{"id":"GO-2026-5374","summary":"Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno","details":"Kyverno Controller Denial of Service via forEach Mutation Panic in github.com/kyverno/kyverno","aliases":["BIT-kyverno-2026-41485","CVE-2026-41485","GHSA-fpjq-c37h-cqcv"],"modified":"2026-06-29T18:29:26.804376605Z","published":"2026-06-25T18:43:19Z","related":["CGA-4q7q-7q3j-38wq"],"database_specific":{"url":"https://pkg.go.dev/vuln/GO-2026-5374","review_status":"UNREVIEWED"},"references":[{"type":"ADVISORY","url":"https://github.com/kyverno/kyverno/security/advisories/GHSA-fpjq-c37h-cqcv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41485"},{"type":"FIX","url":"https://github.com/kyverno/kyverno/commit/76c8fdbe87328722e099e1fd44c3f21c9f7809cb"},{"type":"FIX","url":"https://github.com/kyverno/kyverno/commit/80e728c2283a0c65e5adb02d8a907106e6ebe7e3"}],"affected":[{"package":{"name":"github.com/kyverno/kyverno","ecosystem":"Go","purl":"pkg:golang/github.com/kyverno/kyverno"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.13.0"},{"fixed":"1.16.4"},{"introduced":"1.17.0-rc.1"},{"fixed":"1.17.2"}]}],"ecosystem_specific":{},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2026-5374.json"}}],"schema_version":"1.7.5"}