Vulnerability GHSA-wv26-88m5-6h59
Medium Risk
MEDIUM RISK
CVSS Score: 6.0
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
5 months ago
May 05, 2026 at 06:37 PM UTC
External Secrets Operator has Namespace Isolation Bypass in CAProvider ConfigMap Resolution for SecretStore
v0.1.0-esoctl - v1.3.2
v0.1.0-esoctl - v1.3.2
Summary
External Secrets Operator has Namespace Isolation Bypass in CAProvider ConfigMap Resolution for SecretStore
Details
Impact
Namespaced SecretStore resources that used CAProvider with type ConfigMap could resolve CA material from another namespace when caProvider.namespace was set. This bypassed the namespace boundary enforced for SecretStore-backed references in providers that rely on the shared runtime CA resolver.
The accessible data is used as CA validation material, hence it is not directly exposed.
Impact:
- Direct data exfiltration risk: low
- Existence disclosure: an attacker can infer whether a target ConfigMap/key exists in another namespace.
- Trust-boundary violation: a tenant can make its SecretStore consume CA material owned by another namespace.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
3 hours ago
External Secrets Operator: label enforcement bypass in webhook generator enables secret exfiltration
v0.10.0 - v1.3.1 GHSA-q7hv-xx6h-q2x8
v0.10.0 - v1.3.1 GHSA-q7hv-xx6h-q2x8
Unknown
3 months ago
External Secrets Operator has Namespace Isolation Bypass in CAProvider ConfigMap Resolution for SecretStore in github.com/external-secrets/external-secrets
v0.1.0-esoctl - v1.3.2 GO-2026-5723
v0.1.0-esoctl - v1.3.2 GO-2026-5723
Unknown
3 months ago
External Secrets Operator has DNS-based secret exfiltration via getHostByName in External Secrets v2 template engine in github.com/external-secrets/external-secrets
v0.1.0-esoctl - v1.3.2 GO-2026-5602
v0.1.0-esoctl - v1.3.2 GO-2026-5602
Medium Risk
5 months ago
External Secrets Operator has DNS-based secret exfiltration via getHostByName in External Secrets v2 template engine
v0.1.0-esoctl - v1.3.2 GHSA-r2pg-r6h7-crf3
v0.1.0-esoctl - v1.3.2 GHSA-r2pg-r6h7-crf3
Unknown
8 months ago
External Secrets Operator insecurely retrieves secrets through the getSecretKey templating function in github.com/external-secrets/external-secrets
v0.20.2 - v1.1.1 GO-2026-4330
v0.20.2 - v1.1.1 GO-2026-4330
Impacted packages
Timeline
Published
5 months ago
May 05, 2026 at 06:37 PM UTC
Last Modified
26 days ago
September 10, 2026 at 03:50 AM UTC