FlareStart
HomeNewsHow ToSources
FlareStart

Where developers start their day. All the tech news & tutorials that matter, in one place.

Quick Links

  • Home
  • News
  • Tutorials
  • Sources
  • Privacy Policy

Connect

© 2026 FlareStart. All rights reserved.

Back to articles
CVE-2026-22728: The Old Switcheroo: Unsealing Secrets via Metadata Manipulation in Bitnami Sealed Secrets
NewsSecurity

CVE-2026-22728: The Old Switcheroo: Unsealing Secrets via Metadata Manipulation in Bitnami Sealed Secrets

via Dev.toCVE Reports1mo ago

The Old Switcheroo: Unsealing Secrets via Metadata Manipulation in Bitnami Sealed Secrets Vulnerability ID: CVE-2026-22728 CVSS Score: 4.9 Published: 2026-02-26 Bitnami Sealed Secrets, the standard-bearer for GitOps secret management, contains a logic flaw in its key rotation mechanism that allows attackers to widen the scope of encrypted secrets. By injecting malicious metadata during the rotation process, an attacker can transform a strictly scoped secret (bound to a specific namespace) into a cluster-wide secret, subsequently recovering the plaintext credentials. This vulnerability highlights a classic 'Time-of-Check to Time-of-Use' (TOCTOU) style disconnect between the decryption and re-encryption phases. TL;DR A logic flaw in the /v1/rotate endpoint allows attackers to bypass scope restrictions. By modifying the metadata of a SealedSecret during rotation, an attacker can force the controller to re-encrypt a restricted secret as 'cluster-wide,' enabling them to decrypt it in any na

Continue reading on Dev.to

Opens in a new tab

Read Full Article
37 views

Related Articles

These XR glasses effectively replaced my dual monitors for work - and they're $170 off
News

These XR glasses effectively replaced my dual monitors for work - and they're $170 off

ZDNet • 4d ago

Computer Science Is Controlling Your Life (And You Don’t Even Know)
News

Computer Science Is Controlling Your Life (And You Don’t Even Know)

Medium Programming • 4d ago

Judge irate as defendant joins by Zoom while driving—then lies about it
News

Judge irate as defendant joins by Zoom while driving—then lies about it

Ars Technica • 4d ago

These 20 award-winning tech products are on sale (but we'd pay full price)
News

These 20 award-winning tech products are on sale (but we'd pay full price)

ZDNet • 4d ago

AV1’s open, royalty-free promise in question as Dolby sues Snapchat over codec
News

AV1’s open, royalty-free promise in question as Dolby sues Snapchat over codec

Ars Technica • 4d ago

Discover More Articles