kyverno

module

Versions in this module

v1
Sep 10, 2026 GO-2025-3615 +2 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Sep 9, 2026 GO-2025-3615 +2 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Aug 20, 2026 GO-2025-3615 +2 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Aug 18, 2026 GO-2025-3615 +2 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Aug 12, 2026 GO-2025-3615 +2 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Aug 11, 2026 GO-2025-3615 +2 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Aug 3, 2026 GO-2025-3615 +2 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jul 10, 2026 GO-2025-3615 +2 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jul 9, 2026 GO-2025-3615 +3 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Alert  GO-2026-6296: Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system in github.com/kyverno/kyverno
May 18, 2026 GO-2025-3615 +3 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Alert  GO-2026-6296: Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system in github.com/kyverno/kyverno
May 15, 2026 GO-2025-3615 +3 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Alert  GO-2026-6296: Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system in github.com/kyverno/kyverno
May 13, 2026 GO-2025-3615 +3 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Alert  GO-2026-6296: Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system in github.com/kyverno/kyverno
Apr 29, 2026 GO-2025-3615 +3 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Alert  GO-2026-6296: Kyverno's NamespacedGeneratingPolicy generator.apply() namespace argument unvalidated -- background controller creates RoleBindings in any namespace including kube-system in github.com/kyverno/kyverno
Apr 21, 2026 GO-2025-3615 +2 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Apr 23, 2026 GO-2025-3615 +2 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Apr 17, 2026 GO-2025-3615 +3 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Feb 19, 2026 GO-2025-3615 +3 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Feb 18, 2026 GO-2025-3615 +3 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Feb 2, 2026 GO-2025-3615 +3 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 30, 2026 GO-2025-3615 +7 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Alert  GO-2026-5621: Kyverno has SSRF via CEL http.Get/http.Post in NamespacedValidatingPolicy allows cross-namespace data access in github.com/kyverno/kyverno
Jan 28, 2026 GO-2025-3615 +7 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Alert  GO-2026-5621: Kyverno has SSRF via CEL http.Get/http.Post in NamespacedValidatingPolicy allows cross-namespace data access in github.com/kyverno/kyverno
Jan 21, 2026 GO-2025-3615 +7 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Alert  GO-2026-5621: Kyverno has SSRF via CEL http.Get/http.Post in NamespacedValidatingPolicy allows cross-namespace data access in github.com/kyverno/kyverno
Apr 23, 2026 GO-2025-3615 +6 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Alert  GO-2026-5621: Kyverno has SSRF via CEL http.Get/http.Post in NamespacedValidatingPolicy allows cross-namespace data access in github.com/kyverno/kyverno
Apr 20, 2026 GO-2025-3615 +7 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Alert  GO-2026-5621: Kyverno has SSRF via CEL http.Get/http.Post in NamespacedValidatingPolicy allows cross-namespace data access in github.com/kyverno/kyverno
Jan 27, 2026 GO-2025-3615 +7 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Alert  GO-2026-5621: Kyverno has SSRF via CEL http.Get/http.Post in NamespacedValidatingPolicy allows cross-namespace data access in github.com/kyverno/kyverno
Jan 27, 2026 GO-2025-3615 +9 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Alert  GO-2026-5621: Kyverno has SSRF via CEL http.Get/http.Post in NamespacedValidatingPolicy allows cross-namespace data access in github.com/kyverno/kyverno
Jan 9, 2026 GO-2025-3615 +9 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Alert  GO-2026-5621: Kyverno has SSRF via CEL http.Get/http.Post in NamespacedValidatingPolicy allows cross-namespace data access in github.com/kyverno/kyverno
Jan 7, 2026 GO-2025-3615 +10 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Alert  GO-2026-5621: Kyverno has SSRF via CEL http.Get/http.Post in NamespacedValidatingPolicy allows cross-namespace data access in github.com/kyverno/kyverno
Dec 3, 2025 GO-2025-3615 +10 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Alert  GO-2026-5621: Kyverno has SSRF via CEL http.Get/http.Post in NamespacedValidatingPolicy allows cross-namespace data access in github.com/kyverno/kyverno
Dec 2, 2025 GO-2025-3615 +10 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Alert  GO-2026-5621: Kyverno has SSRF via CEL http.Get/http.Post in NamespacedValidatingPolicy allows cross-namespace data access in github.com/kyverno/kyverno
Nov 17, 2025 GO-2025-3615 +10 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Alert  GO-2026-5621: Kyverno has SSRF via CEL http.Get/http.Post in NamespacedValidatingPolicy allows cross-namespace data access in github.com/kyverno/kyverno
Nov 7, 2025 GO-2025-3615 +10 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Alert  GO-2026-5621: Kyverno has SSRF via CEL http.Get/http.Post in NamespacedValidatingPolicy allows cross-namespace data access in github.com/kyverno/kyverno
Nov 6, 2025 GO-2025-3615 +9 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 23, 2025 GO-2025-3615 +9 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Nov 5, 2025 GO-2025-3615 +7 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 27, 2026 GO-2025-3615 +7 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 27, 2026 GO-2025-3615 +9 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Sep 18, 2025 GO-2025-3615 +9 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Sep 17, 2025 GO-2025-3615 +9 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Aug 15, 2025 GO-2025-3615 +9 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Aug 14, 2025 GO-2025-3615 +9 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Aug 13, 2025 GO-2025-3615 +9 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Aug 12, 2025 GO-2025-3615 +9 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jul 31, 2025 GO-2025-3615 +9 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jul 28, 2025 GO-2025-3615 +9 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jul 25, 2025 GO-2025-3615 +9 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jul 25, 2025 GO-2025-3615 +9 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jul 17, 2025 GO-2025-3615 +9 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jul 1, 2025 GO-2025-3615 +9 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Nov 4, 2025 GO-2025-3615 +9 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 31, 2025 GO-2025-3615 +9 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jun 26, 2025 GO-2025-3615 +9 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jun 18, 2025 GO-2025-3615 +9 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jun 2, 2025 GO-2025-3615 +9 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
May 29, 2025 GO-2025-3615 +10 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Apr 30, 2025 GO-2025-3615 +10 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Apr 24, 2025 GO-2025-3615 +10 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Apr 2, 2025 GO-2025-3615 +11 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Mar 22, 2025 GO-2025-3615 +11 more
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
May 8, 2025 GO-2025-3562 +11 more
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Apr 29, 2025 GO-2025-3562 +11 more
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Feb 8, 2025 GO-2025-3562 +12 more
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Feb 6, 2025 GO-2025-3562 +12 more
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Dec 10, 2024 GO-2025-3562 +12 more
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Dec 5, 2024 GO-2025-3562 +12 more
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Nov 12, 2024 GO-2025-3562 +12 more
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Nov 7, 2024 GO-2025-3562 +12 more
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 29, 2024 GO-2025-3562 +12 more
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 22, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 14, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Sep 26, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Sep 12, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 16, 2025 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Sep 27, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Sep 26, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Sep 18, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Sep 16, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jul 12, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jul 11, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jul 9, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jun 17, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jun 14, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jun 11, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
May 31, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
May 30, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
May 23, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
May 23, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
May 22, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
May 21, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
May 3, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
May 1, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Apr 22, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Apr 17, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Apr 4, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Mar 30, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Mar 15, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Mar 8, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Mar 5, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Feb 29, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Feb 28, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Feb 26, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Feb 13, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Feb 5, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
May 9, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 19, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 5, 2024 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Dec 28, 2023 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Dec 22, 2023 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Nov 28, 2023 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Nov 10, 2023 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Nov 9, 2023 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Nov 6, 2023 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Nov 6, 2023 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Nov 3, 2023 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 24, 2023 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 20, 2023 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 13, 2023 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 12, 2023 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Sep 27, 2023 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Sep 25, 2023 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Sep 22, 2023 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Sep 20, 2023 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Dec 20, 2023 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Nov 28, 2023 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Nov 3, 2023 GO-2024-3230 +13 more
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 31, 2023 GO-2023-2340 +14 more
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Aug 11, 2023 GO-2023-2340 +14 more
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jul 28, 2023 GO-2023-2340 +14 more
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jul 6, 2023 GO-2023-2340 +14 more
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jun 29, 2023 GO-2023-2340 +14 more
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
May 30, 2023 GO-2023-2340 +14 more
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
May 23, 2023 GO-2023-1819 +15 more
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
May 10, 2023 GO-2023-1819 +15 more
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Apr 14, 2023 GO-2023-1819 +15 more
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Apr 6, 2023 GO-2023-1819 +15 more
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
May 26, 2023 GO-2023-1819 +15 more
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
May 25, 2023 GO-2023-1804 +16 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
May 9, 2023 GO-2023-1801 +17 more
Alert  GO-2023-1801: kyverno seccomp control can be circumvented in github.com/kyverno/kyverno
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Mar 21, 2023 GO-2023-1801 +17 more
Alert  GO-2023-1801: kyverno seccomp control can be circumvented in github.com/kyverno/kyverno
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Mar 13, 2023 GO-2023-1804 +16 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Mar 9, 2023 GO-2023-1804 +16 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Mar 6, 2023 GO-2023-1804 +16 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Feb 1, 2023 GO-2023-1804 +16 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4285: Bypassing Kyverno Policies via Double Policy Exceptions in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 25, 2023 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 24, 2023 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 18, 2023 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 16, 2023 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 10, 2023 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Dec 22, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Dec 20, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Dec 19, 2022 GO-2022-1180 +16 more
Alert  GO-2022-1180: Verification rule bypass in github.com/kyverno/kyverno
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Dec 9, 2022 GO-2022-1180 +16 more
Alert  GO-2022-1180: Verification rule bypass in github.com/kyverno/kyverno
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Dec 8, 2022 GO-2022-1180 +16 more
Alert  GO-2022-1180: Verification rule bypass in github.com/kyverno/kyverno
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Dec 5, 2022 GO-2022-1180 +16 more
Alert  GO-2022-1180: Verification rule bypass in github.com/kyverno/kyverno
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Dec 2, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Nov 30, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Nov 21, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Nov 18, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Nov 17, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 25, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 17, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 24, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 21, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 19, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 10, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 7, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 4, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Sep 30, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Sep 29, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Sep 12, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Sep 8, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 11, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Sep 26, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Aug 24, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jul 25, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jul 21, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jun 28, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jun 17, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jun 2, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
May 30, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
May 25, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
May 12, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Feb 25, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jun 17, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Mar 31, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Mar 30, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Mar 29, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Mar 25, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Mar 1, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Feb 25, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Feb 23, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Feb 8, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Feb 7, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Feb 4, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 29, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 25, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 26, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 25, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 24, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 20, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 20, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 12, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 11, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 7, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 7, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 6, 2022 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Dec 10, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Dec 9, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Dec 7, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Dec 3, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Nov 30, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Nov 16, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 26, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 20, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 19, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 18, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 15, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 8, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Sep 16, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Sep 15, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Sep 13, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Aug 11, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Aug 11, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jul 30, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jul 28, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jul 23, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jun 24, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jun 18, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jun 18, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jun 17, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jun 16, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jun 8, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jun 2, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
May 17, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
May 13, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
May 10, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
May 8, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
May 7, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Apr 29, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Apr 16, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Apr 16, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Apr 14, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Apr 6, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Apr 1, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Mar 26, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Mar 5, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Mar 3, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Feb 16, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Feb 9, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Feb 9, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Feb 3, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 25, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 19, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 12, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 1, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Dec 9, 2020 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Dec 7, 2020 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Dec 1, 2020 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Nov 24, 2020 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Nov 19, 2020 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Nov 18, 2020 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Nov 16, 2020 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 9, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 4, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 2, 2021 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Nov 9, 2020 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 22, 2020 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 8, 2020 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 16, 2020 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 15, 2020 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jan 11, 2020 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Dec 5, 2019 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Nov 14, 2019 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
v0
Oct 31, 2019 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Oct 28, 2019 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Sep 4, 2019 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Aug 30, 2019 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Aug 22, 2019 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Aug 9, 2019 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Aug 3, 2019 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jul 21, 2019 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jul 1, 2019 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jun 20, 2019 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
Jun 6, 2019 GO-2023-1804 +15 more
Alert  GO-2023-1804: Kyverno vulnerable due to usage of insecure cipher in github.com/kyverno/kyverno
Alert  GO-2023-1819: Kyverno resource with a deletionTimestamp may allow policy circumvention in github.com/kyverno/kyverno
Alert  GO-2023-2340: Attacker can cause Kyverno user to unintentionally consume insecure image in github.com/kyverno/kyverno
Alert  GO-2024-3230: Kyverno's PolicyException objects can be created in any namespace by default in github.com/kyverno/kyverno
Alert  GO-2025-3562: Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Alert  GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
Alert  GO-2025-3652: Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno
Alert  GO-2025-3823: Kyverno's Improper JMESPath Variable Evaluation Lead to Denial of Service in github.com/kyverno/kyverno
Alert  GO-2026-4381: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
Alert  GO-2026-4382: Kyverno Denial of Service via Context Variable Amplification in Policy Engine in github.com/kyverno/kyverno
Alert  GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
Alert  GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
Alert  GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
Alert  GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
Alert  GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
Alert  GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL