Disclosure summary
## Summary A bug in the `webhook` generator initialization order incorrectly cleared the label-enforcement flag (`EnforceLabels`) after it was set, resulting in the provider-side check for `external-secrets.io/type=webhook` being skipped (and the operation to succeed while it should have failed with `secret does not contain needed label 'external-secrets.io/type: webhook'. Update secret label to use it with webhook`. ## Impact A user with the permission to create webhook generator can set the webhook generator to a victim' secret (which was not previously labelled for webhook's use), and exfiltrate it to a malicious URL. ## Mitigations Until you upgrade, you can reduce risk by: - disabling webhook generators if not needed (or denying `generators.external-secrets.io/v1alpha1` `Webhook` via an admission policy); - restricting RBAC: limit who can create generators of kind `Webhook`; - enforcing an admission policy (OPA Gatekeeper / Kyverno) requiring referenced secrets to be labeled `external-secrets.io/type=webhook`; - restricting egress from external-secrets controller pods to an allowlist (kubernetes `NetworkPolicy` / service mesh egress policy). ## References - PR #5901 (fix: webh
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-q7hv-xx6h-q2x8
Open original source · Updated Oct 06, 2026
External Secrets Operator: label enforcement bypass in webhook generator enables secret exfiltration
Source severity: HIGH / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| go | github.com/external-secrets/external-secrets | >= 0.10.0, < 1.3.2 | 1.3.2 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-06T11:29:25-04:00
MODIFIED 2026-10-06T11:29:26-04:00
INGESTED 2026-10-06T11:45:43-04:00