VDB
GO-2025-3562
GO-2025-3562
PUBLISHED
Kyverno ignores subjectRegExp and IssuerRegExp in github.com/kyverno/kyverno
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | kyverno/kyverno | 0, 0 |
Timeline
- Mar 25, 2025 CVE Published
- Feb 4, 2026 CVE Updated
- May 1, 2026 Security Advisory
References
- https://github.com/kyverno/kyverno/security/advisories/GHSA-46mp-8w32-6g94 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-29778 advisory
- https://github.com/kyverno/kyverno/commit/8777672fb17bdf252bd2e7d8de3441e240404a60 patch
- https://github.com/kyverno/kyverno/pull/12237 patch
- https://github.com/Mohdcode/kyverno/blob/373f942ea9fa8b63140d0eb0e101b9a5f71033f3/pkg/cosign/cosign.go#L537 url
- https://github.com/kyverno/policies/issues/1246 url