Kyverno, versions 1.16.0 and later, are vulnerable to SSRF due to unrestricted CEL HTTP functions.

Project Subscriptions

Vendors Products
Kyverno Subscribe
Kyverno Subscribe
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-qqrv-2hch-83q4 Kyverno is vulnerable to server-side request forgery (SSRF)
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Apr 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Kyverno
Kyverno kyverno
Weaknesses CWE-918
Vendors & Products Kyverno
Kyverno kyverno

Tue, 31 Mar 2026 03:00:00 +0000

Type Values Removed Values Added
Description Kyverno, versions 1.16.0 and later, are vulnerable to SSRF due to unrestricted CEL HTTP functions.
Title CVE-2026-4789
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-04-01T18:43:50.952Z

Reserved: 2026-03-24T20:03:13.388Z

Link: CVE-2026-4789

cve-icon Vulnrichment

Updated: 2026-03-30T21:18:08.577Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-30T21:17:10.843

Modified: 2026-04-01T19:16:34.170

Link: CVE-2026-4789

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-31T20:40:02Z

Weaknesses