external-secrets vulnerabilities
CVEs whose affected-version data names the external-secrets package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-26287High· 7.1External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.10.0 and prior to version 1.3.2, a bug in the `webhook` generator initialization ord…
▾ Twilightexternal-secrets · external-secretsvia NVD
CVE-2026-42876Medium· 4.9External Secrets Operator: Privilege escalation with secret overwriting
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Prior to 2.4.1, a user who only has permission to create ExternalSecret resources can cause the operator t…
▾ Sunlitexternal-secrets · external-secretsEPSS 0.26%via CVEORG