WhisperX tag archive

#serviceaccount-token

This page collects WhisperX intelligence signals tagged #serviceaccount-token. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-04-24 03:54:06 · GitHub Issues

1. Kyverno apiCall Service Mode Exposes Kubernetes ServiceAccount Tokens by Default in High-Severity Vulnerability

A high-severity vulnerability in Kyverno's policy engine allows ServiceAccount tokens to be automatically forwarded to external endpoints without policy authors' knowledge or consent. The flaw, tracked as GHSA-8wfp-579w-6r25, stems from an insecure-by-default behavior in Kyverno's apiCall service mode, where the admiss...