Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

kyverno — Vulnerabilities & Security Advisories 31

Browse all 31 CVE security advisories affecting kyverno. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Kyverno serves as a policy engine for Kubernetes, enforcing security and compliance through declarative policies. Historically, vulnerabilities have included remote code execution, cross-site scripting, and privilege escalation, often stemming from improper input validation and insecure default configurations. The project maintains active development with regular security updates, though past incidents have exposed flaws in policy enforcement mechanisms and webhook validation. With 18 CVEs recorded, the project demonstrates typical risks associated with complex policy management systems, requiring careful implementation and ongoing monitoring to prevent potential bypasses of security controls in containerized environments.

Top products by kyverno: kyverno
CVE ID Title CVSS Severity Published
CVE-2026-100707 Kyverno before 1.19.1 Namespace Isolation Bypass via Percent-Encoded Path — kyverno CWE-22 7.7 High 2026-09-26
CVE-2026-100706 kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath — kyverno CWE-441 9.9 Critical 2026-09-26
CVE-2026-100705 Kyverno before 1.19.1 SSRF via legacy apiCall service executor — kyverno CWE-918 7.6 High 2026-09-26
CVE-2026-100703 Kyverno before 1.19.1 Cross-Namespace Data Access via globalcontext.Lib — kyverno CWE-200 7.7 High 2026-09-26
CVE-2026-100704 Kyverno before 1.19.1 ImageValidatingPolicy Exception Bypass — kyverno CWE-863 7.7 High 2026-09-26
CVE-2026-84199 Kyverno before 1.16.2 SSRF via APICall Feature — kyverno CWE-918 7.7 High 2026-09-01
CVE-2026-84200 Kyverno before v1.13.0 Policy Bypass via Multiple Exceptions — kyverno CWE-284 9.0 Critical 2026-09-01
CVE-2026-84196 Kyverno before 1.18.0 Server-Side Request Forgery via apiCall — kyverno CWE-918 7.7 High 2026-09-01
CVE-2026-84195 Kyverno before 1.16.4 Credential Leak via apiCall — kyverno CWE-200 7.7 High 2026-09-01
CVE-2025-15613 Kyverno before v1.13.4 SSRF via Service Call — kyverno CWE-918 6.5 Medium 2026-09-01
CVE-2023-54356 Kyverno before 1.9.5 Sweet32 Medium Strength Cipher Suites — kyverno CWE-326 3.7 Low 2026-09-01
CVE-2026-54523 Kyverno: NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system — kyverno CWE-862 9.6 Critical 2026-08-26
CVE-2026-44245 Kyverno: [policy-reporter-ui] XSS via Stored Property Values in PropertyCard Component — kyverno CWE-79 6.1 Medium 2026-05-12
CVE-2026-41485 Kyverno Controller Denial of Service via forEach Mutation Panic — kyverno CWE-617 7.7 High 2026-04-24
CVE-2026-41323 Kyverno: ServiceAccount token leaked to external servers via apiCall service URL — kyverno CWE-200 8.1 High 2026-04-24
CVE-2026-41068 Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) — kyverno CWE-863 7.7 High 2026-04-24
CVE-2026-40868 kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token — kyverno CWE-922 8.1 High 2026-04-21
CVE-2026-4789 CVE-2026-4789 — Kyverno 9.8 - 2026-03-30
CVE-2026-23881 Kyverno Denial of Service via Context Variable Amplification in Policy Engine — kyverno CWE-770 7.7 High 2026-01-27
CVE-2026-22039 Kyverno Cross-Namespace Privilege Escalation via Policy apiCall — kyverno CWE-269 10.0 Critical 2026-01-27
CVE-2025-47281 Kyverno's Improper JMESPath Variable Evaluation Leads to Denial of Service — kyverno CWE-20 7.7 High 2025-07-23
CVE-2025-46342 Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements — kyverno CWE-1287 8.6 High 2025-04-30
CVE-2025-29778 Kyverno ignores subjectRegExp and IssuerRegExp — kyverno CWE-285 5.8 Medium 2025-03-24
CVE-2024-48921 Kyverno's PolicyException objects can be created in any namespace by default — kyverno CWE-285 8.1AI High AI 2024-10-29
CVE-2023-47630 Attacker can cause Kyverno user to unintentionally consume insecure image — kyverno CWE-345 7.1 High 2023-11-14
CVE-2023-42813 Denial of service from malicious manifest in kyverno — kyverno CWE-400 6.1 Medium 2023-11-13
CVE-2023-42814 Denial of service from malicious image manifest in kyverno — kyverno CWE-835 3.1 Low 2023-11-13
CVE-2023-42815 Denial of service from malicious image manifest in kyverno — kyverno CWE-835 3.1 Low 2023-11-13
CVE-2023-42816 Denial of service from malicious signature in kyverno — kyverno CWE-345 6.1 Medium 2023-11-13
CVE-2023-34091 Kyverno resource with a deletionTimestamp may allow policy circumvention — kyverno CWE-285 6.5 Medium 2023-06-01

This page lists every published CVE security advisory associated with kyverno. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.