Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 01 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url that allows authenticated users to send arbitrary HTTP requests by injecting user-controlled input through variable substitution. Attackers can target internal services, cloud metadata endpoints, and loopback addresses, with response data reflected in admission error messages enabling non-blind data exfiltration. | |
| Title | Kyverno before 1.18.0 Server-Side Request Forgery via apiCall | |
| First Time appeared |
Kyverno
Kyverno kyverno |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:kyverno:kyverno:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Kyverno
Kyverno kyverno |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-01T11:33:59.097Z
Reserved: 2026-09-01T10:51:59.729Z
Link: CVE-2026-84196
No data.
Status : Received
Published: 2026-09-01T12:17:49.270
Modified: 2026-09-01T12:17:49.270
Link: CVE-2026-84196
No data.
OpenCVE Enrichment
Updated: 2026-09-01T12:30:04Z
-
CWE-918
Server-Side Request Forgery (SSRF)