Vulnerability GO-2026-5723

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
3 months ago
June 25, 2026 at 10:34 PM UTC
External Secrets Operator has Namespace Isolation Bypass in CAProvider ConfigMap Resolution for SecretStore in github.com/external-secrets/external-secrets
v0.1.0-esoctl - v1.3.2
v0.1.0-esoctl - v1.3.2

Summary

External Secrets Operator has Namespace Isolation Bypass in CAProvider ConfigMap Resolution for SecretStore in github.com/external-secrets/external-secrets

Details

External Secrets Operator has Namespace Isolation Bypass in CAProvider ConfigMap Resolution for SecretStore in github.com/external-secrets/external-secrets.

NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.

(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)

The additional affected modules and versions are: github.com/external-secrets/external-secrets before v2.4.0.

Timeline

Published
3 months ago
June 25, 2026 at 10:34 PM UTC
Last Modified
3 months ago
June 25, 2026 at 11:01 PM UTC