VulnSea

kyverno has 15 CVEs on record between 2022 and 2026. Disclosure cadence is accelerating: 7 in the last 90 days against 1 in the 90 before. The busiest recent month was September 2026 with 6. The median CVSS is 7.7 (high), with 2 rated critical. 7% have been exploited in the wild, in line with the corpus average. The most common weakness class is CWE-918 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
7% vs 1% corpus
Median CVSS
7.7
Publish → KEV
Last 90 days
7 prev 1

Products

  • github.com/kyverno/kyverno 15
15
Total CVEs
2
Critical
0
CISA KEV
1
Exploited

kyverno vulnerabilities

CVEs affecting kyverno, newest first. Open any entry for full detail, references, and exploit status.

15 CVEsRSS

CVE-2026-84196High· 7.7
3w ago

Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url that allows authenticated users to send arbitrary HTTP requests by injecting user-controlled input through variable substitution

Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url that allows authenticated users to send arbitrary HTTP requests by injecting user-controlled input through variable substitution. Attackers…

Twilightkyverno · github.com/kyverno/kyvernoEPSS 0.26%via NVD
CVE-2023-54356Low· 3.7
3w ago

Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints

Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints. These 64-bit block ciphers are vulnerable to the Sweet32 attack (CVE-2…

Sunlitkyverno · github.com/kyverno/kyvernoEPSS 0.15%via NVD
CVE-2026-84200Critical· 9.0
3w ago

Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw

Kyverno versions v1.9.0 through v1.12.7 contain a policy exception handling flaw. When a policy in enforce mode is combined with two PolicyExceptions, the less restrictive exception takes precedence, allowing an attacker to bypass the po…

Midnightkyverno · github.com/kyverno/kyvernoEPSS 0.18%via NVD
CVE-2026-84199High· 7.7
3w ago

Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature

Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The URL field in a Policy's ServiceCall configuration is not validated, so a user with namespace-level Policy creation permissions …

Twilightkyverno · github.com/kyverno/kyvernoEPSS 0.26%via NVD
CVE-2026-84195High· 7.7
3w ago

Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorization headers

Kyverno before 1.16.4 automatically attaches the admission controller's ServiceAccount token to outbound HTTP requests in apiCall service mode without explicit authorization headers. Attackers can exfiltrate the token by directing apiCal…

Twilightkyverno · github.com/kyverno/kyvernoEPSS 0.29%via NVD
CVE-2025-15613Medium· 6.5
3w ago

Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality

Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality. An attacker with permission to create Kyverno (Cluster)Policies can specify an external URL in a policy's apiCall/service conf…

Sunlitkyverno · github.com/kyverno/kyvernoEPSS 0.27%via NVD
CVE-2026-54523Critical· 9.6
3w ago

Kyverno is a policy engine designed for cloud native platform engineering teams

Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy CEL compiler exposes the generator library to matchConditions, allowing a namespace-scoped policy to …

Midnightkyverno · github.com/kyverno/kyvernoEPSS 0.40%via NVD
CVE-2026-41068High· 7.7
5mo ago

Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix)

Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix)

Twilightkyverno · github.com/kyverno/kyvernoEPSS 0.27%via OSV
CVE-2025-29778Medium· 5.8
1y ago

Kyverno ignores subjectRegExp and IssuerRegExp

Kyverno ignores subjectRegExp and IssuerRegExp

Sunlitkyverno · github.com/kyverno/kyvernoEPSS 0.33%via OSV
GO-2023-1804None
2y ago

Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno

Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno

Sunlitkyverno · github.com/kyverno/kyvernovia OSV
CVE-2023-47630High· 7.1⚠ Exploited0day
2y ago

Attacker can cause Kyverno user to unintentionally consume insecure image

Attacker can cause Kyverno user to unintentionally consume insecure image

Abyssalkyverno · github.com/kyverno/kyvernoEPSS 0.26%via OSV
CVE-2023-34091Medium· 6.5
3y ago

Kyverno resource with a deletionTimestamp may allow policy circumvention

Kyverno resource with a deletionTimestamp may allow policy circumvention

Sunlitkyverno · github.com/kyverno/kyvernoEPSS 0.50%via OSV
GHSA-hgv6-w7r3-w4qwMedium
3y ago

Kyverno vulnerable due to usage of insecure cipher

Kyverno vulnerable due to usage of insecure cipher

Sunlitkyverno · github.com/kyverno/kyvernovia OSV
CVE-2023-33191Medium· 4.6
3y ago

kyverno seccomp control can be circumvented

kyverno seccomp control can be circumvented

Sunlitkyverno · github.com/kyverno/kyvernoEPSS 0.48%via OSV
CVE-2022-47633High· 8.1
3y ago

kyverno verifyImages rule bypass possible with malicious proxy/registry

kyverno verifyImages rule bypass possible with malicious proxy/registry

Twilightkyverno · github.com/kyverno/kyvernoEPSS 0.96%via OSV
kyverno vulnerabilities (CVEs) · VulnSea