GHSA-wv26-88m5-6h59

Suggest an improvement
Source
https://github.com/advisories/GHSA-wv26-88m5-6h59
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-wv26-88m5-6h59/GHSA-wv26-88m5-6h59.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-wv26-88m5-6h59
Aliases
Downstream
CGA (36)
MINI (2)
Published
2026-05-05T18:37:12Z
Modified
2026-09-10T03:50:47Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
External Secrets Operator has Namespace Isolation Bypass in CAProvider ConfigMap Resolution for SecretStore
Details

Impact

Namespaced SecretStore resources that used CAProvider with type ConfigMap could resolve CA material from another namespace when caProvider.namespace was set. This bypassed the namespace boundary enforced for SecretStore-backed references in providers that rely on the shared runtime CA resolver.

The accessible data is used as CA validation material, hence it is not directly exposed.

Impact:

  • Direct data exfiltration risk: low
  • Existence disclosure: an attacker can infer whether a target ConfigMap/key exists in another namespace.
  • Trust-boundary violation: a tenant can make its SecretStore consume CA material owned by another namespace.
Database specific
{
    "cwe_ids":  [
        "CWE-285",
        "CWE-668"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-05-05T18:37:12Z",
    "nvd_published_at":  "2026-05-11T20:25:44Z",
    "severity":  "MODERATE"
}
References

Affected packages

Go / github.com/external-secrets/external-secrets

Package

Name
github.com/external-secrets/external-secrets
View open source insights on deps.dev
Purl
pkg:golang/github.com/external-secrets/external-secrets

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.4.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-wv26-88m5-6h59/GHSA-wv26-88m5-6h59.json"