CLEANSTART-2026-XV99350

See a problem?
Import Source
https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-XV99350.json
JSON Data
https://api.test.osv.dev/v1/vulns/CLEANSTART-2026-XV99350
Upstream
  • CVE-2025-58183
  • CVE-2025-58186
  • CVE-2025-61725
  • CVE-2026-56864
  • CVE-2026-56865
  • ghsa-259r-337f-4rfw
  • ghsa-gcjh-h69q-9w9g
  • ghsa-hrxh-6v49-42gf
  • ghsa-pmwq-pjrm-6p5r
  • ghsa-vh4v-2xq2-g5cg
Published
2026-09-10T01:29:08Z
Modified
2026-09-10T03:15:04Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log
Details

Multiple security vulnerabilities affect the kyverno package. A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. See references for individual vulnerability details.

References

Affected packages

CleanStart / kyverno

Package

Name
kyverno

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.17.2-r3

Database specific

source
"https://github.com/cleanstart-dev/cleanstart-security-advisories/blob/main/advisories/2026/CLEANSTART-2026-XV99350.json"