{"id":"CVE-2026-54725","summary":"vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API","details":"vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/config.go accepts the vault.security.banzaicloud.io/vault-addr annotation, MutateConfigMap and MutateSecret call newVaultClient in pkg/webhook/webhook.go, and vault.security.banzaicloud.io/vault-serviceaccount can cause a ServiceAccount JWT to be sent to an attacker-controlled Vault address. This issue is fixed in version 1.23.1.","aliases":["GHSA-r2v3-8gwf-7ghm","GO-2026-6160"],"modified":"2026-09-12T03:30:29.928911798Z","published":"2026-07-31T17:45:09.548Z","related":["openSUSE-SU-2026:21761-1"],"database_specific":{"cwe_ids":["CWE-918"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54725.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/bank-vaults/vault-secrets-webhook/releases/tag/v1.23.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54725.json"},{"type":"ADVISORY","url":"https://github.com/bank-vaults/vault-secrets-webhook/security/advisories/GHSA-r2v3-8gwf-7ghm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54725"},{"type":"FIX","url":"https://github.com/bank-vaults/vault-secrets-webhook/commit/76db45976fee0f54cafd94dffa425e6b542f65a0"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bank-vaults/vault-secrets-webhook","events":[{"introduced":"0"},{"fixed":"76db45976fee0f54cafd94dffa425e6b542f65a0"},{"fixed":"0aea3939ce1b4cd9775f34d5ebd90c7abd62a0b6"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"1.23.1"}]}}],"versions":["v1.23.0","v1.22.2","v1.22.1","v1.22.0","v1.21.4","v1.21.3","v1.21.2","v1.21.1","v1.21.0","v1.20.0","v1.20.0-dev.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54725.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"}]}