CVE-2025-29778
Last modified
CVE-2025-29778 is a high-severity vulnerability rated 8/10 on the CVSS scale. Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to version 1.14.0-alpha.1, Kyverno ignores subjectRegExp and IssuerRegExp while verifying artifact's sign with keyless mode. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to version 1.14.0-alpha.1, Kyverno ignores subjectRegExp and IssuerRegExp while verifying artifact's sign with keyless mode. It allows the attacker to deploy kubernetes resources with the artifacts that were signed by unexpected certificate. Deploying these unauthorized kubernetes resources can lead to full compromise of kubernetes cluster. Version 1.14.0-alpha.1 contains a patch for the issue.
Metrics
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kyverno | Kyverno | >= 1.13.0, < 1.13.6 |
References
- https://github.com/kyverno/kyverno/pull/12237Issue Tracking
- https://github.com/kyverno/kyverno/security/advisories/GHSA-46mp-8w32-6g94Exploit, Vendor Advisory
- https://github.com/kyverno/policies/issues/1246Exploit, Issue Tracking
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-29778?
How severe is CVE-2025-29778?
How do I fix CVE-2025-29778?
Are you affected by CVE-2025-29778?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
