CVE-2026-44245General(kyverno / policy-reporter-ui)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 2.5.2, Vue 3's v-html directive is the framework-documented mechanism for injecting raw HTML, and it intentionally disables the auto-escaping that {{ }} interpolation provides. The PropertyCard.vue component uses v-html for the else branch of the URL check, meaning any non-URL string value flows directly into the DOM as HTML. The isURL() guard only filters values that parse as http: or https: URLs, so any HTML payload not starting with those schemes bypasses it entirely. The data originates from Kubernetes PolicyReport .results[].properties fields, which are arbitrary string maps populated by policy engines and potentially by any principal with write access to PolicyReport objects in the cluster. This vulnerability is fixed in 2.5.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • policy-reporter-ui

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-12); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
policy-reporter-ui

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-12: 1Mentions · 2026-05-13: 1Technical Details · 2026-05-13: 105-1205-13
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-121
General1
2026-05-131
Disclosure1
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-44245 Cross-Site Scripting Vulnerability in Kyverno Prior to Version 2.5.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-44245

    Post summary

    The text announces a new CVE (CVE-2026-44245) describing an XSS vulnerability in Kyverno versions before 2.5.2, providing basic technical details but no PoC, exploit, or mitigation information.

    0000042
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-44245 Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 2.5.2, Vue 3's v-html directive is the framework-documented mechanism for in… https://www.cve.org/CVERecord?id=CVE-2026-44245

    Post summary

    The tweet references CVE-2026-44245 involving Kyverno and the Vue 3 v-html directive but provides no deep technical, exploit, or mitigation details.

    0000082
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkyvernopolicy-reporter-ui---

Explore more