Affected by GO-2025-3615
and 7 other vulnerabilities
GO-2025-3615: Kyverno vulnerable to SSRF via Service Calls in github.com/kyverno/kyverno
GO-2026-5268: Kyverno apiCall automatically forwards ServiceAccount token to external endpoints (credential leak) in github.com/kyverno/kyverno
GO-2026-5337: Kyverno: Cross-Namespace Read Bypasses RBAC Isolation (CVE-2026-22039 Incomplete Fix) in github.com/kyverno/kyverno
GO-2026-5351: Kyverno: ServiceAccount token leaked to external servers via apiCall service URL in github.com/kyverno/kyverno
GO-2026-5371: Kyverno APICall SSRF Vulnerability Leading to Multi-Tenant Isolation Breach in github.com/kyverno/kyverno
GO-2026-5374: Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno
GO-2026-5575: kyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount token in github.com/kyverno/kyverno
GO-2026-5594: Kyverno has unrestricted outbound requests in Kyverno apiCall enabling SSRF in github.com/kyverno/kyverno
package
Version:
v1.15.20
Opens a new window with list of versions in this module.
Published: Nov 5, 2025
License: Apache-2.0
Opens a new window with license information.
Imports: 20
Opens a new window with list of imports.
Imported by: 0
Opens a new window with list of known importers.
Documentation
¶
func New(
ctx context.Context,
gce *kyvernov2alpha1.GlobalContextEntry,
eventGen event.Interface,
kyvernoClient versioned.Interface,
gceLister kyvernov2alpha1listers.GlobalContextEntryLister,
logger logr.Logger,
client apicall.ClientInterface,
call kyvernov1.APICall,
period time.Duration,
maxResponseLength int64,
shouldUpdateStatus bool,
jp jmespath.Interface,
) (store.Entry, error)
Source Files
¶
Click to show internal directories.
Click to hide internal directories.