A critical vulnerability affecting github.com/bank-vaults/vault-secrets-webhook versions <= 1.22.2 CVE-2026-54725 exists in the vault-secrets-webhook component, affecting versions prior to 1.23.1. This flaw is a server-side request forgery (SSRF) issue that allows an attacker to cause the webhook process to make arbitrary outbound HTTP connections and exfiltrate ServiceAccount JWTs. The vulnerability occurs when the webhook's admission handler reads the 'vault-addr' annotation from ConfigMaps or Secrets without any validation, allowing an attacker to specify a malicious address for the Vault server. This can be exploited by creating a ConfigMap or Secret in a watched namespace with malicious annotations, triggering the webhook process to make outbound HTTP connections and exfiltrate ServiceAccount JWTs. The attack requires no special privileges beyond create/update rights on ConfigMaps or Secrets and happens at admission time in the webhook server process. A user with these rights can cause the webhook process to make arbitrary outbound HTTP connections to any address, including cloud IMDS, and replay the obtained JWT against the real Vault server to access secrets authorized for the ServiceAccount's role. The CVSS v3 score is 9.6 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N), indicating a high severity impact on business operations.
We recommend you to update vault-secrets-webhook to version 1.23.1.[/subscribe_to_unlock_form]
A critical vulnerability affecting github.com/bank-vaults/vault-secrets-webhook versions <= 1.22.2 CVE-2026-54725 exists in the vault-secrets-webhook component, affecting versions prior to 1.23.1. This flaw is a server-side request forgery (SSRF) issue that allows an attacker to cause the webhook process to make arbitrary outbound HTTP connections and exfiltrate ServiceAccount JWTs. The vulnerability occurs when the webhook's admission handler reads the 'vault-addr' annotation from ConfigMaps or Secrets without any validation, allowing an attacker to specify a malicious address for the Vault server. This can be exploited by creating a ConfigMap or Secret in a watched namespace with malicious annotations, triggering the webhook process to make outbound HTTP connections and exfiltrate ServiceAccount JWTs. The attack requires no special privileges beyond create/update rights on ConfigMaps or Secrets and happens at admission time in the webhook server process. A user with these rights can cause the webhook process to make arbitrary outbound HTTP connections to any address, including cloud IMDS, and replay the obtained JWT against the real Vault server to access secrets authorized for the ServiceAccount's role. The CVSS v3 score is 9.6 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N), indicating a high severity impact on business operations.
We recommend you to update vault-secrets-webhook to version 1.23.1.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]