CVE-2025-47281
Last modified
CVE-2025-47281 is a high-severity vulnerability rated 7.7/10 on the CVSS scale. Kyverno is a policy engine designed for cloud native platform engineering teams. In versions 1.14.1 and below, a Denial of Service (DoS) vulnerability exists due to improper handling of JMESPath variable substitutions. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
Kyverno is a policy engine designed for cloud native platform engineering teams. In versions 1.14.1 and below, a Denial of Service (DoS) vulnerability exists due to improper handling of JMESPath variable substitutions. Attackers with permissions to create or update Kyverno policies can craft expressions using the {{@}} variable combined with a pipe and an invalid JMESPath function (e.g., {{@ | non_existent_function }}). This leads to a nil value being substituted into the policy structure. Subsequent processing by internal functions, specifically getValueAsStringMap, which expect string values, results in a panic due to a type assertion failure (interface {} is nil, not string). This crashes Kyverno worker threads in the admission controller and causes continuous crashes of the reports controller pod. This is fixed in version 1.14.2.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Kyverno | Kyverno | < 1.14.2 |
References
- https://github.com/kyverno/kyverno/security/advisories/GHSA-r5p3-955p-5ggqExploit, Mitigation, Vendor Advisory
- https://github.com/kyverno/kyverno/security/advisories/GHSA-r5p3-955p-5ggqExploit, Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-47281?
How severe is CVE-2025-47281?
How do I fix CVE-2025-47281?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-47276Actualizer is a single shell script solution to allow develo…7.5
- CVE-2025-47277vLLM, an inference and serving engine for large language mod…9.8
- CVE-2025-47278Flask is a web server gateway interface (WSGI) web applicati…1.8
- CVE-2025-47279Undici is an HTTP/1.1 client for Node.js. Prior to versions …3.1
- CVE-2025-4728A vulnerability was found in SourceCodester Best Online News…9.8
- CVE-2025-47280Umbraco Forms is a form builder that integrates with the Umb…6.1
- CVE-2025-47282Gardener External DNS Management is an environment to manage…9.9
- CVE-2025-47283Gardener implements the automated management and operation o…9.9
- CVE-2025-47284Gardener implements the automated management and operation o…9.9
- CVE-2025-47285Vyper is the Pythonic Programming Language for the Ethereum …2.9
- CVE-2025-47286Combodo iTop is a web based IT service management tool. In v…7.2
- CVE-2025-47287Tornado is a Python web framework and asynchronous networkin…7.5
Are you affected by CVE-2025-47281?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
