—
GO-2026-6160
vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API in github.com/bank-vaults/vault-secrets-webhook
Quick fix
GO-2026-6160 — github.com/bank-vaults/vault-secrets-webhook: upgrade to the fixed version with the command below.
go get github.com/bank-vaults/vault-secrets-webhook@v1.23.1Details
vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API in github.com/bank-vaults/vault-secrets-webhook
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/bank-vaults/vault-secrets-webhook
Introduced in:
0Fixed in: 1.23.1Fix
go get github.com/bank-vaults/vault-secrets-webhook@v1.23.1