CVE-2026-23881

Source
https://cve.org/CVERecord?id=CVE-2026-23881
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23881.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-23881
Aliases
Downstream
Related
Published
2026-01-27T16:10:44.376Z
Modified
2026-05-18T05:58:34.135606893Z
Severity
  • 7.7 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H CVSS Calculator
Summary
Kyverno Denial of Service via Context Variable Amplification in Policy Engine
Details

Kyverno is a policy engine designed for cloud native platform engineering teams. Versions prior to 1.16.3 and 1.15.3 have unbounded memory consumption in Kyverno's policy engine that allows users with policy creation privileges to cause denial of service by crafting policies that exponentially amplify string data through context variables. Versions 1.16.3 and 1.15.3 contain a patch for the vulnerability.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/23xxx/CVE-2026-23881.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-770"
    ]
}
References

Affected packages

Git / github.com/kyverno/kyverno

Affected ranges

Type
GIT
Repo
https://github.com/kyverno/kyverno
Events

Affected versions

kyverno-chart-3.*
kyverno-chart-3.6.0
kyverno-chart-3.6.1
kyverno-chart-3.6.1-rc.1
kyverno-chart-3.6.1-rc.2
kyverno-chart-3.6.2
kyverno-chart-3.6.2-rc.1
kyverno-chart-3.6.3-rc.1
kyverno-policies-chart-3.*
kyverno-policies-chart-3.6.0
kyverno-policies-chart-3.6.1
kyverno-policies-chart-3.6.1-rc.1
kyverno-policies-chart-3.6.1-rc.2
kyverno-policies-chart-3.6.2
kyverno-policies-chart-3.6.2-rc.1
kyverno-policies-chart-3.6.3-rc.1
v1.*
v1.16.0
v1.16.1
v1.16.1-rc.1
v1.16.1-rc.2
v1.16.2
v1.16.2-rc.1
v1.16.3-rc.1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-23881.json"