GPU VulnDB

Database/Container, Kubernetes & orchestration

Kyverno: legacy apiCall path skips the egress blocklist, allowing SSRF to cloud metadata from the admission controller

CVSS 8.3CVE-2026-100705Container, Kubernetes & orchestrationcurated

Impact

The egress blocklist (link-local metadata, loopback) and the scoped-token control were only wired into the new CEL http.Get/Post library, so every non-CEL context[].apiCall.service call and every GlobalContextEntry external-API call still uses a plain HTTP client with no destination filtering. A policy author - or, where a deployed policy templates the service URL from the admission resource, a lower-privileged user who can submit that resource - makes the admission controller fetch arbitrary hosts from its own network position: the node's cloud metadata endpoint, loopback services, and any in-cluster service that trusts the cluster network. On a GPU cluster the admission controller usually runs on a control-plane node with an instance role that can reach the cloud API, so the payoff is instance credentials plus a probe of internal endpoints. Kyverno also attaches its projected ServiceAccount token to the attacker-chosen destination, though that token is audience-scoped and of limited replay value.

Who can reach it

Authenticated Kubernetes user able to create or modify a ClusterPolicy or GlobalContextEntry; where a policy templates the service URL from the admitted resource, any user who can submit that resource.

What to do

Upgrade Kyverno to 1.19.1 and roll the admission controller deployment - a rolling restart of the Kyverno pods, no node disruption and no GPU workload impact. Until then, audit ClusterPolicy and GlobalContextEntry objects for apiCall.service entries whose URL is templated from request data, and restrict who can create policy objects.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.