CLEANSTART-2026-XV99350
Dashboard / Vulnerabilities / CLEANSTART-2026-XV99350
CLEANSTART-2026-XV99350
Summary: malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log
Details: Multiple security vulnerabilities affect the kyverno package. A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. See references for individual vulnerability details.
References: https://github.com/cleanstart-dev/cleanstart-security-advisories/tree/main/advisories/2026/CLEANSTART-2026-XV99350.json, https://osv.dev/vulnerability/CVE-2025-47912, https://osv.dev/vulnerability/CVE-2025-58183, https://osv.dev/vulnerability/CVE-2025-58185, https://osv.dev/vulnerability/CVE-2025-58186, https://osv.dev/vulnerability/CVE-2025-58187, https://osv.dev/vulnerability/CVE-2025-58188, https://osv.dev/vulnerability/CVE-2025-58189, https://osv.dev/vulnerability/CVE-2025-61723, https://osv.dev/vulnerability/CVE-2025-61724, https://osv.dev/vulnerability/CVE-2025-61725, https://osv.dev/vulnerability/CVE-2025-61729, https://osv.dev/vulnerability/CVE-2026-24122, https://osv.dev/vulnerability/CVE-2026-32952, https://osv.dev/vulnerability/CVE-2026-39395, https://osv.dev/vulnerability/CVE-2026-39984, https://osv.dev/vulnerability/CVE-2026-48978, https://osv.dev/vulnerability/CVE-2026-49478, https://osv.dev/vulnerability/CVE-2026-49834, https://osv.dev/vulnerability/CVE-2026-50151, https://osv.dev/vulnerability/CVE-2026-50162, https://osv.dev/vulnerability/CVE-2026-50163, https://osv.dev/vulnerability/CVE-2026-54787, https://osv.dev/vulnerability/CVE-2026-56864, https://osv.dev/vulnerability/CVE-2026-56865, https://osv.dev/vulnerability/ghsa-259r-337f-4rfw, https://osv.dev/vulnerability/ghsa-gcjh-h69q-9w9g, https://osv.dev/vulnerability/ghsa-hrxh-6v49-42gf, https://osv.dev/vulnerability/ghsa-pmwq-pjrm-6p5r, https://osv.dev/vulnerability/ghsa-vh4v-2xq2-g5cg, https://nvd.nist.gov/vuln/detail/CVE-2025-47912, https://nvd.nist.gov/vuln/detail/CVE-2025-58183, https://nvd.nist.gov/vuln/detail/CVE-2025-58185, https://nvd.nist.gov/vuln/detail/CVE-2025-58186, https://nvd.nist.gov/vuln/detail/CVE-2025-58187, https://nvd.nist.gov/vuln/detail/CVE-2025-58188, https://nvd.nist.gov/vuln/detail/CVE-2025-58189, https://nvd.nist.gov/vuln/detail/CVE-2025-61723, https://nvd.nist.gov/vuln/detail/CVE-2025-61724, https://nvd.nist.gov/vuln/detail/CVE-2025-61725, https://nvd.nist.gov/vuln/detail/CVE-2025-61729, https://nvd.nist.gov/vuln/detail/CVE-2026-24122, https://nvd.nist.gov/vuln/detail/CVE-2026-32952, https://nvd.nist.gov/vuln/detail/CVE-2026-39395, https://nvd.nist.gov/vuln/detail/CVE-2026-39984, https://nvd.nist.gov/vuln/detail/CVE-2026-48978, https://nvd.nist.gov/vuln/detail/CVE-2026-49478, https://nvd.nist.gov/vuln/detail/CVE-2026-49834, https://nvd.nist.gov/vuln/detail/CVE-2026-50151, https://nvd.nist.gov/vuln/detail/CVE-2026-50162, https://nvd.nist.gov/vuln/detail/CVE-2026-50163, https://nvd.nist.gov/vuln/detail/CVE-2026-54787, https://nvd.nist.gov/vuln/detail/CVE-2026-56864, https://nvd.nist.gov/vuln/detail/CVE-2026-56865
Affected packages
Package
Name: kyverno
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
