📦 External Secrets Operator

by External Secrets

🔍 What is External Secrets Operator?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-22822

HIGH CVSS 8.8 Jan 21, 2026

The External Secrets Operator's getSecretKey template function allows cross-namespace secret retrieval, bypassing Kubernetes RBAC controls. This affects users of External Secrets Operator versions 0.2...

CVE-2024-45041

HIGH CVSS 8.3 Sep 9, 2024

External Secrets Operator versions before 0.10.2 have an overly permissive ClusterRole that allows the default-external-secrets-cert-controller deployment to read all secrets in the Kubernetes cluster...