kyverno-fips-1.17

Direct Vulnerabilities

Known vulnerabilities in the kyverno-fips-1.17 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Use of a Key Past its Expiration Date

<1.17.2-r10
  • L
GHSA-gcjh-h69q-9w9g

<1.17.2-r9
  • L
Directory Traversal

<1.17.2-r9
  • L
CVE-2026-56852

<1.17.2-r8
  • L
GHSA-hrxh-6v49-42gf

<1.17.2-r8
  • L
CVE-2026-46600

<1.17.2-r8
  • H
Allocation of Resources Without Limits or Throttling

<1.17.2-r7
  • H
Improper Verification of Cryptographic Signature

<1.17.2-r7
  • L
Uncontrolled Memory Allocation

<1.17.2-r7
  • M
Improper Check for Unusual or Exceptional Conditions

<1.17.2-r6
  • L
GHSA-vh4v-2xq2-g5cg

<1.17.2-r6
  • L
Server-Side Request Forgery (SSRF)

<1.17.2-r6
  • L
External Control of File Name or Path

<1.17.2-r6
  • L
Cleartext Transmission of Sensitive Information

<1.17.2-r6
  • L
CVE-2026-42505

<1.17.2-r5
  • L
GHSA-9g5q-2w5x-hmxf

*
  • L
CVE-2026-39822

<1.17.2-r5
  • L
CVE-2026-49478

<1.17.2-r7
  • L
GHSA-rjr7-jggh-pgcp

*
  • L
CVE-2026-48702

<1.17.2-r7
  • L
Uncontrolled Memory Allocation

<1.17.2-r0
  • L
CVE-2026-2303

<1.17.1-r12
  • L
Improper Certificate Validation

<1.17.2-r6
  • L
Missing Authorization

<1.17.2-r4
  • L
Improper Restriction of Rendered UI Layers or Frames

<1.17.2-r4
  • L
Improper Restriction of Rendered UI Layers or Frames

<1.17.2-r4
  • L
CVE-2026-39824

<1.17.2-r4
  • L
Improper Restriction of Rendered UI Layers or Frames

<1.17.2-r4
  • L
Cross-site Scripting (XSS)

<1.17.2-r4
  • L
Improper Certificate Validation

<1.17.2-r4
  • L
Integer Overflow or Wraparound

<1.17.2-r4
  • L
Resource Exhaustion

<1.17.2-r4
  • L
Improper Enforcement of Message Integrity During Transmission in a Communication Channel

<1.17.2-r4
  • L
Incorrect Type Conversion or Cast

<1.17.2-r4
  • L
Improper Certificate Validation

<1.17.2-r4
  • L
Deserialization of Untrusted Data

<1.17.2-r4
  • L
CVE-2026-39821

<1.17.2-r4
  • L
Missing Authorization

<1.17.2-r4
  • L
Out-of-Bounds

<1.17.2-r4
  • L
Improper Verification of Cryptographic Signature

<1.17.2-r4
  • L
CVE-2026-46595

<1.17.2-r4
  • L
Improper Certificate Validation

<1.17.2-r4
  • L
CVE-2026-46598

<1.17.2-r4
  • L
CVE-2026-27145

<1.17.2-r3
  • L
CVE-2026-42507

<1.17.2-r3
  • L
CVE-2026-42504

<1.17.2-r3
  • L
GHSA-pmwq-pjrm-6p5r

<1.17.2-r6
  • L
CVE-2026-42499

<1.17.2-r2
  • L
CVE-2026-39825

<1.17.2-r2
  • H
NULL Pointer Dereference

<1.17.2-r2
  • H
Allocation of Resources Without Limits or Throttling

<1.17.2-r2
  • M
Out-of-bounds Write

<1.17.2-r2
  • L
Cross-site Scripting (XSS)

<1.17.2-r2
  • L
CVE-2026-42501

<1.17.2-r2
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1.17.2-r2
  • H
Double Free

<1.17.2-r2
  • M
Link Following

<1.17.2-r2
  • L
Improper Encoding or Escaping of Output

<1.17.2-r2
  • L
Allocation of Resources Without Limits or Throttling

<1.17.1-r11
  • L
Reachable Assertion

<1.17.2-r0
  • H
Integer Overflow or Wraparound

<1.17.2-r1
  • L
Server-Side Request Forgery (SSRF)

<1.17.2-r0
  • L
Incorrect Authorization

<1.17.2-r0
  • L
GHSA-qr4g-8hrp-c4rw

<1.17.2-r0
  • L
GHSA-3xc5-wrhm-f963

<1.17.1-r13
  • C
CVE-2026-27143

<1.17.1-r10
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<1.17.1-r10
  • L
Improper Certificate Validation

<1.17.1-r12
  • H
Improper Certificate Validation

<1.17.1-r10
  • M
Link Following

<1.17.1-r10
  • M
Cross-site Scripting (XSS)

<1.17.1-r10
  • L
CVE-2026-32280

<1.17.1-r10
  • H
Incorrect Authorization

<1.17.1-r10
  • H
Allocation of Resources Without Limits or Throttling

<1.17.1-r10
  • H
Improper Certificate Validation

<1.17.1-r10
  • M
Allocation of Resources Without Limits or Throttling

<1.17.1-r10
  • H
Untrusted Search Path

<1.17.1-r11
  • L
Uncaught Exception

<1.17.1-r9
  • L
Improper Validation of Array Index

<1.17.1-r8
  • L
Integer Underflow

<1.17.1-r8
  • L
Improper Authorization

<1.17.1-r7
  • L
Direct Request ('Forced Browsing')

<1.17.1-r6
  • L
Improper Certificate Validation

<1.17.1-r6
  • L
Cross-site Scripting (XSS)

<1.17.1-r6
  • L
Directory Traversal

<1.17.1-r6
  • L
Improper Certificate Validation

<1.17.1-r6
  • H
CVE-2025-15558

<1.17.1-r5
  • L
Untrusted Search Path

<1.17.1-r4
  • C
CVE-2026-1229

<1.17.1-r3
  • M
Improper Validation of Integrity Check Value

<1.17.0-r1