Github.com/kyverno/kyverno
This hub aggregates every CVE we track for Github.com/kyverno/kyverno, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
10
CVEs tracked
1
Critical
5
High
0
In CISA KEV
Severity distribution
HIGH5MEDIUM3LOW1CRITICAL1
Monthly trend
1
0
0
0
0
1
1
0
0
1
0
0
0
0
0
2
0
0
0
0
0
0
0
0
2024-102026-09
Latest CVEs
The 10 most recently published vulnerabilities affecting Github.com/kyverno/kyverno.
- CVE-2026-23881Kyverno Denial of Service via Context Variable Amplification in Policy Engine7.7
- CVE-2026-22039Kyverno Cross-Namespace Privilege Escalation via Policy apiCall9.9
- CVE-2025-47281Kyverno's Improper JMESPath Variable Evaluation Leads to Denial of Service7.7
- CVE-2025-46342Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements8.5
- CVE-2025-29778Kyverno ignores subjectRegExp and IssuerRegExp5.8
- CVE-2024-48921Kyverno's PolicyException objects can be created in any namespace by default2.7
- CVE-2023-47630Attacker can cause Kyverno user to unintentionally consume insecure image7.1
- CVE-2023-34091Kyverno resource with a deletionTimestamp may allow policy circumvention6.5
- CVE-2023-33191kyverno seccomp control can be circumvented4.6
- CVE-2022-47633An image signature validation bypass vulnerability in Kyverno 1.8.3 and 1.8.4 allows a malicious image registry (or a man-in-the-middle attacker) to inject unsigned arbitrary container images into ...8.1
Product normalization is registry-driven with AI assist and human review. How it works