Server-Side Request Forgery Vulnerability in Kargo by Akuity
CVE-2026-32828

5.1MEDIUM

Key Information:

Vendor

Akuity

Status
Vendor
CVE Published:
20 March 2026

What is CVE-2026-32828?

A vulnerability in Kargo allows for Server-Side Request Forgery (SSRF) attacks via the http and http-download promotion steps. This issue affects versions 1.4.0 to 1.9.4 and enables unauthorized access to link-local addresses, prominently the cloud metadata endpoint (169.254.169.254). Attackers can exfiltrate sensitive data, including IAM credentials, by crafting malicious Promotion manifests. Users are advised to update to the secure versions (1.6.4, 1.7.9, 1.8.12, 1.9.5) to mitigate this risk.

Affected Version(s)

kargo >= 1.4.0, < 1.6.4 < 1.4.0, 1.6.4

kargo >= 1.7.0-rc.1, < 1.7.9 < 1.7.0-rc.1, 1.7.9

kargo >= 1.8.0-rc.1, < 1.8.12 < 1.8.0-rc.1, 1.8.12

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.