<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:54:50.226019+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-kyverno-2025-46342</id>
    <title>BIT-kyverno-2025-46342 — Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements</title>
    <updated>2026-10-02T16:54:50.230614+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: kyverno</p>
<p>Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.13.5 and 1.14.0, it may happen that policy rules using namespace selector(s) in their match statements are mistakenly not applied during admission review request processing due to a missing error propagation in function `GetNamespaceSelectorsFromNamespaceLister` in `pkg/utils/engine/labels.go`. As a consequence, security-critical mutations and validations are bypassed, potentially allowing attackers with K8s API access to perform malicious operations. This issue has been patched in versions 1.13.5 and 1.14.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-kyverno-2025-46342"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-uq68343</id>
    <title>Withdrawn: CLEANSTART-2026-UQ68343 — During chain building, the amount of work that is done is not correctly limited when a large number of intermediate cer…</title>
    <updated>2026-10-02T16:54:50.230667+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: kyverno-policy-reporter-kyverno-plugin-fips</p>
<p>Multiple security vulnerabilities affect the kyverno-policy-reporter-kyverno-plugin-fips package. During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-uq68343"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-235927</id>
    <title>EUVD-2026-235927</title>
    <updated>2026-10-02T16:54:50.230693+00:00</updated>
    <content>EUVD-2026-235927</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-235927"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-46342</id>
    <title>fkie_cve-2025-46342</title>
    <updated>2026-10-02T16:54:50.230707+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.13.5 and 1.14.0, it may happen that policy rules using namespace selector(s) in their match statements are mistakenly not applied during admission review request processing due to a missing error propagation in function `GetNamespaceSelectorsFromNamespaceLister` in `pkg/utils/engine/labels.go`. As a consequence, security-critical mutations and validations are bypassed, potentially allowing attackers with K8s API access to perform malicious operations. This issue has been patched in versions 1.13.5 and 1.14.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-46342"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jrr2-x33p-6hvc</id>
    <title>GHSA-jrr2-x33p-6hvc — Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements</title>
    <updated>2026-10-02T16:54:50.230730+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/kyverno/kyverno</p>
<p>### Summary</p>
<p>Due to a missing error propagation in function `GetNamespaceSelectorsFromNamespaceLister` in `pkg/utils/engine/labels.go` it may happen that policy rules using namespace selector(s) in their `match` statements are mistakenly not applied during admission review request processing. As a consequence, security-critical mutations and validations are bypassed, potentially allowing attackers with K8s API access to perform malicious operations.</p>
<p>### Details</p>
<p>As a policy engine Kyverno is a critical component ensuring the security of Kubernetes clusters by apply security-relevant policy rules in the Kubernetes admission control process.</p>
<p>We encountered a case where Kyverno did not apply policy rules which should have been applied.  This happened in both the mutation and the validation phase of admission control.  Effectively Kyverno handled the admission review requests as
if those policy rules did not exist.  Consequently, the Kube API request was accepted without applying security-relevant patches and validations.</p>
<p>As the root cause we identified a missing error propagation in function `GetNamespaceSelectorsFromNamespaceLister` in `pkg/utils/engine/labels.go` ([src][1]).</p>
<p>All affected policy rules use a namespace selector in their match resource filters like this:</p>
<p>```yaml
match:
  all:
  - resources:
      namespaceSelector:
        matchExpressions:
        - key: label1
          operator: Exists
```</p>
<p>Such specification intents to apply rules only to resource object…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jrr2-x33p-6hvc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15059-1</id>
    <title>openSUSE-SU-2025:15059-1 — govulncheck-vulndb-0.0.20250506T153719-1.1 on GA media</title>
    <updated>2026-10-02T16:54:50.230779+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>govulncheck-vulndb-0.0.20250506T153719-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15059-1"/>
  </entry>
</feed>
