External-Secrets vulnerabilities
7 known vulnerabilities affecting external-secrets/external-secrets.
Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2024-45041P3HIGHCVSS 8.8fixed in 0.10.22024-09-09
CVE-2024-45041 [HIGH] CWE-269 CVE-2024-45041: External Secrets Operator is a Kubernetes operator that integrates external secret management system
External Secrets Operator is a Kubernetes operator that integrates external secret management systems. The external-secrets has a deployment called default-external-secrets-cert-controller, which is bound with a same-name ClusterRole. This ClusterRole has "get/list" verbs of secrets resources. It also has path/update verb of validatingwebhookconfigura
nvd
CVE-2025-62159P3HIGHCVSS 8.7v>= 0.10.1, < 0.20.02025-10-10
CVE-2025-62159 [HIGH] CWE-284 CVE-2025-62159: External Secrets Operator reads information from a third-party service and automatically injects the
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. A vulnerability was discovered in the BeyondTrust provider implementation for External Secrets Operator versions 0.10.1 through 0.19.2. The provider previously retrieved Kubernetes secrets directly, without validating the
nvd
CVE-2026-22822P3HIGHCVSS 8.8v>= 0.20.2, < 1.2.02026-01-21
CVE-2026-22822 [HIGH] CWE-863 CVE-2026-22822: External Secrets Operator reads information from a third-party service and automatically injects the
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.20.2 and prior to version 1.2.0, the `getSecretKey` template function, while introduced for senhasegura Devops Secrets Management (DSM) provider, has the ability to fetch secrets cross-namespaces with
nvd
CVE-2025-55196P3HIGHCVSS 7.1v>= 0.15.0, < 0.19.22025-08-13
CVE-2025-55196 [HIGH] CWE-284 CVE-2025-55196: External Secrets Operator is a Kubernetes operator that integrates external secret management system
External Secrets Operator is a Kubernetes operator that integrates external secret management systems. From version 0.15.0 to before 0.19.2, a vulnerability was discovered where the List() calls for Kubernetes Secret and SecretStore resources performed by the PushSecret controller did not apply a namespace selector. This flaw allowed an attacker to us
nvd
CVE-2026-34984P3MEDIUMCVSS 6.5fixed in 2.3.02026-04-14
CVE-2026-34984 [MEDIUM] CWE-200 CVE-2026-34984: External Secrets Operator reads information from a third-party service and automatically injects the
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Versions 2.2.0 and below contain a vulnerability in runtime/template/v2/template.go where the v2 template engine removes env and expandenv from Sprig's TxtFuncMap() but leaves the getHostByName function accessible to use
nvd
CVE-2026-42875P4MEDIUMCVSS 5.3fixed in 2.4.02026-05-11
CVE-2026-42875 [MEDIUM] CWE-285 CVE-2026-42875: External Secrets Operator reads information from a third-party service and automatically injects the
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Prior to 2.4.0, Namespaced SecretStore resources that used CAProvider with type ConfigMap could resolve CA material from another namespace when caProvider.namespace was set. This bypassed the namespace boundary enforced
nvd
CVE-2026-42876P4MEDIUMCVSS 4.9fixed in 2.4.12026-05-11
CVE-2026-42876 [MEDIUM] CWE-285 CVE-2026-42876: External Secrets Operator reads information from a third-party service and automatically injects the
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Prior to 2.4.1, a user who only has permission to create ExternalSecret resources can cause the operator to create a Secret that Kubernetes will automatically populate with a long-lived token for the specified service ac
nvd