{"id":"GO-2026-5351","summary":"Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno","details":"Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno","aliases":["BIT-kyverno-2026-41323","CVE-2026-41323","GHSA-f9g8-6ppc-pqq4"],"modified":"2026-06-25T19:56:36.059134840Z","published":"2026-06-25T18:43:19Z","database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2026-5351"},"references":[{"type":"ADVISORY","url":"https://github.com/kyverno/kyverno/security/advisories/GHSA-f9g8-6ppc-pqq4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41323"},{"type":"FIX","url":"https://github.com/kyverno/kyverno/commit/bc4f91c4801b1eaa2edc0a14e2f1b0af8cf0c1f5"},{"type":"FIX","url":"https://github.com/kyverno/kyverno/commit/c2eab00033e635bda4e4efb58c1b472b41728bb6"},{"type":"FIX","url":"https://github.com/kyverno/kyverno/commit/f70e8ac1e7acd2e3844f9553e4a884f07f953de0"}],"affected":[{"package":{"name":"github.com/kyverno/kyverno","ecosystem":"Go","purl":"pkg:golang/github.com/kyverno/kyverno"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.17.0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-5351.json"}}],"schema_version":"1.7.5"}