Flyte 2.0.1 through 2.0.51 contains a cleartext secret storage vulnerability that allows users with Pod read access to obtain secrets by reading init container environment variables. The embedded secret manager webhook writes base64-encoded FILE-mounted secret values into the SECRETS environment variable, letting principals without Secret store access decode them from the Pod spec.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 11 Oct 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flyte 2.0.1 through 2.0.51 contains a cleartext secret storage vulnerability that allows users with Pod read access to obtain secrets by reading init container environment variables. The embedded secret manager webhook writes base64-encoded FILE-mounted secret values into the SECRETS environment variable, letting principals without Secret store access decode them from the Pod spec. | |
| Title | Flyte 2.0.1 through 2.0.51 Cleartext Secret Exposure via Admission Webhook | |
| Weaknesses | CWE-312 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-11T12:19:36.569Z
Reserved: 2026-10-11T01:52:34.655Z
Link: CVE-2026-108728
No data.
Status : Received
Published: 2026-10-11T13:17:16.590
Modified: 2026-10-11T13:17:16.590
Link: CVE-2026-108728
No data.
OpenCVE Enrichment
Updated: 2026-10-11T13:45:03Z
Weaknesses