THREAT OPS › Threat News › [GHSA] GHSA-r2v3-8gwf-7ghm (critical) — vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API
[GHSA] GHSA-r2v3-8gwf-7ghm (critical) — vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API
GHSA-r2v3-8gwf-7ghm Severity: critical CVE: CVE-2026-54725
vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API
## Summary
The vault-secrets-webhook reads the `vault.security.banzaicloud.io/vault-addr` annotation from any ConfigMap or Secret being admitted and uses it as the
Indicators of compromise
- CVE-2026-54725cve
- http://169.254.169.254/latest/meta-data/url
- http://169.254.169.254/latest/meta-data/`url
- http://169.254.169.254/latest/meta-data/v1/auth/kubernetes/login`url
- vault.security.banzaicloud.iodomain
Original source: https://github.com/advisories/GHSA-r2v3-8gwf-7ghm