CLEANSTART-2026-VU72808

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-VU72808.json
JSON Data
https://api.osv.dev/v1/vulns/CLEANSTART-2026-VU72808
Upstream
  • CVE-2026-46600
  • CVE-2026-56852
  • ghsa-hfvc-g4fc-pqhx
  • ghsa-mh2q-q3fh-2475
  • ghsa-mpwr-8vm7-h73f
  • ghsa-pjcq-xvwq-hhpj
Published
2026-07-21T07:11:52.868291Z
Modified
2026-07-23T18:24:16.031267975Z
Summary
Security fixes for CVE-2025-61729, CVE-2026-25680, CVE-2026-25681, CVE-2026-27136, CVE-2026-32952, CVE-2026-39821, CVE-2026-39822, CVE-2026-39883, CVE-2026-42502, CVE-2026-42505, CVE-2026-42506, CVE-2026-46600, CVE-2026-56852, ghsa-hfvc-g4fc-pqhx, ghsa-mh2q-q3fh-2475, ghsa-mpwr-8vm7-h73f, ghsa-pjcq-xvwq-hhpj applied in versions: 1.1.0-r0, 2.4.1-r0, 2.5.0-r0, 2.6.0-r1, 2.6.0-r3
Details

Multiple security vulnerabilities affect the external-secrets-operator package. These issues are resolved in later releases. See references for individual vulnerability details.

References

Affected packages

CleanStart / external-secrets-operator

Package

Name
external-secrets-operator

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.6.0-r3

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-VU72808.json"