CVE-2026-54725 | bank-vaults vault-secrets-webhook up to 1.23.0 Config Parser pkg/webhook/config.go parseVaultConfig vault.security.banzaicloud.io/vault-addr injection

SecurityVulns

A vulnerability, which was classified as problematic, has been found in bank-vaults vault-secrets-webhook up to 1.23.0. This vulnerability affects the function parseVaultConfig of the file pkg/webhook/config.go of the component Config Parser. Performing a manipulation of the argument vault.security.banzaicloud.io/vault-addr results in injection.

This vulnerability was named CVE-2026-54725. The attack may be initiated remotely. There is no available exploit.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More