OVERVIEW CVE-2026-34984 affects External Secrets Operator (ESO) versions 2.2.0 and below. The vulnerability exists in the v2 template engine, where the getHostByName function remains accessible to user-controlled templates despite other dangerous functions being removed. This enables DNS-based exfiltration of sensitive secrets stored within Kubernetes clusters. SEVERITY The vulnerability carries a CVSS score of 6.5 (Medium) with a network-based attack vector, low complexity, and low privilege requirements. An attacker with permissions to create or update templated ExternalSecret resources can exploit this flaw. The primary impact is confidentiality loss, as secret material can be leaked through DNS queries without requiring the attacker to maintain direct outbound network access from their workload. The vulnerability does not enable modification or denial of service. EXPLOITATION STATUS Currently, there is no indication of active exploitation in the wild. The exploit is not listed on the KEV catalog and the EPSS score of 0.00034 indicates minimal community exploitation activity. However, the vulnerability is straightforward to weaponize for organizations where lower-trust users can create ExternalSecret resources and the controller has DNS resolution capabilities. The fix has been available in version 2.3.0, and affected organizations should prioritize upgrades to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.0CPE matchmatch criteria | cpe:2.3:a:external-secrets:external_secrets_operator:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.