Vulnerability GHSA-q7hv-xx6h-q2x8

High Risk
HIGH RISK
CVSS Score: 7.1
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
2 hours ago
October 06, 2026 at 03:29 PM UTC
External Secrets Operator: label enforcement bypass in webhook generator enables secret exfiltration
v0.10.0 - v1.3.1
v0.10.0 - v1.3.1

Summary

External Secrets Operator: label enforcement bypass in webhook generator enables secret exfiltration

Details

Summary

A bug in the webhook generator initialization order incorrectly cleared the label-enforcement flag (EnforceLabels) after it was set, resulting in the provider-side check for external-secrets.io/type=webhook being skipped (and the operation to succeed while it should have failed with secret does not contain needed label 'external-secrets.io/type: webhook'. Update secret label to use it with webhook.

Impact

A user with the permission to create webhook generator can set the webhook generator to a victim' secret (which was not previously labelled for webhook's use), and exfiltrate it to a malicious URL.

Mitigations

Until you upgrade, you can reduce risk by:

  • disabling webhook generators if not needed (or denying generators.external-secrets.io/v1alpha1 Webhook via an admission policy);
  • restricting RBAC: limit who can create generators of kind Webhook;
  • enforcing an admission policy (OPA Gatekeeper / Kyverno) requiring referenced secrets to be labeled external-secrets.io/type=webhook;
  • restricting egress from external-secrets controller pods to an allowlist (kubernetes NetworkPolicy / service mesh egress policy).

References

  • PR #5901 (fix: webhook initialization order)

Timeline

Published
2 hours ago
October 06, 2026 at 03:29 PM UTC
Last Modified
2 hours ago
October 06, 2026 at 03:46 PM UTC