GHSA-r2v3-8gwf-7ghm
CRITICALCVE-2026-54725The vault-secrets-webhook reads the vault.security.banzaicloud.io/vault-addr annotation from any ConfigMap or Secret being admitted and uses it as the Vault server address without any validation or allowlist. When a ConfigMap or Secret contains a value prefixed with vault:, the webhook's admission handler synchronously calls the Vault API at the attacker-supplied address from inside the webhook pr
- Affected
- <= 1.22.2, >=0, <1.23.1
- Fixed in
- 1.23.1
- Weakness
- CWE-918
- Published
- 2026-07-31
- Source
- github