PT-2025-12664 · Kyverno · Kyverno

Frgt10Cs

·

Published

2025-03-24

·

Updated

2025-09-12

·

CVE-2025-29778

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kyverno versions prior to 1.14.0-alpha.1
Description Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to version 1.14.0-alpha.1, Kyverno ignores the subjectRegExp and issuerRegExp fields when verifying artifact signatures in keyless mode. This allows an attacker to deploy Kubernetes resources with artifacts signed by an unexpected certificate. Deploying these unauthorized Kubernetes resources can lead to a full compromise of the Kubernetes cluster. The vulnerability occurs because Kyverno only checks the subject and issuer fields when verifying signatures, while the subjectRegExp and issuerRegExp fields, intended for more flexible matching, are not considered.
Recommendations Upgrade to Kyverno version 1.14.0-alpha.1 or later to resolve this issue.

Exploit

Fix

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-KYVERNO-2025-29778
CVE-2025-29778
GHSA-46MP-8W32-6G94
GO-2025-3562
OPENSUSE-SU-2025:14937-1

Affected Products

Kyverno