{"schema_version":"1.7.3","id":"GO-2025-3652","published":"2025-05-05T16:14:30Z","modified":"2026-02-04T03:59:06.128478Z","aliases":["BIT-kyverno-2025-46342","CVE-2025-46342","GHSA-jrr2-x33p-6hvc"],"related":["CGA-wvg2-4p5m-223g"],"summary":"Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno","details":"Kyverno vulnerable to bypass of policy rules that use namespace selectors in match statements in github.com/kyverno/kyverno","affected":[{"package":{"name":"github.com/kyverno/kyverno","ecosystem":"Go","purl":"pkg:golang/github.com/kyverno/kyverno"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.13.5"},{"introduced":"1.14.0-alpha.1"},{"fixed":"1.14.0"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2025-3652.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/kyverno/kyverno/security/advisories/GHSA-jrr2-x33p-6hvc"},{"type":"FIX","url":"https://github.com/kyverno/kyverno/commit/3ff923b7756e1681daf73849954bd88516589194"}],"database_specific":{"review_status":"UNREVIEWED","url":"https://pkg.go.dev/vuln/GO-2025-3652"}}