Root cause, affected code and disclosure timeline.
At a glance
Conditions
A tenant able to create requests using the git resolver can read files accessible to the resolver pod, including its credentials.
What to do
Use the listed patched release for your branch. Until updated, restrict access to the git resolver and reduce its service-account permissions. The upstream broad affected range overlaps its own patched list.
1seal reading guide, reviewed 2026-09-25 against the linked records. Not a new vendor assessment or a device rollout check.
Source assessments remain separate. Different CVSS versions are not a revision of one another. Code fixes, released versions and deployed updates are distinct evidence.
A tenant reaches cluster-wide secrets through a path-boundary failure in a shared resolver.
Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.
This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules.