CVE-2026-91923
EUVD-2026-7841415.09.2026, 11:17
KubeSphere through 4.1.3 contains a server-side request forgery vulnerability in the git credential verification endpoint that accepts unvalidated caller-supplied URLs without allowlist restrictions. Authenticated attackers can supply arbitrary URLs to reach internal services and exfiltrate basic-auth credentials from Secrets in any namespace by leveraging the endpoint's error response handling.
Awaiting analysis
This vulnerability is currently awaiting analysis.
References