{"schema_version":1,"title":"github.com/kyverno/kyverno (Go) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 28 vulnerabilities in github.com/kyverno/kyverno (Go): 0 in the last 7 days and 4 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-84199, was published on 1 September 2026.","url":"https://junglewise.ai/threats/technologies/github-com-kyverno-kyverno","json_url":"https://junglewise.ai/threats/technologies/github-com-kyverno-kyverno.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/github-com-kyverno-kyverno","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":9,"all_time":28,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":3,"last_90_days":4,"last_365_days":16},"latest":[{"cve":"CVE-2026-84199","cvss":7.7,"epss":0.0036,"slug":"cve-2026-84199-kyverno-apicall-server-side-request-forgery-ssrf-via-unvalidated","title":"Kyverno APICall server-side request forgery (SSRF) via unvalidated URL","severity":"high","exploited":false,"published_at":"2026-09-01T12:17:49.407+00:00","url":"https://junglewise.ai/threats/cve-2026-84199-kyverno-apicall-server-side-request-forgery-ssrf-via-unvalidated"},{"cve":"CVE-2025-15613","cvss":6.5,"epss":0.0027,"slug":"cve-2025-15613-kyverno-server-side-request-forgery-via-service-calls","title":"Kyverno server-side request forgery via Service Calls","severity":"medium","exploited":false,"published_at":"2026-09-01T12:17:18.183+00:00","url":"https://junglewise.ai/threats/cve-2025-15613-kyverno-server-side-request-forgery-via-service-calls"},{"cve":"CVE-2023-54356","cvss":3.7,"epss":0.0015,"slug":"cve-2023-54356-kyverno-weak-cipher-suite-support-in-tls","title":"Kyverno weak cipher suite support in TLS","severity":"low","exploited":false,"published_at":"2026-09-01T12:17:11.22+00:00","url":"https://junglewise.ai/threats/cve-2023-54356-kyverno-weak-cipher-suite-support-in-tls"},{"cve":"CVE-2026-54523","cvss":9.6,"epss":0.0047,"slug":"cve-2026-54523-kyverno-namespacedmutatingpolicy-generator-apply-namespace","title":"Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy CEL","severity":"critical","exploited":false,"published_at":"2026-08-26T15:16:48.91+00:00","url":"https://junglewise.ai/threats/cve-2026-54523-kyverno-namespacedmutatingpolicy-generator-apply-namespace"},{"cve":"CVE-2026-41485","cvss":7.7,"epss":0.0057,"slug":"cve-2026-41485-kyverno-controller-denial-of-service-via-foreach-mutation-panic","title":"Kyverno Controller Denial of Service via forEach Mutation Panic","severity":"high","exploited":false,"published_at":"2026-04-24T20:40:39+00:00","url":"https://junglewise.ai/threats/cve-2026-41485-kyverno-controller-denial-of-service-via-foreach-mutation-panic"},{"cvss":7.7,"slug":"kyverno-apicall-credential-leak-via-serviceaccount-token-forwarding-c14bd03f","title":"Kyverno apiCall credential leak via ServiceAccount token forwarding","severity":"high","exploited":false,"published_at":"2026-04-16T21:37:29+00:00","url":"https://junglewise.ai/threats/kyverno-apicall-credential-leak-via-serviceaccount-token-forwarding-c14bd03f"},{"cve":"CVE-2026-41323","cvss":8.1,"epss":0.0057,"slug":"cve-2026-41323-kyverno-serviceaccount-token-leaked-to-external-servers-via","title":"Kyverno: ServiceAccount token leaked to external servers via apiCall service URL","severity":"high","exploited":false,"published_at":"2026-04-16T21:36:20+00:00","url":"https://junglewise.ai/threats/cve-2026-41323-kyverno-serviceaccount-token-leaked-to-external-servers-via"},{"cve":"CVE-2026-41068","cvss":7.7,"epss":0.0037,"slug":"cve-2026-41068-kyverno-cross-namespace-read-bypasses-rbac-isolation-incomplete","title":"Kyverno: Cross-Namespace Read Bypasses RBAC Isolation ( Incomplete Fix)","severity":"high","exploited":false,"published_at":"2026-04-16T21:35:04+00:00","url":"https://junglewise.ai/threats/cve-2026-41068-kyverno-cross-namespace-read-bypasses-rbac-isolation-incomplete"},{"cve":"CVE-2026-4789","cvss":8.5,"epss":0.0065,"slug":"cve-2026-4789-kyverno-ssrf-in-cel-http-library-functions","title":"Kyverno SSRF in CEL HTTP library functions","severity":"high","exploited":false,"published_at":"2026-04-14T22:37:20+00:00","url":"https://junglewise.ai/threats/cve-2026-4789-kyverno-ssrf-in-cel-http-library-functions"},{"cve":"CVE-2026-40868","cvss":8.1,"epss":0.0041,"slug":"cve-2026-40868-kyverno-apicall-servicecall-implicit-bearer-token-injection-leaks","title":"kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token","severity":"high","exploited":false,"published_at":"2026-04-14T20:09:00+00:00","url":"https://junglewise.ai/threats/cve-2026-40868-kyverno-apicall-servicecall-implicit-bearer-token-injection-leaks"},{"cvss":7.7,"slug":"kyverno-ssrf-in-apicall-feature-leading-to-multi-tenant-breach-0b4e8088","title":"Kyverno SSRF in APICall feature leading to multi-tenant breach","severity":"high","exploited":false,"published_at":"2026-04-14T20:06:09+00:00","url":"https://junglewise.ai/threats/kyverno-ssrf-in-apicall-feature-leading-to-multi-tenant-breach-0b4e8088"},{"cvss":7.7,"slug":"kyverno-ssrf-in-apicall-via-variable-substitution-6ae5ddc6","title":"Kyverno SSRF in apiCall via variable substitution","severity":"high","exploited":false,"published_at":"2026-04-14T20:05:52+00:00","url":"https://junglewise.ai/threats/kyverno-ssrf-in-apicall-via-variable-substitution-6ae5ddc6"},{"cvss":4,"slug":"duplicate-advisory-kyverno-is-vulnerable-to-server-side-request-forgery-3b736f27","title":"Duplicate Advisory: Kyverno is vulnerable to server-side request forgery (SSRF)","severity":"medium","exploited":false,"published_at":"2026-03-30T21:31:05+00:00","url":"https://junglewise.ai/threats/duplicate-advisory-kyverno-is-vulnerable-to-server-side-request-forgery-3b736f27"},{"cvss":9.8,"slug":"kyverno-ssrf-via-unrestricted-cel-http-functions-d54eaa1c","title":"Kyverno SSRF via unrestricted CEL HTTP functions","severity":"medium","exploited":false,"published_at":"2026-03-30T21:31:05+00:00","url":"https://junglewise.ai/threats/kyverno-ssrf-via-unrestricted-cel-http-functions-d54eaa1c"},{"cve":"CVE-2026-23881","cvss":3.1,"epss":0.006,"slug":"cve-2026-23881-kyverno-denial-of-service-via-context-variable-amplification-in","title":"GO-2026-4382 - Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno","severity":"low","exploited":false,"published_at":"2026-02-02T21:05:59+00:00","url":"https://junglewise.ai/threats/cve-2026-23881-kyverno-denial-of-service-via-context-variable-amplification-in"},{"cve":"CVE-2026-22039","cvss":3.1,"epss":0.0058,"slug":"cve-2026-22039-kyverno-cross-namespace-privilege-escalation-via-policy-apicall","title":"GO-2026-4381 - Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno","severity":"low","exploited":false,"published_at":"2026-02-02T21:05:59+00:00","url":"https://junglewise.ai/threats/cve-2026-22039-kyverno-cross-namespace-privilege-escalation-via-policy-apicall"},{"cve":"CVE-2025-47281","cvss":3.1,"epss":0.0049,"slug":"cve-2025-47281-kyverno-s-improper-jmespath-variable-evaluation-lead-to-denial-of","title":"GO-2025-3823 - Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno","severity":"low","exploited":false,"published_at":"2025-07-29T18:49:33+00:00","url":"https://junglewise.ai/threats/cve-2025-47281-kyverno-s-improper-jmespath-variable-evaluation-lead-to-denial-of"},{"cve":"CVE-2025-46342","cvss":3.1,"epss":0.0075,"slug":"cve-2025-46342-kyverno-vulnerable-to-bypass-of-policy-rules-that-use-namespace","title":"GO-2025-3652 - Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno","severity":"low","exploited":false,"published_at":"2025-05-05T16:14:30+00:00","url":"https://junglewise.ai/threats/cve-2025-46342-kyverno-vulnerable-to-bypass-of-policy-rules-that-use-namespace"},{"cve":"CVE-2025-29778","cvss":3.1,"epss":0.0034,"slug":"cve-2025-29778-kyverno-ignores-subjectregexp-and-issuerregexp","title":"GO-2025-3562 - Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno","severity":"low","exploited":false,"published_at":"2025-03-25T19:38:11+00:00","url":"https://junglewise.ai/threats/cve-2025-29778-kyverno-ignores-subjectregexp-and-issuerregexp"},{"cve":"CVE-2024-48921","cvss":3.1,"epss":0.0057,"slug":"cve-2024-48921-kyverno-s-policyexception-objects-can-be-created-in-any-namespace","title":"GO-2024-3230 - Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno","severity":"low","exploited":false,"published_at":"2024-10-30T21:22:08+00:00","url":"https://junglewise.ai/threats/cve-2024-48921-kyverno-s-policyexception-objects-can-be-created-in-any-namespace"},{"cve":"CVE-2023-47630","cvss":3.1,"epss":0.0026,"slug":"cve-2023-47630-attacker-can-cause-kyverno-user-to-unintentionally-consume","title":"GO-2023-2340 - Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno","severity":"low","exploited":false,"published_at":"2024-08-21T14:30:24+00:00","url":"https://junglewise.ai/threats/cve-2023-47630-attacker-can-cause-kyverno-user-to-unintentionally-consume"},{"cve":"CVE-2023-42814","epss":0.0067,"slug":"cve-2023-42814-go-2023-2336-denial-of-service-from-malicious-image-manifest-in","title":"GO-2023-2336 - Denial of service from malicious image manifest in kyverno in github.com/kyverno/kyverno","severity":"info","exploited":false,"published_at":"2024-08-21T14:30:22+00:00","url":"https://junglewise.ai/threats/cve-2023-42814-go-2023-2336-denial-of-service-from-malicious-image-manifest-in"},{"cve":"CVE-2023-42816","epss":0.0046,"slug":"cve-2023-42816-go-2023-2338-denial-of-service-from-malicious-signature-in","title":"GO-2023-2338 - Denial of service from malicious signature in kyverno in github.com/kyverno/kyverno","severity":"info","exploited":false,"published_at":"2024-08-21T14:30:22+00:00","url":"https://junglewise.ai/threats/cve-2023-42816-go-2023-2338-denial-of-service-from-malicious-signature-in"},{"cve":"CVE-2023-42815","epss":0.0067,"slug":"cve-2023-42815-go-2023-2337-denial-of-service-from-malicious-image-manifest-in","title":"GO-2023-2337 - Denial of service from malicious image manifest in kyverno in github.com/kyverno/kyverno","severity":"info","exploited":false,"published_at":"2024-08-21T14:30:22+00:00","url":"https://junglewise.ai/threats/cve-2023-42815-go-2023-2337-denial-of-service-from-malicious-image-manifest-in"},{"cve":"CVE-2023-42813","epss":0.0066,"slug":"cve-2023-42813-go-2023-2335-denial-of-service-from-malicious-manifest-in-kyverno","title":"GO-2023-2335 - Denial of service from malicious manifest in kyverno in github.com/kyverno/kyverno","severity":"info","exploited":false,"published_at":"2024-08-21T14:30:22+00:00","url":"https://junglewise.ai/threats/cve-2023-42813-go-2023-2335-denial-of-service-from-malicious-manifest-in-kyverno"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":1,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"github.com/siyuan-note/siyuan/kernel (Go)","slug":"github-com-siyuan-note-siyuan-kernel","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/github-com-siyuan-note-siyuan-kernel"},{"name":"code.gitea.io/gitea (Go)","slug":"code-gitea-io-gitea","vulnerabilities":76,"url":"https://junglewise.ai/threats/technologies/code-gitea-io-gitea"},{"name":"github.com/rclone/rclone (Go)","slug":"github-com-rclone-rclone","vulnerabilities":26,"url":"https://junglewise.ai/threats/technologies/github-com-rclone-rclone"},{"name":"gogs.io/gogs (Go)","slug":"gogs-io-gogs","vulnerabilities":25,"url":"https://junglewise.ai/threats/technologies/gogs-io-gogs"},{"name":"github.com/filebrowser/filebrowser/v2 (Go)","slug":"github-com-filebrowser-filebrowser-v2","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-filebrowser-filebrowser-v2"},{"name":"github.com/fission/fission (Go)","slug":"github-com-fission-fission","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-fission-fission"},{"name":"github.com/klever-io/klever-go (Go)","slug":"github-com-klever-io-klever-go","vulnerabilities":18,"url":"https://junglewise.ai/threats/technologies/github-com-klever-io-klever-go"},{"name":"code.vikunja.io/api (Go)","slug":"code-vikunja-io-api","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/code-vikunja-io-api"},{"name":"github.com/cloudreve/Cloudreve/v4 (Go)","slug":"github-com-cloudreve-cloudreve-v4","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/github-com-cloudreve-cloudreve-v4"},{"name":"github.com/gotenberg/gotenberg/v8 (Go)","slug":"github-com-gotenberg-gotenberg-v8","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-gotenberg-gotenberg-v8"},{"name":"github.com/nezhahq/nezha (Go)","slug":"github-com-nezhahq-nezha","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/github-com-nezhahq-nezha"},{"name":"github.com/fleetdm/fleet/v4 (Go)","slug":"github-com-fleetdm-fleet-v4","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/github-com-fleetdm-fleet-v4"}],"technology":{"hub":true,"name":"github.com/kyverno/kyverno (Go)","slug":"github-com-kyverno-kyverno","vendor":{"name":"Go","slug":"go","url":"https://junglewise.ai/threats/vendors/go"},"aliases":[],"homepage":"https://kyverno.io/","repo_url":"https://github.com/kyverno/kyverno","description":"A policy engine designed for Kubernetes to manage configurations through admission controls and background scans.","url":"https://junglewise.ai/threats/technologies/github-com-kyverno-kyverno"},"most_severe":[{"cve":"CVE-2026-54523","cvss":9.6,"epss":0.0047,"slug":"cve-2026-54523-kyverno-namespacedmutatingpolicy-generator-apply-namespace","title":"Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy CEL","severity":"critical","exploited":false,"published_at":"2026-08-26T15:16:48.91+00:00","url":"https://junglewise.ai/threats/cve-2026-54523-kyverno-namespacedmutatingpolicy-generator-apply-namespace"},{"cve":"CVE-2026-4789","cvss":8.5,"epss":0.0065,"slug":"cve-2026-4789-kyverno-ssrf-in-cel-http-library-functions","title":"Kyverno SSRF in CEL HTTP library functions","severity":"high","exploited":false,"published_at":"2026-04-14T22:37:20+00:00","url":"https://junglewise.ai/threats/cve-2026-4789-kyverno-ssrf-in-cel-http-library-functions"},{"cve":"CVE-2026-41323","cvss":8.1,"epss":0.0057,"slug":"cve-2026-41323-kyverno-serviceaccount-token-leaked-to-external-servers-via","title":"Kyverno: ServiceAccount token leaked to external servers via apiCall service URL","severity":"high","exploited":false,"published_at":"2026-04-16T21:36:20+00:00","url":"https://junglewise.ai/threats/cve-2026-41323-kyverno-serviceaccount-token-leaked-to-external-servers-via"},{"cve":"CVE-2026-40868","cvss":8.1,"epss":0.0041,"slug":"cve-2026-40868-kyverno-apicall-servicecall-implicit-bearer-token-injection-leaks","title":"kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token","severity":"high","exploited":false,"published_at":"2026-04-14T20:09:00+00:00","url":"https://junglewise.ai/threats/cve-2026-40868-kyverno-apicall-servicecall-implicit-bearer-token-injection-leaks"},{"cve":"CVE-2026-41485","cvss":7.7,"epss":0.0057,"slug":"cve-2026-41485-kyverno-controller-denial-of-service-via-foreach-mutation-panic","title":"Kyverno Controller Denial of Service via forEach Mutation Panic","severity":"high","exploited":false,"published_at":"2026-04-24T20:40:39+00:00","url":"https://junglewise.ai/threats/cve-2026-41485-kyverno-controller-denial-of-service-via-foreach-mutation-panic"},{"cve":"CVE-2026-41068","cvss":7.7,"epss":0.0037,"slug":"cve-2026-41068-kyverno-cross-namespace-read-bypasses-rbac-isolation-incomplete","title":"Kyverno: Cross-Namespace Read Bypasses RBAC Isolation ( Incomplete Fix)","severity":"high","exploited":false,"published_at":"2026-04-16T21:35:04+00:00","url":"https://junglewise.ai/threats/cve-2026-41068-kyverno-cross-namespace-read-bypasses-rbac-isolation-incomplete"},{"cve":"CVE-2026-84199","cvss":7.7,"epss":0.0036,"slug":"cve-2026-84199-kyverno-apicall-server-side-request-forgery-ssrf-via-unvalidated","title":"Kyverno APICall server-side request forgery (SSRF) via unvalidated URL","severity":"high","exploited":false,"published_at":"2026-09-01T12:17:49.407+00:00","url":"https://junglewise.ai/threats/cve-2026-84199-kyverno-apicall-server-side-request-forgery-ssrf-via-unvalidated"},{"cvss":7.7,"slug":"kyverno-apicall-credential-leak-via-serviceaccount-token-forwarding-c14bd03f","title":"Kyverno apiCall credential leak via ServiceAccount token forwarding","severity":"high","exploited":false,"published_at":"2026-04-16T21:37:29+00:00","url":"https://junglewise.ai/threats/kyverno-apicall-credential-leak-via-serviceaccount-token-forwarding-c14bd03f"},{"cvss":7.7,"slug":"kyverno-ssrf-in-apicall-feature-leading-to-multi-tenant-breach-0b4e8088","title":"Kyverno SSRF in APICall feature leading to multi-tenant breach","severity":"high","exploited":false,"published_at":"2026-04-14T20:06:09+00:00","url":"https://junglewise.ai/threats/kyverno-ssrf-in-apicall-feature-leading-to-multi-tenant-breach-0b4e8088"},{"cvss":7.7,"slug":"kyverno-ssrf-in-apicall-via-variable-substitution-6ae5ddc6","title":"Kyverno SSRF in apiCall via variable substitution","severity":"high","exploited":false,"published_at":"2026-04-14T20:05:52+00:00","url":"https://junglewise.ai/threats/kyverno-ssrf-in-apicall-via-variable-substitution-6ae5ddc6"}],"generated_at":"2026-09-26T16:07:00.132667+00:00"}