Angaben zum Datum
Datum aus der Quelle.
Erstmals gesehen am .
kyverno 1.19.1 – Sicherheitsfixes und Blocklist-Verbesserungen
kyverno v1.19.1 behebt mehrere Sicherheitslücken durch Updates auf Go 1.26.6 und x/net (u. a. CVE-2026-39821, CVE-2026-56853), wendet die HTTP-Blocklist auf den apiCall.service-Executor an, schließt eine IPv6-eingebettete-IPv4-Umgehung der Blocklist, behebt eine Umgehung des PolicyException-Geltungsbereichs bei IVPol, ergänzt die fehlende Autogen-Webhook-Erweiterung für NamespacedValidatingPolicy und beseitigt eine Data Race im Image-Evaluator-Prefetch.
What's Changed
- fix: bump Go 1.26.6 and x/net to resolve CVE-2026-39821 by @Manoj-Kumar-Selvaraj in https://github.com/kyverno/kyverno/pull/17230
- fix: update Go to address CVE-2026-56853 by @Sashang-debug in https://github.com/kyverno/kyverno/pull/17232
- Fix missing autogen webhook expansion for NamespacedValidatingPolicy (Cherry-pick #17262) by @kyverno-pr-updater[bot] in https://github.com/kyverno/kyverno/pull/17273
- fix: apply HTTP blocklist to apiCall.service executor (cherry-pick #17234) by @realshuting in https://github.com/kyverno/kyverno/pull/17298
- fix: harden apiCall.service egress proxy path and cover CABundle branch (Cherry-pick #17299) by @kyverno-pr-updater[bot] in https://github.com/kyverno/kyverno/pull/17302
- fix: avoid data race in image evaluator prefetch (Cherry-pick #17313) by @kyverno-pr-updater[bot] in https://github.com/kyverno/kyverno/pull/17327
- cherry-pick: fix IVPol PolicyException scope bypass (GHSA-5cjf-wwfg-pj4c) by @realshuting in https://github.com/kyverno/kyverno/pull/17307
- fix: close IPv6-embedded-IPv4 blocklist bypass in apiCall.service egress (Cherry-pick #17310) by @kyverno-pr-updater[bot] in https://github.com/kyverno/kyverno/pull/17329
- fix(test): disable mutateDigest in exceptions-disabled IVPol by @IceCodeBear in https://github.com/kyverno/kyverno/pull/17336
- fix(test): loosen chainsaw stderr checks to contains by @IceCodeBear in https://github.com/kyverno/kyverno/pull/17334 …