GPU VulnDB

Database/Container, Kubernetes & orchestration

Kyverno: percent-encoded dot-segments in apiCall urlPath bypass namespace scoping in namespaced Policies

CVSS 8.3CVE-2026-100707Container, Kubernetes & orchestrationcurated

Impact

Validation and execution interpret the apiCall urlPath differently: the check that a namespaced Policy only reads its own namespace is done on the raw path, while the request is issued after percent-decoding, so encoded ../ segments escape the namespace prefix. A tenant who can create a Policy in their own namespace then reads arbitrary API objects in other namespaces using the Kyverno admission controller's ServiceAccount, which in a normal install has broad read across the cluster. In a multi-tenant GPU cluster that is a direct tenant-isolation break: Secrets, ConfigMaps and workload specs belonging to other customers become readable through a namespaced object the tenant is legitimately allowed to create. This is a distinct defect from the SSRF in the same release; both are fixed in 1.19.1.

Who can reach it

Low-privileged tenant with permission to create or edit namespaced Policy resources in a namespace they already control. Authentication to the Kubernetes API is required.

What to do

Upgrade Kyverno to 1.19.1 and roll the admission controller deployment - a rolling pod restart, no node drain. Until patched, deny tenants the ability to create namespaced Policy objects, or review existing Policies for apiCall entries containing encoded path separators.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.