---
id: GO-2023-1804
aliases:
  - GHSA-hgv6-w7r3-w4qw
title: >-
  Kyverno vulnerable due to usage of insecure cipher in
  github.com/kyverno/kyverno
summary: >-
  Kyverno vulnerable due to usage of insecure cipher in
  github.com/kyverno/kyverno
severity: none
vendor: kyverno
product: github.com/kyverno/kyverno
ecosystem: go
affected:
  - github.com/kyverno/kyverno < 1.9.5
patched:
  - github.com/kyverno/kyverno 1.9.5
published: '2024-08-20'
updated: '2026-08-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GO-2023-1804'
references:
  - url: 'https://github.com/kyverno/kyverno/security/advisories/GHSA-hgv6-w7r3-w4qw'
  - url: 'https://github.com/kyverno/kyverno/pull/7308'
  - url: 'https://github.com/kyverno/kyverno/releases/tag/v1.9.5'
tags:
  - osv
  - go
ingestedAt: '2026-08-07T19:14:18.233Z'
---

## Overview

Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno

## Affected packages

- `github.com/kyverno/kyverno < 1.9.5`

## Remediation

Upgrade to a patched release:

- `github.com/kyverno/kyverno 1.9.5`
