Description
Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints. These 64-bit block ciphers are vulnerable to the Sweet32 attack (CVE-2016-2183), which, over very long-lived TLS connections carrying large volumes of traffic, could allow an attacker to recover small amounts of plaintext. The issue is fixed in Kyverno 1.9.5 and 1.10.0.
Published: 2026-09-01
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Kyverno versions earlier than 1.9.5 enable the 3DES cipher suites TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA, which have 64‑bit block sizes. These ciphers make the service vulnerable to the Sweet32 attack, allowing a passive eavesdropper to recover small amounts of plaintext from long‑lived TLS connections that carry large volumes of traffic. The consequence is a confidentiality breach that can expose sensitive application data when the attack conditions are met.

Affected Systems

The vulnerability affects Kyverno deployments running version 1.9.4 and earlier. The issue is resolved in Kyverno 1.9.5 and later releases such as 1.10.0.

Risk and Exploitability

The CVSS score of 9.3 classifies this weakness as high severity. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog, indicating no publicly known exploits at this time. The likely attack vector is a remote TLS session intercepted by an attacker, which would need to exercise long‑duration traffic to collect enough ciphertext blocks for decryption. While the theoretical risk is high, the practical exploitation requires specific conditions, placing it in a moderate exploitation likelihood category.

Generated by OpenCVE AI on September 1, 2026 at 12:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Kyverno to version 1.9.5 or later.
  • Configure the TLS settings in Kyverno to exclude 3DES cipher suites.
  • If an upgrade is not yet possible, block 3DES cipher suites at the network level or limit the duration of high‑volume TLS sessions to mitigate sweet32 exposure.

Generated by OpenCVE AI on September 1, 2026 at 12:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints. These 64-bit block ciphers are vulnerable to the Sweet32 attack (CVE-2016-2183), which, over very long-lived TLS connections carrying large volumes of traffic, could allow an attacker to recover small amounts of plaintext. The issue is fixed in Kyverno 1.9.5 and 1.10.0.
Title Kyverno before 1.9.5 Sweet32 Medium Strength Cipher Suites
First Time appeared Kyverno
Kyverno kyverno
Weaknesses CWE-326
CPEs cpe:2.3:a:kyverno:kyverno:*:*:*:*:*:*:*:*
Vendors & Products Kyverno
Kyverno kyverno
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-01T11:33:51.281Z

Reserved: 2026-01-10T01:51:52.987Z

Link: CVE-2023-54356

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T12:17:11.220

Modified: 2026-09-01T12:17:11.220

Link: CVE-2023-54356

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:15:01Z

Weaknesses
  • CWE-326

    Inadequate Encryption Strength