Namespace Selector Bypass in Kyverno Policy Engine
CVE-2025-46342
What is CVE-2025-46342?
Kyverno, a policy engine for cloud-native platform engineering, has a vulnerability that can lead to a bypass of vital security policies. Prior to the release of versions 1.13.5 and 1.14.0, certain policy rules that employ namespace selectors might not be properly enforced during the admission review request process. This occurs because of an oversight in the error handling of the function 'GetNamespaceSelectorsFromNamespaceLister.' As a result, security-sensitive mutations and validations can be sidestepped, enabling potential attackers with Kubernetes API access to execute harmful actions. The issue has been resolved in the updated versions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
kyverno < 1.13.5 < 1.13.5
kyverno >= 1.14.0-alpha.1, < 1.14.0 < 1.14.0-alpha.1, 1.14.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
