CVE-2026-4789: Kyverno

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

Kyverno, versions 1.16.0 and later, are vulnerable to SSRF due to unrestricted CEL HTTP functions.

Affected products

  • Kyverno Kyverno: from 1.16.0, up to and including 1.17.1

Published 2026-03-30. Last modified 2026-06-17.