kyverno

12 known vulnerabilities in kyverno, 4 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-100707 CVSS 8.3 high Kyverno before 1.19.1 contains a namespace isolation bypass in the apiCall context entry of namespaced Policy resources due to…
  • CVE-2026-100706 CVSS 9.4 critical kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace tenants to bypass…
  • CVE-2026-100705 CVSS 8.3 high Kyverno before 1.19.1 is vulnerable to server-side request forgery. The default egress blocklist (169.254.169.254, 169.254.169.253…
  • CVE-2026-100704 CVSS 8.3 high Kyverno is a policy engine for Kubernetes. In versions 1.14.0 through 1.19.0, the ImageValidatingPolicy (policies.kyverno.io/v1beta1)…
  • CVE-2026-100703 CVSS 8.3 high Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL library in its policy environment without confining it to the policy's…
  • CVE-2026-84200 CVSS 9.4 critical Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two…
  • CVE-2026-84199 CVSS 6.9 medium Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The URL field in a Policy's…
  • CVE-2026-84196 CVSS 8.3 high Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url that allows authenticated users to send…
  • CVE-2026-84195 CVSS 8.3 high Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service…
  • CVE-2025-15613 CVSS 6.9 medium Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality. An attacker with permission…
  • CVE-2023-54356 CVSS 9.3 critical Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and…
  • CVE-2026-54523 CVSS 9.6 critical Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy…