BIT-kyverno-2026-23881

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/kyverno/BIT-kyverno-2026-23881.json
JSON Data
https://api.test.osv.dev/v1/vulns/BIT-kyverno-2026-23881
Aliases
Published
2026-02-03T08:42:39Z
Modified
2026-09-10T16:01:12Z
Summary
Kyverno Denial of Service via Context Variable Amplification in Policy Engine
Details

Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have unbounded memory consumption in Kyverno's policy engine that allows users with policy creation privileges to cause denial of service by crafting policies that exponentially amplify string data through context variables. Versions 1.16.3 and 1.15.3 contain a patch for the vulnerability.

Database specific
{
    "cpes": [
        "cpe:2.3:a:kyverno:kyverno:*:*:*:*:*:go:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / kyverno

Package

Name
kyverno
Purl
pkg:bitnami/kyverno

Severity

  • 7.7 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.15.3
Introduced
1.16.0
Fixed
1.16.3

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/kyverno/BIT-kyverno-2026-23881.json"