Server-Side Request Forgery Vulnerability in Kargo by Akuity
CVE-2026-32828
5.1MEDIUM
What is CVE-2026-32828?
A vulnerability in Kargo allows for Server-Side Request Forgery (SSRF) attacks via the http and http-download promotion steps. This issue affects versions 1.4.0 to 1.9.4 and enables unauthorized access to link-local addresses, prominently the cloud metadata endpoint (169.254.169.254). Attackers can exfiltrate sensitive data, including IAM credentials, by crafting malicious Promotion manifests. Users are advised to update to the secure versions (1.6.4, 1.7.9, 1.8.12, 1.9.5) to mitigate this risk.
Affected Version(s)
kargo >= 1.4.0, < 1.6.4 < 1.4.0, 1.6.4
kargo >= 1.7.0-rc.1, < 1.7.9 < 1.7.0-rc.1, 1.7.9
kargo >= 1.8.0-rc.1, < 1.8.12 < 1.8.0-rc.1, 1.8.12
