kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token
Fixed in: 1.16.4
details
- Finding IDs
- F-KYVERNO-APICALL-001
- CVE
- CVE-2026-40868
- GHSA
- GHSA-q93q-v844-jrqp
- Status
- patched
- Fixed in
- 1.16.4
- Recorded credit
- reporter: @1seal
- Note
- GHSA-q93q-v844-jrqp
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- CVE registry state
- PUBLISHED
- CVE state checked
- Upstream title
- kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream @1seal credit
- @1seal: reporter (accepted)
F-KYVERNO-APICALL-001: Outbound request trust. A policy-controlled API destination receives ambient credentials. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-KYVERNO-APICALL-001
Security area (1seal assessment): Authorization. A policy-controlled API destination receives ambient credentials. Reviewed 24 Sep 2026.