LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-29954

CVE-2026-29954 - Vulnerability Analysis

HighCVSS: 7.6

Last Updated: March 30, 2026

KubePlus - Server Side Request Forgery & HTTP Header Injection

Published: March 30, 2026Updated: March 30, 2026PoC AvailableRemote Exploitable

Overview

KubePlus 4.1.4 contains a server side request forgery caused by improper validation and direct concatenation of the chartURL field in mutating webhook and kubeconfiggenerator components, letting attackers inject arbitrary HTTP headers via wget command, exploit requires crafted chartURL input.

Severity & Score

Severity: High
CVSS Score: 7.6
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Attackers can inject arbitrary HTTP headers and perform SSRF, potentially leading to unauthorized internal requests or data exposure.

Mitigation

Update to the latest version with proper validation and command sanitization for chartURL.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 30, 2026

🟠 CVE-2026-29954 - High (7.6) In KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF vulnerability when processing the chartURL field of ResourceComposition resources. The field is only URL-encoded without validating the target address. More cr... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-29954/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 30, 2026

🟠 CVE-2026-29954 - High (7.6) In KubePlus 4.1.4, the mutating webhook and kubeconfiggenerator components have an SSRF vulnerability when processing the chartURL field of ResourceComposition resources. The field is only URL-encoded without validating the target address. More cr... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-29954/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-29954
Severity
High
CVSS Score
7.6
Type
server_side_request_forgery
Status
new
EPSS
0.0%
Social Posts
2

CWE

  • CWE-88

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N

EPSS Score

0.0%Probability of exploitation in the next 30 days