<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:kubesphere:kubesphere:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3akubespherekubesphere/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 15 Sep 2026 13:40:43 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3akubespherekubesphere/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>SSRF Vulnerability in KubeSphere Git Credential Verification</title><link>https://feed.craftedsignal.io/briefs/2026-09-kubesphere-ssrf/</link><pubDate>Tue, 15 Sep 2026 13:40:43 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-kubesphere-ssrf/</guid><description>KubeSphere versions up to 4.1.3 contain a server-side request forgery (SSRF) vulnerability in the git credential verification endpoint, allowing authenticated attackers to exfiltrate Kubernetes Secrets.</description><content:encoded><![CDATA[<p>KubeSphere versions through 4.1.3 contain a server-side request forgery (SSRF) vulnerability located within the platform's git credential verification endpoint. The vulnerability arises because the endpoint fails to enforce allowlist restrictions on user-supplied URLs. An authenticated attacker can exploit this flaw to force the KubeSphere server to make unauthorized requests to internal network services. By manipulating the input and observing the subsequent error response handling, an attacker can exfiltrate basic-authentication credentials associated with Kubernetes Secrets located in any namespace within the cluster. This vulnerability, tracked as CVE-2026-91923, poses a significant risk to cluster integrity and sensitive data, as it allows for the escalation of privileges through the unauthorized access and retrieval of internal configuration and credential data.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this SSRF vulnerability allows an authenticated attacker to bypass intended network boundaries and access sensitive information, including basic-auth credentials stored within Kubernetes Secrets. This facilitates lateral movement and potentially full cluster compromise, as these secrets may contain keys for other services, databases, or third-party integrations.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade KubeSphere to a version beyond 4.1.3 to remediate CVE-2026-91923.</li>
<li>Audit access logs for the KubeSphere git credential verification endpoint to identify anomalous requests containing internal IP ranges or sensitive ports.</li>
<li>Apply network policies to restrict egress traffic from the KubeSphere controller/API pod to only required external endpoints, preventing internal network scanning.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>