Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

kyverno — Vulnerabilities & Security Advisories 31

All 31 CVE vulnerabilities found in kyverno, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for Kyverno, an open-source policy management engine for Kubernetes, categorized by specific software defects. The collection comprises security advisories issued by the maintainers over the past three years, covering various weakness types including remote code execution, privilege escalation, and configuration errors. Users can track the vendor’s security posture over time, analyze the prevalence of a particular weakness class, and review the complete vulnerability history for the Kyverno product line.

Vendor: kyverno

CVE ID Title CVSS Severity Published
CVE-2026-100707 Kyverno before 1.19.1 Namespace Isolation Bypass via Percent-Encoded Path CWE-22 7.7 High 2026-09-26
CVE-2026-100706 kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath CWE-441 9.9 Critical 2026-09-26
CVE-2026-100705 Kyverno before 1.19.1 SSRF via legacy apiCall service executor CWE-918 7.6 High 2026-09-26
CVE-2026-100703 Kyverno before 1.19.1 Cross-Namespace Data Access via globalcontext.Lib CWE-200 7.7 High 2026-09-26
CVE-2026-100704 Kyverno before 1.19.1 ImageValidatingPolicy Exception Bypass CWE-863 7.7 High 2026-09-26
CVE-2026-84199 Kyverno before 1.16.2 SSRF via APICall Feature CWE-918 7.7 High 2026-09-01
CVE-2026-84200 Kyverno before v1.13.0 Policy Bypass via Multiple Exceptions CWE-284 9.0 Critical 2026-09-01
CVE-2026-84196 Kyverno before 1.18.0 Server-Side Request Forgery via apiCall CWE-918 7.7 High 2026-09-01
CVE-2026-84195 Kyverno before 1.16.4 Credential Leak via apiCall CWE-200 7.7 High 2026-09-01
CVE-2025-15613 Kyverno before v1.13.4 SSRF via Service Call CWE-918 6.5 Medium 2026-09-01
CVE-2023-54356 Kyverno before 1.9.5 Sweet32 Medium Strength Cipher Suites CWE-326 3.7 Low 2026-09-01
CVE-2026-54523 Kyverno: NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system CWE-862 9.6 Critical 2026-08-26
CVE-2026-44245 Kyverno: [policy-reporter-ui] XSS via Stored Property Values in PropertyCard Component CWE-79 6.1 Medium 2026-05-12
CVE-2026-41485 Kyverno Controller Denial of Service via forEach Mutation Panic CWE-617 7.7 High 2026-04-24
CVE-2026-41323 Kyverno: ServiceAccount token leaked to external servers via apiCall service URL CWE-200 8.1 High 2026-04-24
CVE-2026-41068 Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) CWE-863 7.7 High 2026-04-24
CVE-2026-40868 kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token CWE-922 8.1 High 2026-04-21
CVE-2026-4789 CVE-2026-4789 9.8 - 2026-03-30
CVE-2026-23881 Kyverno Denial of Service via Context Variable Amplification in Policy Engine CWE-770 7.7 High 2026-01-27
CVE-2026-22039 Kyverno Cross-Namespace Privilege Escalation via Policy apiCall CWE-269 10.0 Critical 2026-01-27
CVE-2025-47281 Kyverno's Improper JMESPath Variable Evaluation Leads to Denial of Service CWE-20 7.7 High 2025-07-23
CVE-2025-46342 Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements CWE-1287 8.6 High 2025-04-30
CVE-2025-29778 Kyverno ignores subjectRegExp and IssuerRegExp CWE-285 5.8 Medium 2025-03-24
CVE-2024-48921 Kyverno's PolicyException objects can be created in any namespace by default CWE-285 8.1AI High AI 2024-10-29
CVE-2023-47630 Attacker can cause Kyverno user to unintentionally consume insecure image CWE-345 7.1 High 2023-11-14
CVE-2023-42813 Denial of service from malicious manifest in kyverno CWE-400 6.1 Medium 2023-11-13
CVE-2023-42814 Denial of service from malicious image manifest in kyverno CWE-835 3.1 Low 2023-11-13
CVE-2023-42815 Denial of service from malicious image manifest in kyverno CWE-835 3.1 Low 2023-11-13
CVE-2023-42816 Denial of service from malicious signature in kyverno CWE-345 6.1 Medium 2023-11-13
CVE-2023-34091 Kyverno resource with a deletionTimestamp may allow policy circumvention CWE-285 6.5 Medium 2023-06-01

All 31 known CVE vulnerabilities affecting kyverno with full Chinese analysis, references, and POCs where available.