Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

kyverno — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in kyverno, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of common weakness types and security vulnerabilities associated with the Kyverno product developed by the Kyverno vendor. It serves as a centralized repository for tracking known security issues within this specific Kubernetes policy engine and admission controller solution. The content on this page collects a wide variety of vulnerability data points, ranging from configuration errors and logic flaws to potential remote code execution risks. The time range covered spans from the initial public releases of Kyverno to the present day, ensuring that both legacy and recently disclosed issues are accounted for. By consolidating these disparate reports, the page offers a historical perspective on the security posture of the software over its development lifecycle. Here, users can discover detailed insights into how the vendor manages security advisories and patches for the Kyverno platform. The aggregation allows security professionals to understand the specific characteristics of weakness classes that frequently affect this type of cloud-native policy management tool. Furthermore, it enables administrators to look up a product's vulnerability history, helping them assess the risk landscape and prioritize remediation efforts based on actual past incidents. This resource is essential for maintaining robust security practices when deploying Kyverno in production environments, providing clarity on past exploits and current mitigation strategies without relying on fragmented third-party sources.

Vendor: kyverno

CVE IDTitleCVSSSeverityPublished
CVE-2026-44245 Kyverno: [policy-reporter-ui] XSS via Stored Property Values in PropertyCard Component CWE-79 6.1 Medium2026-05-12
CVE-2026-41485 Kyverno Controller Denial of Service via forEach Mutation Panic CWE-617 7.7 High2026-04-24
CVE-2026-41323 Kyverno: ServiceAccount token leaked to external servers via apiCall service URL CWE-200 8.1 High2026-04-24
CVE-2026-41068 Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) CWE-863 7.7 High2026-04-24
CVE-2026-40868 kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token CWE-922 8.1 High2026-04-21
CVE-2026-4789 CVE-2026-4789 9.8 -2026-03-30
CVE-2026-23881 Kyverno Denial of Service via Context Variable Amplification in Policy Engine CWE-770 7.7 High2026-01-27
CVE-2026-22039 Kyverno Cross-Namespace Privilege Escalation via Policy apiCall CWE-269 10.0 Critical2026-01-27
CVE-2025-47281 Kyverno's Improper JMESPath Variable Evaluation Leads to Denial of Service CWE-20 7.7 High2025-07-23
CVE-2025-46342 Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements CWE-1287 8.6 High2025-04-30
CVE-2025-29778 Kyverno ignores subjectRegExp and IssuerRegExp CWE-285 5.8 Medium2025-03-24
CVE-2024-48921 Kyverno's PolicyException objects can be created in any namespace by default CWE-285 8.1AIHighAI2024-10-29
CVE-2023-47630 Attacker can cause Kyverno user to unintentionally consume insecure image CWE-345 7.1 High2023-11-14
CVE-2023-42813 Denial of service from malicious manifest in kyverno CWE-400 6.1 Medium2023-11-13
CVE-2023-42814 Denial of service from malicious image manifest in kyverno CWE-835 3.1 Low2023-11-13
CVE-2023-42815 Denial of service from malicious image manifest in kyverno CWE-835 3.1 Low2023-11-13
CVE-2023-42816 Denial of service from malicious signature in kyverno CWE-345 6.1 Medium2023-11-13
CVE-2023-34091 Kyverno resource with a deletionTimestamp may allow policy circumvention CWE-285 6.5 Medium2023-06-01
CVE-2023-33191 kyverno seccomp control can be circumvented CWE-284 4.6 Medium2023-05-30

All 19 known CVE vulnerabilities affecting kyverno with full Chinese analysis, references, and POCs where available.