github.com/kyverno/kyverno vulnerabilities
CVEs whose affected-version data names the github.com/kyverno/kyverno package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
15 CVEsRSS
CVE-2026-84196High· 7.7Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url that allows authenticated users to send arbitrary HTTP requests by injecting user-controlled input through variable substitution
Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url that allows authenticated users to send arbitrary HTTP requests by injecting user-controlled input through variable substitution. Attackers…
CVE-2023-54356Low· 3.7Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints
Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints. These 64-bit block ciphers are vulnerable to the Sweet32 attack (CVE-2…
CVE-2026-84200Critical· 9.0Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw
Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive exception takes precedence, allowing an attacker to bypass the po…
CVE-2026-84199High· 7.7Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature
Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The URL field in a Policy's ServiceCall configuration is not validated, so a user with namespace-level Policy creation permissions …
CVE-2026-84195High· 7.7Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorization headers
Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorization headers. Attackers can exfiltrate the token by directing apiCal…
CVE-2025-15613Medium· 6.5Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality
Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality. An attacker with permission to create Kyverno (Cluster)Policies can specify an external URL in a policy's apiCall/service conf…
CVE-2026-54523Critical· 9.6Kyverno is a policy engine designed for cloud native platform engineering teams
Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy CEL compiler exposes the generator library to matchConditions, allowing a namespace-scoped policy to …
CVE-2026-41068High· 7.7Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix)
Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix)
CVE-2025-29778Medium· 5.8Kyverno ignores subjectRegExp and IssuerRegExp
Kyverno ignores subjectRegExp and IssuerRegExp
GO-2023-1804NoneKyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
CVE-2023-47630High· 7.1⚠ Exploited0dayAttacker can cause Kyverno user to unintentionally consume insecure image
Attacker can cause Kyverno user to unintentionally consume insecure image
CVE-2023-34091Medium· 6.5Kyverno resource with a deletionTimestamp may allow policy circumvention
Kyverno resource with a deletionTimestamp may allow policy circumvention
GHSA-hgv6-w7r3-w4qwMediumKyverno vulnerable due to usage of insecure cipher
Kyverno vulnerable due to usage of insecure cipher
CVE-2023-33191Medium· 4.6kyverno seccomp control can be circumvented
kyverno seccomp control can be circumvented
CVE-2022-47633High· 8.1kyverno verifyImages rule bypass possible with malicious proxy/registry
kyverno verifyImages rule bypass possible with malicious proxy/registry