blob: 7240fbb03e2f45b255c4b9f76fcc0b542fc43ad1 [file]
id: GO-2026-4381
modules:
- module: github.com/kyverno/kyverno
versions:
- fixed: 1.15.3
- introduced: 1.16.0-rc.1
- fixed: 1.16.3
vulnerable_at: 1.16.3-rc.1
summary: Kyverno Cross-Namespace Privilege Escalation via Policy apiCall in github.com/kyverno/kyverno
cves:
- CVE-2026-22039
ghsas:
- GHSA-8p9x-46gm-qfx2
references:
- advisory: https://github.com/kyverno/kyverno/security/advisories/GHSA-8p9x-46gm-qfx2
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-22039
- fix: https://github.com/kyverno/kyverno/commit/e0ba4de4f1e0ca325066d5095db51aec45b1407b
- fix: https://github.com/kyverno/kyverno/commit/eba60fa856c781bcb9c3be066061a3df03ae4e3e
source:
id: GHSA-8p9x-46gm-qfx2
created: 2026-02-02T11:07:20.85527766-05:00
review_status: UNREVIEWED