Database/Container, Kubernetes & orchestration
Kyverno: legacy apiCall path skips the egress blocklist, allowing SSRF to cloud metadata from the admission controller
Impact
The egress blocklist (link-local metadata, loopback) and the scoped-token control were only wired into the new CEL http.Get/Post library, so every non-CEL context[].apiCall.service call and every GlobalContextEntry external-API call still uses a plain HTTP client with no destination filtering. A policy author - or, where a deployed policy templates the service URL from the admission resource, a lower-privileged user who can submit that resource - makes the admission controller fetch arbitrary hosts from its own network position: the node's cloud metadata endpoint, loopback services, and any in-cluster service that trusts the cluster network. On a GPU cluster the admission controller usually runs on a control-plane node with an instance role that can reach the cloud API, so the payoff is instance credentials plus a probe of internal endpoints. Kyverno also attaches its projected ServiceAccount token to the attacker-chosen destination, though that token is audience-scoped and of limited replay value.
Who can reach it
Authenticated Kubernetes user able to create or modify a ClusterPolicy or GlobalContextEntry; where a policy templates the service URL from the admitted resource, any user who can submit that resource.
What to do
Upgrade Kyverno to 1.19.1 and roll the admission controller deployment - a rolling restart of the Kyverno pods, no node disruption and no GPU workload impact. Until then, audit ClusterPolicy and GlobalContextEntry objects for apiCall.service entries whose URL is templated from request data, and restrict who can create policy objects.
References
Related entries
- Kyverno: percent-encoded dot-segments in apiCall urlPath bypass namespace scoping in namespaced PoliciesCVE-2026-100707 · Kyverno admission controller (namespaced Policy apiCall urlPath validation)High
- docker-socket-proxy: CONTAINERS access lets any client export container filesystems and read filesCVE-2026-78122 · Tecnativa docker-socket-proxy (/containers read endpoints)High
- Kyverno: admission controller ServiceAccount token attached to outbound apiCall requests leaks to any endpointCVE-2026-84195 · Kyverno admission controller (apiCall service mode)High
- Kyverno: SSRF via apiCall.service.url lets authenticated users reach internal and metadata endpointsCVE-2026-84196 · Kyverno admission controller (apiCall.service.url variable substitution)High
- Kubernetes (kubelet): /debug/pprof exposed on the unauthenticated kubelet healthz portCVE-2019-11248 · Kubernetes (kubelet)High
- Envoy: JWT with an issuer absent from the provider list bypasses JWT authenticationCVE-2021-21378 · EnvoyHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.