CVE-2025-46342 is a high-severity vulnerability affecting Kyverno, a policy engine for cloud-native platforms, specifically versions prior to 1.13.5 and 1.14.0. It allows for the bypass of security-critical mutations and validations when policy rules using namespace selectors are not properly applied during admission review, potentially enabling malicious operations by attackers with Kubernetes API access. With a CVSS score of 8.2, this vulnerability has a network attack vector and high impact on integrity and availability, though it requires high attack complexity and low privileges. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), it is not listed in the KEV catalog, and its EPSS score is very low, indicating a low probability of exploitation. However, it has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.11.5CPE matchmatch criteria | cpe:2.3:a:kyverno:kyverno:*:*:*:*:*:*:*:* | ||
>= 1.12.0, < 1.13.5CPE matchmatch criteria | cpe:2.3:a:kyverno:kyverno:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.