Description
KubeSphere through 4.1.3 contains a server-side request forgery vulnerability in the git credential verification endpoint that accepts unvalidated caller-supplied URLs without allowlist restrictions. Authenticated attackers can supply arbitrary URLs to reach internal services and exfiltrate basic-auth credentials from Secrets in any namespace by leveraging the endpoint's error response handling.
Published: 2026-09-15
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Server-side request forgery allowing internal credential exfiltration
Action: Immediate Patch
AI Analysis

Impact

KubeSphere versions up to 4.1.3 contain an SSRF vulnerability in the git credential verification endpoint. The endpoint accepts caller–supplied URLs without validation or allowlist restrictions, and error responses can reveal basic‑auth credentials stored in Secrets. An attacker who can authenticate to the cluster can supply malicious URLs that reach internal or private services, potentially exfiltrating credentials used by the cluster or applications.

Affected Systems

KubeSphere, any installation using version 4.1.3 or earlier. The vulnerability is present in all deployments that expose the git credential verification endpoint and have authentication enabled for the cluster.

Risk and Exploitability

The CVSS score of 8.3 indicates high severity. The EPSS score is reported as less than 1%, suggesting a low exploitation probability, but the potential for internal credential exfiltration and the absence of a KEV listing keep the vulnerability’s risk posture high. An attacker would need authenticated cluster access to supply arbitrary URLs to the git credential verification endpoint, which would then be resolved to internal endpoints; error handling could return credential data in the response. No publicly available exploit exists, so discovery would rely on internal reconnaissance or manual probing, yet the serious impact justifies immediate mitigation.

Generated by OpenCVE AI on September 17, 2026 at 17:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to an affected‑vulnerable version that is newer than 4.1.3, or apply the developers’ patch for the git credential verification endpoint.
  • If upgrade is not immediate, limit the network scope of that block outbound traffic to internal or private addresses and permit only whitelisted destinations.
  • If the git credential verification feature is unused, disable or remove the endpoint entirely from the KubeSphere deployment.

Generated by OpenCVE AI on September 17, 2026 at 17:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Kubesphere
Kubesphere kubesphere
Vendors & Products Kubesphere
Kubesphere kubesphere

Tue, 15 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Description KubeSphere through 4.1.3 contains a server-side request forgery vulnerability in the git credential verification endpoint that accepts unvalidated caller-supplied URLs without allowlist restrictions. Authenticated attackers can supply arbitrary URLs to reach internal services and exfiltrate basic-auth credentials from Secrets in any namespace by leveraging the endpoint's error response handling.
Title KubeSphere through 4.1.3 SSRF via git credential verification endpoint
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


Subscriptions

Kubesphere Kubesphere
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:28.883Z

Reserved: 2026-09-15T10:42:43.665Z

Link: CVE-2026-91923

cve-icon Vulnrichment

Updated: 2026-09-18T17:16:56.310Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T11:17:12.897

Modified: 2026-09-24T21:08:55.030

Link: CVE-2026-91923

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:30:17Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)