| id: GO-2026-4330 |
| modules: |
| - module: github.com/external-secrets/external-secrets |
| versions: |
| - introduced: 0.20.2 |
| - fixed: 1.2.0 |
| vulnerable_at: 1.1.1 |
| summary: |- |
| External Secrets Operator insecurely retrieves secrets through the getSecretKey |
| templating function in github.com/external-secrets/external-secrets |
| cves: |
| - CVE-2026-22822 |
| ghsas: |
| - GHSA-77v3-r3jw-j2v2 |
| references: |
| - advisory: https://github.com/external-secrets/external-secrets/security/advisories/GHSA-77v3-r3jw-j2v2 |
| - fix: https://github.com/external-secrets/external-secrets/commit/17d3e22b8d3fbe339faf8515a95ec06ec92b1feb |
| - fix: https://github.com/external-secrets/external-secrets/pull/3895 |
| - report: https://github.com/external-secrets/external-secrets/issues/5690 |
| - web: https://github.com/external-secrets/external-secrets/releases/tag/v1.2.0 |
| source: |
| id: GHSA-77v3-r3jw-j2v2 |
| created: 2026-01-21T17:33:34.78725+08:00 |
| review_status: UNREVIEWED |