CVE-2026-41485Disclosure(kyverno / kyverno)

LOWCVSS 7.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch kyverno kyverno systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.17.2 and 1.16.4, an unchecked type assertion in the `forEach` mutation handler allows any user with permission to create a `Policy` or `ClusterPolicy` to crash the cluster-wide background controller into a persistent CrashLoopBackOff. The same bug also causes the admission controller to drop connections and block all matching resource operations. The crash loop persists until the policy is deleted. The vulnerability is confined to the legacy engine, and CEL-based policies are unaffected. Versions 1.17.2 and 1.16.4 fix the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-617

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kyverno

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-24); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
kyverno

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-24: 1Mentions · 2026-04-25: 1Mentions · 2026-04-28: 1Patch / Workaround · 2026-04-25: 1Technical Details · 2026-04-24: 1Technical Details · 2026-04-25: 1Technical Details · 2026-04-28: 104-2404-2504-28
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-41485: CVE-2026-41485: Denial of Service in Kyverno via Unchecked Type Assertion in Mutation Engine Kyverno policy engine versions prior to 1.16.4 and 1.17.0-rc1 through 1.17.1 are vulnerable to a Denial of Service. An unchecked Go type asser... https://cvereports.com/reports/CVE-2026-41485

    Post summary

    The post reports a Denial of Service vulnerability (CVE-2026-41485) in Kyverno's policy engine, detailing the affected versions and the flaw’s technical origin, without any evidence of exploitation or mitigation.

    0000021
    36 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41485 Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.17.2 and 1.16.4, an unchecked type assertion in the `forEach` mut… https://www.cve.org/CVERecord?id=CVE-2026-41485

    Post summary

    The text discloses CVE-2026-41485, detailing an unchecked type assertion flaw in Kyverno and indicating that versions 1.17.2 and 1.16.4 contain the fix.

    0000098
    57.2K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Kyverno (High), Unchecked Type Assertion, #CVE-2026-41485 (High) https://dailycve.com/kyverno-high-unchecked-type-assertion-cve-2026-41485-high/

    Post summary

    A high‑severity vulnerability (CVE‑2026‑41485) involving an unchecked type assertion has been disclosed for Kyverno, with no PoC, exploit, or patch details provided in the text.

    0000026
    183 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appkyvernokyverno---
Appkyvernokyverno---

Explore more