VU#655822: Kyverno is vulnerable to server-side request forgery (SSRF)
2026-03-30T20:52:11Z•4fd07422fcfbf25be4af835ef8ed1322e9a476e7b30c579a739d45802dabc82b
KubernetesLPENode.jsRCESSRFcontainer registrydefault credentialshard-coded credentialslocal privilege escalationlog injectionpickleprototype pollutionremote code executionsupply chainunsafe deserialization
What happened
CERT/CC vulnerability notes reporting multiple distinct flaws across open-source and commercial projects. Notable issues include: Kyverno SSRF via CEL HTTP functions enabling namespace-scoped attackers to make arbitrary internal requests; CrewAI vulnerabilities including CVE-2026-2275 (Code Interpreter RCE) and an SSRF (CVE-2026-2286) that can be chained; SGLang unsafe pickle deserialization leading to unauthenticated remote code execution (CVE-2026-3059, CVE-2026-3060) plus CVE-2026-3989; IDrive for Windows local privilege escalation (CVE-2026-1995); GoHarbor Harbor default admin credentials;
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 4fd07422fcfbf25be4af835ef8ed1322e9a476e7b30c579a739d45802dabc82b
- Enrichment time
- 2026-03-30T20:52:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.