BIT-kyverno-2026-41485

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/kyverno/BIT-kyverno-2026-41485.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-kyverno-2026-41485
Aliases
Published
2026-04-28T10:46:31Z
Modified
2026-09-08T08:48:08Z
Summary
Kyverno Controller Denial of Service via forEach Mutation Panic
Details

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.17.2 and 1.16.4, an unchecked type assertion in the forEach mutation handler allows any user with permission to create a Policy or ClusterPolicy to crash the cluster-wide background controller into a persistent CrashLoopBackOff. The same bug also causes the admission controller to drop connections and block all matching resource operations. The crash loop persists until the policy is deleted. The vulnerability is confined to the legacy engine, and CEL-based policies are unaffected. Versions 1.17.2 and 1.16.4 fix the issue.

Database specific
{
    "cpes":  [
        "cpe:2.3:a:kyverno:kyverno:*:*:*:*:*:go:*:*"
    ],
    "severity":  "High"
}
References

Affected packages

Bitnami / kyverno

Package

Name
kyverno
Purl
pkg:bitnami/kyverno

Severity

  • 7.7 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.16.4
Introduced
1.17.0
Fixed
1.17.2

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/kyverno/BIT-kyverno-2026-41485.json"