在 Kyverno 1.19.1 版本之前,存在服务器端请求伪造(Server-Side Request Forgery, SSRF)漏洞。 默认出口阻止列表(包括 169.254.169.254、169.254.169.253、metadata.google.internal、127.0.0.0/8 和 ::1/128)以及作用域化令牌(scoped-token)控制机制仅被集成到新的 CEL(通用表达式语言)HTTP GET/POST 库中,而未被应用于传统的 apiCall 服务执行器(位于 pkg/engi
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100706 | 9.9 CRITICAL | kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath |
| CVE-2026-100704 | 7.7 HIGH | Kyverno before 1.19.1 ImageValidatingPolicy Exception Bypass |
| CVE-2026-100707 | 7.7 HIGH | Kyverno before 1.19.1 Namespace Isolation Bypass via Percent-Encoded Path |
| CVE-2026-100703 | 7.7 HIGH | Kyverno before 1.19.1 Cross-Namespace Data Access via globalcontext.Lib |
No comments yet