Server-Side Request Forgery in Kyverno Affects Kubernetes Security
CVE-2026-84196
8.3HIGH
What is CVE-2026-84196?
Kyverno versions prior to 1.18.0 are susceptible to a server-side request forgery (SSRF) vulnerability. This weakness allows authenticated users to exploit the apiCall.service.url endpoint, enabling them to inject user-controlled input through variable substitution. As a result, attackers can issue arbitrary HTTP requests targeting internal services, cloud metadata endpoints, and loopback addresses. The reflected response data in admission error messages facilitates non-blind data exfiltration, posing serious security risks for organizations relying on Kyverno for their Kubernetes security policies.
Affected Version(s)
kyverno 0 < 1.18.0
kyverno 1.18.0
