Robert Morgan

Robert Morgan is an insightful security blogger who transforms complex technical vulnerabilities into understandable content for both security professionals and business leaders.

Robert Morgan

Kubernetes

CVE-2025-29778: Kyverno Ignores subjectRegExp and IssuerRegExp Leading to Improper Authorization

Executive Summary CVE-2025-29778 is a security vulnerability affecting Kyverno, a policy engine designed for Kubernetes. This vulnerability allows attackers to bypass intended authorization controls by exploiting the fact that Kyverno versions prior to 1.14.0-alpha.1 incorrectly ignore the subjectRegExp and IssuerRegExp fields during keyless signature verification. This oversight