Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Kyverno — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in Kyverno, with AI-generated Chinese analysis, references, and POCs.

This page is a vulnerability aggregation resource for Kyverno, covering weakness types and specific tags associated with the vendor’s security posture. It compiles a comprehensive list of security vulnerabilities and weaknesses identified in Kyverno, focusing on data ranging from the earliest recorded incidents up to recent disclosures. The content reflects both known exploited vulnerabilities and broader classifications such as injection flaws, configuration errors, and access control issues relevant to Kubernetes admission controllers. Users can utilize this page to track Kyverno vendor advisories as they are issued by the maintainers and the community. It provides a centralized location to understand the historical context of specific weakness classes within the product ecosystem, allowing security teams to assess risk exposure over time. The collection includes details on patch availability, affected versions, and remediation steps where documented. By reviewing this information, administrators can better understand Kyverno's vulnerability history and prioritize updates or configuration changes to mitigate known risks. The data supports informed decision-making for organizations relying on Kyverno for policy enforcement in their Kubernetes clusters, ensuring that security teams remain aligned with the latest threat intelligence and vendor guidance without relying on fragmented sources.

Vendor: kyverno

CVE IDTitleCVSSSeverityPublished
CVE-2026-44245 Kyverno: [policy-reporter-ui] XSS via Stored Property Values in PropertyCard Component CWE-79 6.1 Medium2026-05-12
CVE-2026-41485 Kyverno Controller Denial of Service via forEach Mutation Panic CWE-617 7.7 High2026-04-24
CVE-2026-41323 Kyverno: ServiceAccount token leaked to external servers via apiCall service URL CWE-200 8.1 High2026-04-24
CVE-2026-41068 Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) CWE-863 7.7 High2026-04-24
CVE-2026-40868 kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token CWE-922 8.1 High2026-04-21
CVE-2026-4789 CVE-2026-4789 9.8 -2026-03-30
CVE-2026-23881 Kyverno Denial of Service via Context Variable Amplification in Policy Engine CWE-770 7.7 High2026-01-27
CVE-2026-22039 Kyverno Cross-Namespace Privilege Escalation via Policy apiCall CWE-269 10.0 Critical2026-01-27
CVE-2025-47281 Kyverno's Improper JMESPath Variable Evaluation Leads to Denial of Service CWE-20 7.7 High2025-07-23
CVE-2025-46342 Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements CWE-1287 8.6 High2025-04-30
CVE-2025-29778 Kyverno ignores subjectRegExp and IssuerRegExp CWE-285 5.8 Medium2025-03-24
CVE-2024-48921 Kyverno's PolicyException objects can be created in any namespace by default CWE-285 8.1AIHighAI2024-10-29
CVE-2023-47630 Attacker can cause Kyverno user to unintentionally consume insecure image CWE-345 7.1 High2023-11-14
CVE-2023-42813 Denial of service from malicious manifest in kyverno CWE-400 6.1 Medium2023-11-13
CVE-2023-42814 Denial of service from malicious image manifest in kyverno CWE-835 3.1 Low2023-11-13
CVE-2023-42815 Denial of service from malicious image manifest in kyverno CWE-835 3.1 Low2023-11-13
CVE-2023-42816 Denial of service from malicious signature in kyverno CWE-345 6.1 Medium2023-11-13
CVE-2023-34091 Kyverno resource with a deletionTimestamp may allow policy circumvention CWE-285 6.5 Medium2023-06-01
CVE-2023-33191 kyverno seccomp control can be circumvented CWE-284 4.6 Medium2023-05-30

All 19 known CVE vulnerabilities affecting Kyverno with full Chinese analysis, references, and POCs where available.