`127.0.0.1`) - Link-local (`169.254.0.0/16`) - Cloud metadata services (e.g. AWS IMDS) - Internal ClusterIP services - **Redirect handling not restricted** The Go HTTP client uses default redirect behavior (`CheckRedirect == nil`), allowing up to 10 redirects without re-validation of the target. - **Response data reflection in admission errors** Response bodies are propagated back to the user in admission responses under certain conditions. #### Non-blind SSRF behavior The vulnerability is **non-blind** through two mechanisms: 1. **Non-2xx responses** Response body is returned in admission error messages (e.g. `executor.go:98-101`) 2. **2xx responses with non-JSON content** Parsing failures (JSON/JMESPath) include response snippets in error output This allows attackers to retrieve data from internal services

Properties

ghsa_id
GHSA-qr4g-8hrp-c4rw
summary
Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF
severity
high
cvss_score
7.7
cve_id
GHSA-qr4g-8hrp-c4rw
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
is_ghsa_only
true
ghsa_published
2026-04-14T20:05:52Z
source_url
https://github.com/advisories/GHSA-qr4g-8hrp-c4rw
ghsa_updated
2026-04-14T20:05:56Z

Related Entities (4)

HAS_WEAKNESS (1)

[Weakness]Server-Side Request Forgery (SSRF)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]go/github.com/kyverno/kyverno

AFFECTS (1)

[Software]go/github.com/kyverno/kyverno

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-qr4g-8hrp-c4rw (CVSS 7.7) — Ninja Signal Threat Intelligence | Ninja Signal