VU#655822: Kyverno is vulnerable to server-side request forgery (SSRF)

2026-03-30T20:52:11Z4fd07422fcfbf25be4af835ef8ed1322e9a476e7b30c579a739d45802dabc82b
KubernetesLPENode.jsRCESSRFcontainer registrydefault credentialshard-coded credentialslocal privilege escalationlog injectionpickleprototype pollutionremote code executionsupply chainunsafe deserialization

What happened

CERT/CC vulnerability notes reporting multiple distinct flaws across open-source and commercial projects. Notable issues include: Kyverno SSRF via CEL HTTP functions enabling namespace-scoped attackers to make arbitrary internal requests; CrewAI vulnerabilities including CVE-2026-2275 (Code Interpreter RCE) and an SSRF (CVE-2026-2286) that can be chained; SGLang unsafe pickle deserialization leading to unauthenticated remote code execution (CVE-2026-3059, CVE-2026-3060) plus CVE-2026-3989; IDrive for Windows local privilege escalation (CVE-2026-1995); GoHarbor Harbor default admin credentials;

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
4fd07422fcfbf25be4af835ef8ed1322e9a476e7b30c579a739d45802dabc82b
Enrichment time
2026-03-30T20:52:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.