Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2 advisories

Loading
External Secrets Operator insecurely retrieves secrets through the getSecretKey templating function Critical
CVE-2026-22822 was published for github.com/external-secrets/external-secrets (Go) Jan 20, 2026
evrardjp Credited to evrardjp, budimanjojo, and gusfcarvalho budimanjojo budimanjojo
gusfcarvalho gusfcarvalho
External Secrets Operator: label enforcement bypass in webhook generator enables secret exfiltration High
CVE-2026-26287 was published for github.com/external-secrets/external-secrets (Go) Oct 6, 2026
1seal Credited to 1seal, gusfcarvalho, and evrardj-roche gusfcarvalho gusfcarvalho
evrardj-roche evrardj-roche
ProTip! Advisories are also available from the GraphQL API