Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-77v3-r3jw-j2v2 | External Secrets Operator insecurely retrieves secrets through the getSecretKey templating function |
Wed, 18 Feb 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
External-secrets external Secrets Operator
|
|
| CPEs | cpe:2.3:a:external-secrets:external_secrets_operator:*:*:*:*:*:*:*:* | |
| Vendors & Products |
External-secrets external Secrets Operator
|
Fri, 23 Jan 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
External-secrets
External-secrets external-secrets |
|
| Vendors & Products |
External-secrets
External-secrets external-secrets |
Fri, 23 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Thu, 22 Jan 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 21 Jan 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Starting in version 0.20.2 and prior to version 1.2.0, the `getSecretKey` template function, while introduced for senhasegura Devops Secrets Management (DSM) provider, has the ability to fetch secrets cross-namespaces with the roleBinding of the external-secrets controller, bypassing our security mechanisms. This function was completely removed in version 1.2.0, as everything done with that templating function can be done in a different way while respecting External Secrets Operator's safeguards As a workaround, use a policy engine such as Kubernetes, Kyverno, Kubewarden, or OPA to prevent the usage of `getSecretKey` in any ExternalSecret resource. | |
| Title | External Secrets Operator insecurely retrieves secrets through the getSecretKey templating function | |
| Weaknesses | CWE-863 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-22T16:50:23.708Z
Reserved: 2026-01-09T22:50:10.289Z
Link: CVE-2026-22822
Updated: 2026-01-22T15:10:58.931Z
Status : Analyzed
Published: 2026-01-21T22:15:49.380
Modified: 2026-02-18T15:29:01.850
Link: CVE-2026-22822
OpenCVE Enrichment
Updated: 2026-04-18T04:15:05Z
Github GHSA