Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-59341— Sealed Secrets: decryption oracle via Go template injection in unauthenticated controller endpoints

Quick assessment

Affected
Bitnami sealed-secrets
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Sealed Secrets 控制器的未认证 POST 端点存在安全漏洞。通过提交包含自定义 Go 模板逻辑在 中的修改后负载,拥有内部网络访问权限的攻击者可以利用该处理程序作为解密预言机(decryption oracle),从而恢复任意密封机密(sealed secret)的完整明文。 和 处理程序会调用 对目标机密进行解密,随后使用解密后的负载作为评估上下文,渲染 中发现的任何 Go 模板(见 )。模板执行过程中遇到的错误会直接反映在返回的 HTTP 响应状态码中。 AEAD 标签绑定缺失: 字段未被纳入 A

CVSS 4.2 · Medium EPSS 0.40% · P32

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 2

VendorProduct Version RangeStatus
Bitnami sealed-secrets ≤ 0.38.4 affected
0.40.0 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-59341

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Sealed Secrets: decryption oracle via Go template injection in unauthenticated controller endpoints
Source: CVE Program / CVE List V5
Vulnerability Description
A security vulnerability exists in the Sealed Secrets controller's unauthenticated POST endpoints. By submitting a modified payload containing custom Go template logic in spec.template.data, an attacker with internal network access can abuse the handler as a decryption oracle to recover the full plaintext of any sealed secret. The POST /v1/verify and /v1/rotate handlers call Unseal() to decrypt target secrets, then render any Go templates found in spec.template.data.* using the decrypted payload as the evaluation context (pkg/apis/sealedsecrets/v1alpha1/sealedsecret_expansion.go). Errors encountered during template execution are directly reflected in the resulting HTTP response status codes. Missing AEAD label binding: the spec.template.data field is omitted from the AEAD authenticated-data label binding ciphertext to metadata. As a result, an attacker can copy a target's valid metadata and encryptedData verbatim, satisfying AEAD decryption and label validation, while freely replacing spec.template.data with arbitrary template logic. Side-channel oracle: template execution errors map directly to HTTP response codes. HTTP 200 (OK) indicates template execution succeeded; HTTP 409 (Conflict) indicates template execution failed (e.g. via {{ fail "..." }}). By injecting conditional statements such as {{ if eq (substr 0 1 .password) "S" }}ok{{ else }}{{ fail "x" }}{{ end }}, an attacker receives an HTTP 200 status when a character guess is correct and an HTTP 409 when it is incorrect. This differential response leaks one character-equality bit per request, allowing full secret extraction over successive queries. Attack vector & prerequisites: unauthenticated; requires network access to the controller's internal service port (:8080). Although this service is not exposed to the public internet by default, it is accessible to any pod within the Kubernetes cluster or via a kubectl port-forward connection.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Bitnami sealed-secrets 0 ~ 0.38.4 -

II. Public POCs for CVE-2026-59341

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-59341

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-59341 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-59341

No comments yet


Leave a comment