e
external-secrets
Security Risk Profile
46
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 4 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from July 24, 2024 to present
4
Total CVEs
4
Critical+High
0
Exploited
1
Unpatched
Threat Assessment
Avg CVSS
8.8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
1
Critical/High
Risk Level
46/100
medium
Severity Distribution
Critical
2High
2Medium
0Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
1Age Distribution
Common Weaknesses (CWE)
1
Infoleak
1
Most Affected Products
1. go/github.com/external-secrets/external-secrets4
2. external-secrets External Secrets Operator4
3. External Secrets external-secrets1
Recent Vulnerabilities
See more →CVE-2026-34984
CVSS 7.1high
External Secrets Operator has DNS exfiltration via getHostByName in its v2 template engine
Apr 13, 2026
CVE-2026-22822
CVSS 9.3EPSS 0%critical
External Secrets Operator insecurely retrieves secrets through the getSecretKey templating function
Jan 20, 2026
CVE-2024-45041
CVSS 8.8high
External Secrets Operator vulnerable to privilege escalation
Sep 9, 2024
CVE-2024-36540
CVSS 9.8critical
Jul 24, 2024🔧 No Patch
Monitor external-secrets in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.