GHSA-j94x-8wcp-x7hm · Severity: medium · Ecosystem: go — Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration
Kargo manages and automates the promotion of software artifacts. In versions 1.4.0 through 1.6.3, 1.7.0-rc.1 through 1.7.8, 1.8.0-rc.1 through 1.8.11, and 1.9.0-rc.1 through 1.9.4, the http and http-download promotion steps allow Server-Side Request Forgery (SSRF) against link-local addresses, most critically the cloud instance metadata endpoint (169.254.169.254), enabling exfiltration of sensitive data such as IAM credentials. These steps provide full control over request headers and methods, rendering cloud provider header-based SSRF mitigations ineffective. An authenticated attacker with permissions to create/update Stages or craft Promotion resources can exploit this by submitting a malicious Promotion manifest, with response data retrievable via Promotion status fields, Git repositories, or a second http step. This issue has been fixed in versions 1.6.4, 1.7.9, 1.8.12 and 1.9.5.
Conclusion & alert: CVE-2026-32828 is rated Low Risk (23.2/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.03%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-03-20 | — | 0.03% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.1 | 4.0 | MEDIUM |
|
— | — | [email protected] |
| 4.9 | 3.1 | MEDIUM |
|
1.2 | 3.6 | [email protected] |
GHSA-j94x-8wcp-x7hm · Severity: medium · Ecosystem: go — Kargo Vulnerable to SSRF in Promotion http/http-download Steps Enables Internal Network Access and Data Exfiltration
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| akuity | kargo | >= 1.4.0, < 1.6.4 | cpe:2.3:a:akuity:kargo:*:*:*:*:*:kubernetes:*:* |
| akuity | kargo | >= 1.7.0, < 1.7.9 | cpe:2.3:a:akuity:kargo:*:*:*:*:*:kubernetes:*:* |
| akuity | kargo | >= 1.8.0, < 1.8.12 | cpe:2.3:a:akuity:kargo:*:*:*:*:*:kubernetes:*:* |
| akuity | kargo | >= 1.9.0, < 1.9.5 | cpe:2.3:a:akuity:kargo:*:*:*:*:*:kubernetes:*:* |
| URL | Tags |
|---|---|
| https://github.com/akuity/kargo/commit/fd25620c2473ed19bec4be4d0f181287ef0f0391 | Patch |
| https://github.com/akuity/kargo/security/advisories/GHSA-j94x-8wcp-x7hm | Mitigation Vendor Advisory |