VDB
GO-2026-4330
GO-2026-4330
PUBLISHED
External Secrets Operator insecurely retrieves secrets through the getSecretKey templating function in github.com/external-secrets/external-secrets
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | external-secrets/external-secrets | 0.20.2, 0.20.2 |
Timeline
- Feb 3, 2026 CVE Published
- Apr 16, 2026 CVE Updated
References
- https://github.com/external-secrets/external-secrets/security/advisories/GHSA-77v3-r3jw-j2v2 advisory
- https://github.com/external-secrets/external-secrets/commit/17d3e22b8d3fbe339faf8515a95ec06ec92b1feb patch
- https://github.com/external-secrets/external-secrets/pull/3895 patch
- https://github.com/external-secrets/external-secrets/issues/5690 report
- https://github.com/external-secrets/external-secrets/releases/tag/v1.2.0 url