LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-32828

akuity · kargo

Published
CVSS4.9
Severitymedium
WeaknessCWE-918
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Description

Kargo manages and automates the promotion of software artifacts. In versions 1.4.0 through 1.6.3, 1.7.0-rc.1 through 1.7.8, 1.8.0-rc.1 through 1.8.11, and 1.9.0-rc.1 through 1.9.4, the http and http-download promotion steps allow Server-Side Request Forgery (SSRF) against link-local addresses, most critically the cloud instance metadata endpoint (169.254.169.254), enabling exfiltration of sensitive data such as IAM credentials. These steps provide full control over request headers and methods, rendering cloud provider header-based SSRF mitigations ineffective. An authenticated attacker with permissions to create/update Stages or craft Promotion resources can exploit this by submitting a mali

References

← Back to the CVE Tracker

Our coverage of CVE-2026-32828

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-32828.