CVE-2023-54356CWE-326

CVE-2023-54356

Low · published September 1, 2026

CVSS v3.1
3.7
EPSS
0%
Percentile
4.3
In the wild
Unconfirmed
What it is

Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints. These 64-bit block ciphers are vulnerable to the Sweet32 attack (CVE-2016-2183), which, over very long-lived TLS connections carrying large volumes of traffic, could allow an attacker to recover small amounts of plaintext. The issue is fixed in Kyverno 1.9.5 and 1.10.0.

The record
Technical detail
CVSS v3.1
3.7 · LOW
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0
9.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00147 · 4.3th percentile
Weakness
CWE-326 · Inadequate Encryption Strength
Published
2026-09-01T16:17Z
References (2)
EPSS history
Timeline
  • 03 SEP 03:20Z
    EPSS moved — → 0%
    epss
  • 01 SEP 11:33Z
    Kyverno before 1.9.5 Sweet32 Medium Strength Cipher Suites
    cvelistv5