CVEs we hold for Kyverno
Records whose assigning authority named Kyverno as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-84200Kyverno before v1.13.0 Policy Bypass via Multiple Exceptionskyverno CVE-2026-84196Kyverno before 1.18.0 Server-Side Request Forgery via apiCallkyverno CVE-2026-84195Kyverno before 1.16.4 Credential Leak via apiCallkyverno CVE-2026-54523Kyverno: NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates…kyverno CVE-2026-44245Kyverno: [policy-reporter-ui] XSS via Stored Property Values in PropertyCard Componentkyverno CVE-2026-41485Kyverno Controller Denial of Service via forEach Mutation Panickyverno CVE-2026-41323Kyverno: ServiceAccount token leaked to external servers via apiCall service URLkyverno CVE-2026-41068Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix)kyverno CVE-2026-40868kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount tokenkyverno CVE-2026-23881Kyverno Denial of Service via Context Variable Amplification in Policy Enginekyverno CVE-2026-22039Kyverno Cross-Namespace Privilege Escalation via Policy apiCallkyverno CVE-2025-47281Kyverno's Improper JMESPath Variable Evaluation Leads to Denial of Servicekyverno CVE-2025-46342Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statementskyverno CVE-2024-48921Kyverno's PolicyException objects can be created in any namespace by defaultkyverno CVE-2023-54356Kyverno before 1.9.5 Sweet32 Medium Strength Cipher Suiteskyverno CVE-2023-47630Attacker can cause Kyverno user to unintentionally consume insecure imagekyverno CVE-2023-42816Denial of service from malicious signature in kyvernokyverno CVE-2023-42815Denial of service from malicious image manifest in kyvernokyverno CVE-2023-42814Denial of service from malicious image manifest in kyvernokyverno CVE-2023-42813Denial of service from malicious manifest in kyvernokyverno CVE-2023-34091Kyverno resource with a deletionTimestamp may allow policy circumventionkyverno 26 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.