Vulnerability Description
External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Versions 2.2.0 and below contain a vulnerability in runtime/template/v2/template.go where the v2 template engine removes env and expandenv from Sprig's TxtFuncMap() but leaves the getHostByName function accessible to user-controlled templates. Since ESO executes templates within the controller process, an attacker who can create or update templated ExternalSecret resources can invoke controller-side DNS lookups using secret-derived values. This creates a DNS exfiltration primitive, allowing fetched secret material to be leaked via DNS queries without requiring direct outbound network access from the attacker's workload. The impact is a confidentiality issue, particularly in environments where untrusted or lower-trust users can author templated ExternalSecret resources and the controller has DNS resolution capability. This issue has been fixed in version 2.3.0.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| External-Secrets | External Secrets Operator | < 2.3.0 |
Related Weaknesses (CWE)
References
- https://github.com/external-secrets/external-secrets/commit/6800989bdc12782ca260Patch
- https://github.com/external-secrets/external-secrets/releases/tag/v2.3.0ProductRelease Notes
- https://github.com/external-secrets/external-secrets/security/advisories/GHSA-r2Vendor Advisory
FAQ
What is CVE-2026-34984?
CVE-2026-34984 is a vulnerability with a CVSS score of 6.5 (MEDIUM). External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Versions 2.2.0 and below contain a vulnerability in runtime/template/...
How severe is CVE-2026-34984?
CVE-2026-34984 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-34984?
Check the references section above for vendor advisories and patch information. Affected products include: External-Secrets External Secrets Operator.