
CVE-2026-54725 vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in pkg/webhook/confi… https://www.cve.org/CVERecord?id=CVE-2026-54725
Post summary
The CVE record highlights a vulnerability in vault‑secrets‑webhook that permits direct secret injection into Pods, but provides no proof of concept, exploit code, active attacks, or patch information.


