CVE-2026-41485 Details
Description
Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.17.2 and 1.16.4, an unchecked type assertion in the `forEach` mutation handler allows any user with permission to create a `Policy` or `ClusterPolicy` to crash the cluster-wide background controller into a persistent CrashLoopBackOff. The same bug also causes the admission controller to drop connections and block all matching resource operations. The crash loop persists until the policy is deleted. The vulnerability is confined to the legacy engine, and CEL-based policies are unaffected. Versions 1.17.2 and 1.16.4 fix the issue.
A denial-of-service vulnerability has been identified in Kyverno versions 1.13.0 through 1.17.1, excluding 1.17.2 and 1.16.4. The issue arises from an unchecked type assertion in the 'forEach' mutation handler of the legacy engine, allowing users with permission to create 'Policy' or 'ClusterPolicy' to crash the cluster-wide background controller. This crash leads to a persistent 'CrashLoopBackOff' state, disrupting all background processing across namespaces. Additionally, the admission controller drops connections, blocking resource operations for matching kinds. The crash loop continues until the problematic policy is deleted.
Users can upgrade to Kyverno versions 1.17.2 or 1.16.4, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-617 | Reachable Assertion | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| kyverno kyverno | >= 1.13.0, < 1.16.4 >= 1.17.0, < 1.17.2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 27, 2026 | Initial Analysis | [email protected] |
| Apr 24, 2026 | CVE Modified | CISA-ADP |
| Apr 24, 2026 | New CVE Received | [email protected] |