{"schema_version":1,"title":"Kyverno vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 18 vulnerabilities in Kyverno: 5 in the last 7 days and 12 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-100707, was published on 26 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/kyverno","json_url":"https://junglewise.ai/threats/vendors/kyverno.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/kyverno","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":11,"all_time":18,"critical":3,"exploited":0,"last_7_days":5,"last_30_days":11,"last_90_days":12,"last_365_days":18},"latest":[{"cve":"CVE-2026-100707","cvss":7.7,"slug":"cve-2026-100707-kyverno-before-1-19-1-contains-a-namespace-isolation-bypass-in","title":"Kyverno path traversal in apiCall context entry","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:55.983+00:00","url":"https://junglewise.ai/threats/cve-2026-100707-kyverno-before-1-19-1-contains-a-namespace-isolation-bypass-in"},{"cve":"CVE-2026-100706","cvss":9.9,"slug":"cve-2026-100706-kyverno-before-1-19-1-fails-to-properly-validate-url-encoded","title":"Kyverno Policy apiCall URL path validation bypass","severity":"critical","exploited":false,"published_at":"2026-09-26T14:16:55.843+00:00","url":"https://junglewise.ai/threats/cve-2026-100706-kyverno-before-1-19-1-fails-to-properly-validate-url-encoded"},{"cve":"CVE-2026-100705","cvss":7.6,"slug":"cve-2026-100705-kyverno-before-1-19-1-is-vulnerable-to-server-side-request","title":"Kyverno server-side request forgery in apiCall executor","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:55.703+00:00","url":"https://junglewise.ai/threats/cve-2026-100705-kyverno-before-1-19-1-is-vulnerable-to-server-side-request"},{"cve":"CVE-2026-100704","cvss":7.7,"slug":"cve-2026-100704-kyverno-is-a-policy-engine-for-kubernetes-in-versions-1-14-0","title":"Kyverno ImageValidatingPolicy exception bypass in image verification","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:55.563+00:00","url":"https://junglewise.ai/threats/cve-2026-100704-kyverno-is-a-policy-engine-for-kubernetes-in-versions-1-14-0"},{"cve":"CVE-2026-100703","cvss":7.7,"slug":"cve-2026-100703-kyverno-1-16-0-through-1-19-0-registers-the-globalcontext-lib","title":"Kyverno globalcontext.Lib cross-namespace data access in policies","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:55.42+00:00","url":"https://junglewise.ai/threats/cve-2026-100703-kyverno-1-16-0-through-1-19-0-registers-the-globalcontext-lib"},{"cve":"CVE-2026-84200","cvss":9,"epss":0.0027,"slug":"cve-2026-84200-kyverno-policy-bypass-via-multiple-exceptions","title":"Kyverno policy bypass via multiple exceptions","severity":"critical","exploited":false,"published_at":"2026-09-01T12:17:49.54+00:00","url":"https://junglewise.ai/threats/cve-2026-84200-kyverno-policy-bypass-via-multiple-exceptions"},{"cve":"CVE-2026-84199","cvss":7.7,"epss":0.0036,"slug":"cve-2026-84199-kyverno-apicall-server-side-request-forgery-ssrf-via-unvalidated","title":"Kyverno APICall server-side request forgery (SSRF) via unvalidated URL","severity":"high","exploited":false,"published_at":"2026-09-01T12:17:49.407+00:00","url":"https://junglewise.ai/threats/cve-2026-84199-kyverno-apicall-server-side-request-forgery-ssrf-via-unvalidated"},{"cve":"CVE-2026-84196","cvss":7.7,"epss":0.0035,"slug":"cve-2026-84196-kyverno-server-side-request-forgery-in-apicall","title":"Kyverno server-side request forgery in apiCall","severity":"high","exploited":false,"published_at":"2026-09-01T12:17:49.27+00:00","url":"https://junglewise.ai/threats/cve-2026-84196-kyverno-server-side-request-forgery-in-apicall"},{"cve":"CVE-2026-84195","cvss":7.7,"epss":0.0039,"slug":"cve-2026-84195-kyverno-apicall-credential-leak-to-external-endpoints","title":"Kyverno apiCall credential leak to external endpoints","severity":"high","exploited":false,"published_at":"2026-09-01T12:17:49.13+00:00","url":"https://junglewise.ai/threats/cve-2026-84195-kyverno-apicall-credential-leak-to-external-endpoints"},{"cve":"CVE-2025-15613","cvss":6.5,"epss":0.0027,"slug":"cve-2025-15613-kyverno-server-side-request-forgery-via-service-calls","title":"Kyverno server-side request forgery via Service Calls","severity":"medium","exploited":false,"published_at":"2026-09-01T12:17:18.183+00:00","url":"https://junglewise.ai/threats/cve-2025-15613-kyverno-server-side-request-forgery-via-service-calls"},{"cve":"CVE-2023-54356","cvss":3.7,"epss":0.0015,"slug":"cve-2023-54356-kyverno-weak-cipher-suite-support-in-tls","title":"Kyverno weak cipher suite support in TLS","severity":"low","exploited":false,"published_at":"2026-09-01T12:17:11.22+00:00","url":"https://junglewise.ai/threats/cve-2023-54356-kyverno-weak-cipher-suite-support-in-tls"},{"cve":"CVE-2026-54523","cvss":9.6,"epss":0.0047,"slug":"cve-2026-54523-kyverno-namespacedmutatingpolicy-generator-apply-namespace","title":"Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy CEL","severity":"critical","exploited":false,"published_at":"2026-08-26T15:16:48.91+00:00","url":"https://junglewise.ai/threats/cve-2026-54523-kyverno-namespacedmutatingpolicy-generator-apply-namespace"},{"cve":"CVE-2026-44245","cvss":6.1,"epss":0.0027,"slug":"cve-2026-44245-kyverno-policy-reporter-ui-stored-xss-in-propertycard-component","title":"Kyverno policy-reporter-ui stored XSS in PropertyCard component","severity":"medium","exploited":false,"published_at":"2026-05-12T23:16:18.06+00:00","url":"https://junglewise.ai/threats/cve-2026-44245-kyverno-policy-reporter-ui-stored-xss-in-propertycard-component"},{"cvss":7.7,"slug":"kyverno-apicall-credential-leak-via-serviceaccount-token-forwarding-c14bd03f","title":"Kyverno apiCall credential leak via ServiceAccount token forwarding","severity":"high","exploited":false,"published_at":"2026-04-16T21:37:29+00:00","url":"https://junglewise.ai/threats/kyverno-apicall-credential-leak-via-serviceaccount-token-forwarding-c14bd03f"},{"cve":"CVE-2026-4789","cvss":8.5,"epss":0.0065,"slug":"cve-2026-4789-kyverno-ssrf-in-cel-http-library-functions","title":"Kyverno SSRF in CEL HTTP library functions","severity":"high","exploited":false,"published_at":"2026-04-14T22:37:20+00:00","url":"https://junglewise.ai/threats/cve-2026-4789-kyverno-ssrf-in-cel-http-library-functions"},{"cvss":7.7,"slug":"kyverno-ssrf-in-apicall-feature-leading-to-multi-tenant-breach-0b4e8088","title":"Kyverno SSRF in APICall feature leading to multi-tenant breach","severity":"high","exploited":false,"published_at":"2026-04-14T20:06:09+00:00","url":"https://junglewise.ai/threats/kyverno-ssrf-in-apicall-feature-leading-to-multi-tenant-breach-0b4e8088"},{"cvss":7.7,"slug":"kyverno-ssrf-in-apicall-via-variable-substitution-6ae5ddc6","title":"Kyverno SSRF in apiCall via variable substitution","severity":"high","exploited":false,"published_at":"2026-04-14T20:05:52+00:00","url":"https://junglewise.ai/threats/kyverno-ssrf-in-apicall-via-variable-substitution-6ae5ddc6"},{"cvss":9.8,"slug":"kyverno-ssrf-via-unrestricted-cel-http-functions-d54eaa1c","title":"Kyverno SSRF via unrestricted CEL HTTP functions","severity":"medium","exploited":false,"published_at":"2026-03-30T21:31:05+00:00","url":"https://junglewise.ai/threats/kyverno-ssrf-via-unrestricted-cel-http-functions-d54eaa1c"}],"vendor":{"hub":true,"name":"Kyverno","slug":"kyverno","homepage":"https://kyverno.io/","description":"An open source project providing a policy engine designed for Kubernetes.","url":"https://junglewise.ai/threats/vendors/kyverno"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":1,"exploited":0,"vulnerabilities":1},{"week":"2026-08-31","critical":1,"exploited":0,"vulnerabilities":6},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":1,"exploited":0,"vulnerabilities":5}],"most_severe":[{"cve":"CVE-2026-100706","cvss":9.9,"slug":"cve-2026-100706-kyverno-before-1-19-1-fails-to-properly-validate-url-encoded","title":"Kyverno Policy apiCall URL path validation bypass","severity":"critical","exploited":false,"published_at":"2026-09-26T14:16:55.843+00:00","url":"https://junglewise.ai/threats/cve-2026-100706-kyverno-before-1-19-1-fails-to-properly-validate-url-encoded"},{"cve":"CVE-2026-54523","cvss":9.6,"epss":0.0047,"slug":"cve-2026-54523-kyverno-namespacedmutatingpolicy-generator-apply-namespace","title":"Kyverno is a policy engine designed for cloud native platform engineering teams. From 1.18.0 until 1.18.2, the NamespacedMutatingPolicy CEL","severity":"critical","exploited":false,"published_at":"2026-08-26T15:16:48.91+00:00","url":"https://junglewise.ai/threats/cve-2026-54523-kyverno-namespacedmutatingpolicy-generator-apply-namespace"},{"cve":"CVE-2026-84200","cvss":9,"epss":0.0027,"slug":"cve-2026-84200-kyverno-policy-bypass-via-multiple-exceptions","title":"Kyverno policy bypass via multiple exceptions","severity":"critical","exploited":false,"published_at":"2026-09-01T12:17:49.54+00:00","url":"https://junglewise.ai/threats/cve-2026-84200-kyverno-policy-bypass-via-multiple-exceptions"},{"cve":"CVE-2026-4789","cvss":8.5,"epss":0.0065,"slug":"cve-2026-4789-kyverno-ssrf-in-cel-http-library-functions","title":"Kyverno SSRF in CEL HTTP library functions","severity":"high","exploited":false,"published_at":"2026-04-14T22:37:20+00:00","url":"https://junglewise.ai/threats/cve-2026-4789-kyverno-ssrf-in-cel-http-library-functions"},{"cve":"CVE-2026-84195","cvss":7.7,"epss":0.0039,"slug":"cve-2026-84195-kyverno-apicall-credential-leak-to-external-endpoints","title":"Kyverno apiCall credential leak to external endpoints","severity":"high","exploited":false,"published_at":"2026-09-01T12:17:49.13+00:00","url":"https://junglewise.ai/threats/cve-2026-84195-kyverno-apicall-credential-leak-to-external-endpoints"},{"cve":"CVE-2026-84199","cvss":7.7,"epss":0.0036,"slug":"cve-2026-84199-kyverno-apicall-server-side-request-forgery-ssrf-via-unvalidated","title":"Kyverno APICall server-side request forgery (SSRF) via unvalidated URL","severity":"high","exploited":false,"published_at":"2026-09-01T12:17:49.407+00:00","url":"https://junglewise.ai/threats/cve-2026-84199-kyverno-apicall-server-side-request-forgery-ssrf-via-unvalidated"},{"cve":"CVE-2026-84196","cvss":7.7,"epss":0.0035,"slug":"cve-2026-84196-kyverno-server-side-request-forgery-in-apicall","title":"Kyverno server-side request forgery in apiCall","severity":"high","exploited":false,"published_at":"2026-09-01T12:17:49.27+00:00","url":"https://junglewise.ai/threats/cve-2026-84196-kyverno-server-side-request-forgery-in-apicall"},{"cve":"CVE-2026-100707","cvss":7.7,"slug":"cve-2026-100707-kyverno-before-1-19-1-contains-a-namespace-isolation-bypass-in","title":"Kyverno path traversal in apiCall context entry","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:55.983+00:00","url":"https://junglewise.ai/threats/cve-2026-100707-kyverno-before-1-19-1-contains-a-namespace-isolation-bypass-in"},{"cve":"CVE-2026-100704","cvss":7.7,"slug":"cve-2026-100704-kyverno-is-a-policy-engine-for-kubernetes-in-versions-1-14-0","title":"Kyverno ImageValidatingPolicy exception bypass in image verification","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:55.563+00:00","url":"https://junglewise.ai/threats/cve-2026-100704-kyverno-is-a-policy-engine-for-kubernetes-in-versions-1-14-0"},{"cve":"CVE-2026-100703","cvss":7.7,"slug":"cve-2026-100703-kyverno-1-16-0-through-1-19-0-registers-the-globalcontext-lib","title":"Kyverno globalcontext.Lib cross-namespace data access in policies","severity":"high","exploited":false,"published_at":"2026-09-26T14:16:55.42+00:00","url":"https://junglewise.ai/threats/cve-2026-100703-kyverno-1-16-0-through-1-19-0-registers-the-globalcontext-lib"}],"generated_at":"2026-09-26T15:07:00.181821+00:00","technologies":[{"name":"Kyverno","slug":"kyverno","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/kyverno"}]}