Server-side Request Forgery (SSRF) Affecting github.com/kyverno/kyverno/pkg/engine/factories package, versions <1.15.3-rc.1>=1.16.0-rc.1 <1.16.3-rc.1


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.54% (43rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMKYVERNOKYVERNOPKGENGINEFACTORIES-15123996
  • published28 Jan 2026
  • disclosed27 Jan 2026
  • creditVille Vesilehto

Introduced: 27 Jan 2026

CVE-2026-22039  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade github.com/kyverno/kyverno/pkg/engine/factories to version 1.15.3-rc.1, 1.16.3-rc.1 or higher.

Overview

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via apiCall. An attacker can gain unauthorized access to sensitive resources and escalate privileges via malicious urlPath values that cause the system to perform Kubernetes API requests outside the intended namespace or scope, with the admission controller's service account permissions. This can result in reading or modifying resources across namespaces or at the cluster level.

CVSS Base Scores

version 4.0
version 3.1