Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/kyverno/kyverno
  4. ›
  5. CVE-2026-41485

CVE-2026-41485: Kyverno Controller Denial of Service via forEach Mutation Panic

April 24, 2026

An unchecked type assertion in the forEach mutation handler allows any user with permission to create a Policy or ClusterPolicy to crash the cluster-wide background controller into a persistent CrashLoopBackOff. The same bug also causes the admission controller to drop connections and block all matching resource operations. The crash loop persists until the policy is deleted. The vulnerability is confined to the legacy engine, and CEL-based policies are unaffected.

References

  • github.com/advisories/GHSA-fpjq-c37h-cqcv
  • github.com/kyverno/kyverno
  • github.com/kyverno/kyverno/commit/76c8fdbe87328722e099e1fd44c3f21c9f7809cb
  • github.com/kyverno/kyverno/commit/80e728c2283a0c65e5adb02d8a907106e6ebe7e3
  • github.com/kyverno/kyverno/security/advisories/GHSA-fpjq-c37h-cqcv
  • nvd.nist.gov/vuln/detail/CVE-2026-41485

Code Behaviors & Features

Detect and mitigate CVE-2026-41485 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 1.13.0 before 1.16.4, all versions starting from 1.17.0-rc.1 before 1.17.2

Fixed versions

  • 1.16.4
  • 1.17.2

Solution

Upgrade to versions 1.16.4, 1.17.2 or above.

Impact 7.7 HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-617: Reachable Assertion

Source file

go/github.com/kyverno/kyverno/CVE-2026-41485.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Fri, 08 May 2026 00:23:07 +0000.