Database/Container, Kubernetes & orchestration
Kyverno: percent-encoded dot-segments in apiCall urlPath bypass namespace scoping in namespaced Policies
Impact
Validation and execution interpret the apiCall urlPath differently: the check that a namespaced Policy only reads its own namespace is done on the raw path, while the request is issued after percent-decoding, so encoded ../ segments escape the namespace prefix. A tenant who can create a Policy in their own namespace then reads arbitrary API objects in other namespaces using the Kyverno admission controller's ServiceAccount, which in a normal install has broad read across the cluster. In a multi-tenant GPU cluster that is a direct tenant-isolation break: Secrets, ConfigMaps and workload specs belonging to other customers become readable through a namespaced object the tenant is legitimately allowed to create. This is a distinct defect from the SSRF in the same release; both are fixed in 1.19.1.
Who can reach it
Low-privileged tenant with permission to create or edit namespaced Policy resources in a namespace they already control. Authentication to the Kubernetes API is required.
What to do
Upgrade Kyverno to 1.19.1 and roll the admission controller deployment - a rolling pod restart, no node drain. Until patched, deny tenants the ability to create namespaced Policy objects, or review existing Policies for apiCall entries containing encoded path separators.
References
Related entries
- docker-socket-proxy: CONTAINERS access lets any client export container filesystems and read filesCVE-2026-78122 · Tecnativa docker-socket-proxy (/containers read endpoints)High
- Kyverno: admission controller ServiceAccount token attached to outbound apiCall requests leaks to any endpointCVE-2026-84195 · Kyverno admission controller (apiCall service mode)High
- Kyverno: SSRF via apiCall.service.url lets authenticated users reach internal and metadata endpointsCVE-2026-84196 · Kyverno admission controller (apiCall.service.url variable substitution)High
- Kubernetes (kubelet): /debug/pprof exposed on the unauthenticated kubelet healthz portCVE-2019-11248 · Kubernetes (kubelet)High
- Envoy: JWT with an issuer absent from the provider list bypasses JWT authenticationCVE-2021-21378 · EnvoyHigh
- KubeVirt: A compromised node's virt-handler service account can be abused cluster-wideCVE-2023-26484 · KubeVirtHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.