CVE-2026-4789 Details
Description
Kyverno, versions 1.16.0 and later, are vulnerable to SSRF due to unrestricted CEL HTTP functions.
A server-side request forgery (SSRF) vulnerability has been identified in Kyverno versions 1.16.0 and later. This vulnerability arises from unrestricted HTTP functions in the Common Expression Language (CEL) used by namespaced policies, allowing arbitrary internal HTTP requests to be made from the Kyverno admission controller pod. An attacker with only namespace-level permissions can exploit this to access sensitive internal services or cloud metadata via the Kyverno admission controller, which often has privileged network access.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.kb.cert.org/vuls/id/655822 | CVE | Third Party Advisory |
| https://github.com/kyverno/kyverno | [email protected] | Product |
| https://kb.cert.org/vuls/id/655822 | [email protected] | Third Party Advisory |
| https://portswigger.net/web-security/ssrf | [email protected] | Technical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| kyverno kyverno | >= 1.16.0, <= 1.17.1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 3, 2026 | Initial Analysis | [email protected] |
| Apr 1, 2026 | CVE Modified | CISA-ADP |
| Mar 30, 2026 | CVE Modified | CVE |
| Mar 30, 2026 | New CVE Received | [email protected] |