{"id":"CVE-2026-29954","details":"In KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF vulnerability when processing the chartURL field of ResourceComposition resources. The field is only URL-encoded without validating the target address. More critically, when kubeconfiggenerator uses wget to download charts, the chartURL is directly concatenated into the command, allowing attackers to inject wget's `--header` option to achieve arbitrary HTTP header injection.","modified":"2026-07-15T01:49:11.382409608Z","published":"2026-03-30T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/29xxx/CVE-2026-29954.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"https://gist.github.com/b0b0haha/33baea60fd2a847f11f1fb02e43c64c0"},{"type":"WEB","url":"https://github.com/b0b0haha/CVE-2026-29954/blob/main/README.md"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/29xxx/CVE-2026-29954.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-29954"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cloud-ark/kubeplus","events":[{"introduced":"5d1a577f4b4a51e363ad125a5a50891aa65311ea"},{"last_affected":"5d1a577f4b4a51e363ad125a5a50891aa65311ea"}],"database_specific":{"cpe":"cpe:2.3:a:cloudark:kubeplus:4.1.4:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.1.4"},{"last_affected":"4.1.4"}],"source":"CPE_STRING"}}],"versions":["4.1.4","kubeplus-kubectl-plugins-v4.1.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-29954.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N"}]}