{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3akubespherekubesphere/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:kubesphere:kubesphere:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.7,"id":"CVE-2026-91923"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["KubeSphere (\u003c= 4.1.3)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["KubeSphere"],"content_html":"\u003cp\u003eKubeSphere versions through 4.1.3 contain a server-side request forgery (SSRF) vulnerability located within the platform's git credential verification endpoint. The vulnerability arises because the endpoint fails to enforce allowlist restrictions on user-supplied URLs. An authenticated attacker can exploit this flaw to force the KubeSphere server to make unauthorized requests to internal network services. By manipulating the input and observing the subsequent error response handling, an attacker can exfiltrate basic-authentication credentials associated with Kubernetes Secrets located in any namespace within the cluster. This vulnerability, tracked as CVE-2026-91923, poses a significant risk to cluster integrity and sensitive data, as it allows for the escalation of privileges through the unauthorized access and retrieval of internal configuration and credential data.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this SSRF vulnerability allows an authenticated attacker to bypass intended network boundaries and access sensitive information, including basic-auth credentials stored within Kubernetes Secrets. This facilitates lateral movement and potentially full cluster compromise, as these secrets may contain keys for other services, databases, or third-party integrations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade KubeSphere to a version beyond 4.1.3 to remediate CVE-2026-91923.\u003c/li\u003e\n\u003cli\u003eAudit access logs for the KubeSphere git credential verification endpoint to identify anomalous requests containing internal IP ranges or sensitive ports.\u003c/li\u003e\n\u003cli\u003eApply network policies to restrict egress traffic from the KubeSphere controller/API pod to only required external endpoints, preventing internal network scanning.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T13:40:43Z","date_published":"2026-09-15T13:40:43Z","id":"https://feed.craftedsignal.io/briefs/2026-09-kubesphere-ssrf/","summary":"KubeSphere versions up to 4.1.3 contain a server-side request forgery (SSRF) vulnerability in the git credential verification endpoint, allowing authenticated attackers to exfiltrate Kubernetes Secrets.","title":"SSRF Vulnerability in KubeSphere Git Credential Verification","url":"https://feed.craftedsignal.io/briefs/2026-09-kubesphere-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:kubesphere:kubesphere:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}