๐Ÿ” CVE Alert

CVE-2026-41485

HIGH 7.7

Kyverno Controller Denial of Service via forEach Mutation Panic

CVSS Score
7.7
EPSS Score
0.0%
EPSS Percentile
0th

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.17.2 and 1.16.4, an unchecked type assertion in the `forEach` mutation handler allows any user with permission to create a `Policy` or `ClusterPolicy` to crash the cluster-wide background controller into a persistent CrashLoopBackOff. The same bug also causes the admission controller to drop connections and block all matching resource operations. The crash loop persists until the policy is deleted. The vulnerability is confined to the legacy engine, and CEL-based policies are unaffected. Versions 1.17.2 and 1.16.4 fix the issue.

CWE CWE-617
Vendor kyverno
Product kyverno
Published Apr 24, 2026
Stay Ahead of the Next One

Get instant alerts for kyverno kyverno

Be the first to know when new high vulnerabilities affecting kyverno kyverno are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

kyverno / kyverno
< 1.16.4 >= 1.17.0-rc1, < 1.17.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kyverno/kyverno/security/advisories/GHSA-fpjq-c37h-cqcv github.com: https://github.com/kyverno/kyverno/commit/76c8fdbe87328722e099e1fd44c3f21c9f7809cb github.com: https://github.com/kyverno/kyverno/commit/80e728c2283a0c65e5adb02d8a907106e6ebe7e3