VDB
KO

GO-2026-5268

Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno

Details

Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / github.com/kyverno/kyverno
Introduced in: 0 Fixed in: 1.17.0
Fix go get github.com/kyverno/kyverno@v1.17.0

References