← العودة للجدول
CVE-2026-44182
CVE-2026-44182 — GHSA: Jupyter Enterprise Gateway: Kubernetes Manifest Injection in Jinja2 Template Rendering
📅 2026-06-03
🔴 Critical 🔥 No GHSA PoC Research Linux

📋 الوصف الكامل

### Summary The environment variables used during the rendering of the Kubernetes manifest allow YAML injection, enabling attackers to overwrite existing keys like `securityContext` and inject multi-document YAML to create additional unintended Kubernetes resources. ### Details The server interpolates untrusted environment variables (e.g., `KERNEL_XXX`) into Kubernetes manifests without YAML-aw

💻 الأنظمة المتأثرة

Kubernetes

⚠️ نوع التهديد

PoC Research

🔗 CVE ID

CVE-2026-44182

📡 المصدر

GHSA

✅ الحلول والتخفيف

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←