GHSA-q7hv-xx6h-q2x8HighCVSS 7.1

External Secrets Operator: label enforcement bypass in webhook generator enables secret exfiltration

Published
October 6, 2026
Last Modified
October 6, 2026

🔗 CVE IDs covered (1)

📋 Description

Summary

A bug in the webhook generator initialization order incorrectly cleared the label-enforcement flag (EnforceLabels) after it was set, resulting in the provider-side check for external-secrets.io/type=webhook being skipped (and the operation to succeed while it should have failed with secret does not contain needed label 'external-secrets.io/type: webhook'. Update secret label to use it with webhook.

Impact

A user with the permission to create webhook generator can set the webhook generator to a victim' secret (which was not previously labelled for webhook's use), and exfiltrate it to a malicious URL.

Mitigations

Until you upgrade, you can reduce risk by:

  • disabling webhook generators if not needed (or denying generators.external-secrets.io/v1alpha1 Webhook via an admission policy);
  • restricting RBAC: limit who can create generators of kind Webhook;
  • enforcing an admission policy (OPA Gatekeeper / Kyverno) requiring referenced secrets to be labeled external-secrets.io/type=webhook;
  • restricting egress from external-secrets controller pods to an allowlist (kubernetes NetworkPolicy / service mesh egress policy).

References

  • PR #5901 (fix: webhook initialization order)

🎯 Affected products1

  • go/github.com/external-secrets/external-secrets:>= 0.10.0, < 1.3.2

🔗 References (5)