Server-Side Request Forgery in KubeSphere Git Credential Verification Endpoint
CVE-2026-91923
8.3HIGH
What is CVE-2026-91923?
KubeSphere, up to version 4.1.3, presents a server-side request forgery vulnerability in its git credential verification endpoint. This flaw allows authenticated users to exploit unvalidated caller-supplied URLs without any allowlist restrictions. By leveraging error responses from the endpoint, attackers can craft arbitrary URLs that reach internal services and potentially exfiltrate sensitive basic-auth credentials from Secrets across various namespaces. This risk emphasizes the importance of implementing strict validation protocols to safeguard exposure of internal resources.
Affected Version(s)
kubesphere 0 <= 4.1.3
