CVE-2026-29954 describes a high-severity Server-Side Request Forgery (SSRF) vulnerability in KubePlus 4.1.4, affecting its mutating webhook and kubeconfiggenerator components. This flaw allows an attacker to inject arbitrary HTTP headers into `wget` commands by manipulating the `chartURL` field of `ResourceComposition` resources, due to improper validation and direct command concatenation. Rated with a CVSS score of 7.6 (High), successful exploitation requires high privileges but has low attack complexity, potentially leading to significant confidentiality impact and minor integrity compromise. There is currently no evidence of active exploitation, nor are public exploit modules or widespread media coverage available, though it has received minor community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.1.4CPE matchmatch criteria | cpe:2.3:a:cloudark:kubeplus:4.1.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.