kyverno-fips-1.15

Direct Vulnerabilities

Known vulnerabilities in the kyverno-fips-1.15 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Use of a Key Past its Expiration Date

*
  • L
GHSA-259r-337f-4rfw

*
  • L
GHSA-gcjh-h69q-9w9g

*
  • L
CVE-2026-56852

*
  • L
CVE-2026-46600

*
  • L
GHSA-hrxh-6v49-42gf

*
  • L
Improper Certificate Validation

*
  • M
Improper Check for Unusual or Exceptional Conditions

*
  • L
Server-Side Request Forgery (SSRF)

*
  • L
GHSA-vrw8-fxc6-2r93

*
  • L
External Control of File Name or Path

*
  • L
CVE-2026-2303

*
  • L
GHSA-vh4v-2xq2-g5cg

*
  • H
Improper Verification of Cryptographic Signature

*
  • L
GHSA-459x-q9hg-4gpq

*
  • L
Cleartext Transmission of Sensitive Information

*
  • L
GHSA-xmrv-pmrh-hhx2

*
  • L
GO-2026-5932

*
  • L
Uncontrolled Memory Allocation

*
  • L
Directory Traversal

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • L
CVE-2026-42505

<1.15.3-r11
  • L
CVE-2026-39822

<1.15.3-r11
  • L
GHSA-9g5q-2w5x-hmxf

*
  • L
CVE-2026-49478

*
  • L
CVE-2026-48702

*
  • L
GHSA-rjr7-jggh-pgcp

*
  • L
GHSA-qr4g-8hrp-c4rw

*
  • L
Deserialization of Untrusted Data

<1.15.3-r10
  • L
Improper Verification of Cryptographic Signature

<1.15.3-r10
  • L
Missing Authorization

<1.15.3-r10
  • L
Improper Certificate Validation

<1.15.3-r10
  • L
CVE-2026-39824

<1.15.3-r10
  • L
Improper Restriction of Rendered UI Layers or Frames

<1.15.3-r10
  • L
Integer Overflow or Wraparound

<1.15.3-r10
  • L
CVE-2026-39821

<1.15.3-r10
  • L
Improper Enforcement of Message Integrity During Transmission in a Communication Channel

<1.15.3-r10
  • L
Improper Restriction of Rendered UI Layers or Frames

<1.15.3-r10
  • L
CVE-2026-46595

<1.15.3-r10
  • L
Improper Certificate Validation

<1.15.3-r10
  • L
Missing Authorization

<1.15.3-r10
  • L
Resource Exhaustion

<1.15.3-r10
  • L
Cross-site Scripting (XSS)

<1.15.3-r10
  • L
Improper Restriction of Rendered UI Layers or Frames

<1.15.3-r10
  • L
Improper Certificate Validation

<1.15.3-r10
  • L
Out-of-Bounds

<1.15.3-r10
  • L
Incorrect Type Conversion or Cast

<1.15.3-r10
  • L
CVE-2026-46598

<1.15.3-r10
  • L
CVE-2026-42504

<1.15.3-r9
  • L
CVE-2026-42507

<1.15.3-r9
  • L
CVE-2026-27145

<1.15.3-r9
  • L
GHSA-pmwq-pjrm-6p5r

*
  • L
Cross-site Scripting (XSS)

<1.15.3-r8
  • M
Out-of-bounds Write

<1.15.3-r8
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1.15.3-r8
  • H
Allocation of Resources Without Limits or Throttling

<1.15.3-r8
  • L
CVE-2026-39825

<1.15.3-r8
  • H
NULL Pointer Dereference

<1.15.3-r8
  • H
Double Free

<1.15.3-r8
  • L
CVE-2026-42501

<1.15.3-r8
  • L
Improper Encoding or Escaping of Output

<1.15.3-r8
  • M
Link Following

<1.15.3-r8
  • L
CVE-2026-42499

<1.15.3-r8
  • L
Improper Authorization

*
  • L
Uncaught Exception

*
  • L
GHSA-8wfp-579w-6r25

*
  • L
GHSA-fmqp-4wfc-w3v7

*
  • L
Insecure Storage of Sensitive Information

*
  • L
Incorrect Authorization

*
  • C
Information Exposure

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • L
Reachable Assertion

*
  • H
Integer Overflow or Wraparound

*
  • C
CVE-2026-27143

<1.15.3-r7
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<1.15.3-r7
  • H
Incorrect Authorization

<1.15.3-r7
  • H
Allocation of Resources Without Limits or Throttling

<1.15.3-r7
  • H
Improper Certificate Validation

<1.15.3-r7
  • M
Allocation of Resources Without Limits or Throttling

<1.15.3-r7
  • H
Improper Certificate Validation

<1.15.3-r7
  • M
Cross-site Scripting (XSS)

<1.15.3-r7
  • M
Link Following

<1.15.3-r7
  • L
CVE-2026-32280

<1.15.3-r7
  • C
CVE-2026-1229

*
  • L
Untrusted Search Path

*
  • H
CVE-2025-15558

*
  • L
Improper Certificate Validation

<1.15.3-r6
  • L
Directory Traversal

<1.15.3-r6
  • L
Cross-site Scripting (XSS)

<1.15.3-r6
  • L
Improper Certificate Validation

<1.15.3-r6
  • L
Direct Request ('Forced Browsing')

<1.15.3-r6
  • L
Improper Initialization

*
  • M
Directory Traversal

*
  • L
Directory Traversal

*
  • L
NULL Pointer Dereference

*
  • L
Server-Side Request Forgery (SSRF)

*
  • C
CVE-2025-68121

<1.15.3-r3
  • L
CVE-2025-61732

<1.15.3-r3
  • H
Reachable Assertion

*
  • H
Improper Verification of Cryptographic Signature

*
  • L
Allocation of Resources Without Limits or Throttling

<1.15.2-r2
  • L
Allocation of Resources Without Limits or Throttling

<1.15.2-r2
  • L
Out-of-bounds Write

<1.15.2-r2
  • L
CVE-2025-61731

<1.15.2-r2
  • L
CVE-2025-61730

<1.15.2-r2
  • L
Improper Privilege Management

<1.15.3-r0
  • M
Allocation of Resources Without Limits or Throttling

<1.15.3-r0
  • L
Asymmetric Resource Consumption (Amplification)

*
  • M
Server-Side Request Forgery (SSRF)

*
  • L
Asymmetric Resource Consumption (Amplification)

*
  • M
Insufficient Verification of Data Authenticity

*