THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-r2v3-8gwf-7ghm (critical) — vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API

[GHSA] GHSA-r2v3-8gwf-7ghm (critical) — vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API

highgithub_advisoriesPublished 2026-07-31

GHSA-r2v3-8gwf-7ghm Severity: critical CVE: CVE-2026-54725

vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API

## Summary

The vault-secrets-webhook reads the `vault.security.banzaicloud.io/vault-addr` annotation from any ConfigMap or Secret being admitted and uses it as the

Indicators of compromise

Original source: https://github.com/advisories/GHSA-r2v3-8gwf-7ghm