CVE Tools

Kyverno

11 CVEs tracked since 2023. Since Nov 2023, none of them reached CISA KEV.

Kyverno CVEs per month

Nov 2023 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Kyverno CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2023-1150
2023-12null or fewer
2024-01null or fewer
2024-02null or fewer
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-09null or fewer
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-01null or fewer
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-05null or fewer
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-02null or fewer
2026-03null or fewer
2026-04null or fewer
2026-05null or fewer
2026-06null or fewer
2026-07null or fewer
2026-08null or fewer
2026-0960

Products

The products that kept showing up in Kyverno's monthly top three, with their CVEs summed over those months.

  1. Kyverno112 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Kyverno.

  1. CVE-2026-100707Kyverno before 1.19.1 Namespace Isolation Bypass via Percent-Encoded Path7.7
  2. CVE-2026-100706kyverno before 1.19.1 Privilege Escalation via Policy apiCall urlPath9.9
  3. CVE-2026-100705Kyverno before 1.19.1 SSRF via legacy apiCall service executor7.6
  4. CVE-2026-100704Kyverno before 1.19.1 ImageValidatingPolicy Exception Bypass7.7
  5. CVE-2026-100703Kyverno before 1.19.1 Cross-Namespace Data Access via globalcontext.Lib7.7
  6. CVE-2026-84200Kyverno before v1.13.0 Policy Bypass via Multiple Exceptions9.0
  7. CVE-2026-84196Kyverno before 1.18.0 Server-Side Request Forgery via apiCall7.7
  8. CVE-2026-84199Kyverno before 1.16.2 SSRF via APICall Feature7.7
  9. CVE-2026-84195Kyverno before 1.16.4 Credential Leak via apiCall7.7
  10. CVE-2025-15613Kyverno before v1.13.4 SSRF via Service Call6.5
  11. CVE-2023-54356Kyverno before 1.9.5 Sweet32 Medium Strength Cipher Suites3.7
  12. CVE-2026-54523Kyverno: NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system9.6
  13. CVE-2026-44245Kyverno: [policy-reporter-ui] XSS via Stored Property Values in PropertyCard Component6.1
  14. CVE-2026-41485Kyverno Controller Denial of Service via forEach Mutation Panic7.7
  15. CVE-2026-41323Kyverno: ServiceAccount token leaked to external servers via apiCall service URL8.1

The record

Peak rank
#144 in Nov 2023
Busiest month shown
Sep 2026, 6 CVEs
Months with a KEV entry
0 since Nov 2023
Monthly snapshots
2 since 2023
Kyverno's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store