Nirmata Enterprise for Kyverno

Hardened Kyverno. Your admission controller can't have CVEs.

Every change to your cluster passes through Kyverno.

Created KyvernoOSS-compatible, no fork24/7 enterprise supportFrom $14,800/yr
56
CVEs fixed in Nirmata Enterprise for Kyverno in 2026
10
of them rated Critical
96
fixes shipped across older releases
18 mo
of patch support for each release

Source: N4K release notes, v1.13–v1.18, Jan–Sep 2026

The backport gap

If you are not on v1.19, upstream is not patching your Kyverno

Kyverno releases a new minor version about every three months, and community patches move with it. Fleets under change control upgrade slower than that.

Upstream Kyverno Latest only

Patches go to the latest minor release only. Kyverno's own policy limits them to critical bugs and critical-to-high CVEs, for about three months. After that, your options are an unplanned upgrade or running unpatched.

Nirmata Enterprise for Kyverno Every supported release

Each release is supported for 18 months. Kyverno engine fixes and dependency CVEs are backported to every supported branch, so a version you deployed a year ago is still a patched version.

What that looks like

One advisory. Five releases patched the same day.

When the apiCall SSRF advisory landed, upstream only patched the latest release, v1.19. Every supported N4K release got the fix the same day.

Advisory · Sep 2026
SSRF in context.apiCall.service
GHSA-qr4g-8hrp-c4rw
High
You runUpstream KyvernoNirmata Enterprise
v1.18✕ No patch✓ Fixed Sep 5
v1.17✕ No patch✓ Fixed Sep 5
v1.16✕ No patch✓ Fixed Sep 5
v1.15✕ No patch✓ Fixed Sep 5
v1.14✕ No patch✓ Fixed Sep 5
One advisory, five releases patched the same day. Upstream patches only v1.19. See every CVE →
Version check

What are you missing on the version you run?

Pick your Kyverno version to see its upstream status and what Nirmata has fixed on that branch.

Not sure? kubectl get deploy -n kyverno -o jsonpath='{..image}'

How backports work

From advisory to patched image on your branch

An advisory lands

Kyverno engine CVEs, Go toolchain issues and dependency advisories, including Sigstore, grpc and x/crypto, are triaged against every supported N4K release, not just the latest.

The maintainers backport the fix

Dependency bumps are the easy part. Engine fixes, like the apiCall SSRF guard, have to be reworked for each older branch by the people who wrote the engine.

You get a patched release

Each fix ships as a new N4K build for your branch, such as v1.16.3-n4k.nirmata.16, tested against the Kubernetes versions it supports, with every CVE listed in the release notes.

Upstream Kyverno vs Nirmata Enterprise for Kyverno

Same Kyverno, same policies, no fork. The difference is who patches it, and for how long.

Upstream KyvernoNirmata Enterprise
Releases that get CVE fixesLatest minor onlyEvery supported release
Patch window per releaseAbout 3 months18 months
Kyverno engine fixes backported to older releasesNoYes, by the maintainers
Kubernetes compatibility testingCurrent Kubernetes versions onlyTested for each supported release
SupportCommunity Slack and GitHub24/7 enterprise support with SLAs for CVEs
Upgrade helpRelease notesPlanned upgrades, including the 1.20 CEL migration
Policies and APIsKyvernoSame Kyverno, OSS-compatible
“The onboarding process for Nirmata is very easy. It's very quick, well-documented, and supported by a well-trained Nirmata team. It took us less than two hours to upgrade.”
Kuldeep Tomar, Director Infosec, Games24x7
Pricing
$14,800 per year, starting

Scales with your cluster footprint. Tell us what you run and we'll put together a quote.

  • Backported CVE fixes for every supported release
  • 18 months of patch support per release, with Kubernetes compatibility testing
  • 24/7 enterprise support with SLAs for CVEs and critical fixes
  • Upgrade planning with the Kyverno maintainers, including the 1.20 CEL migration
  • Drop-in, OSS-compatible: your policies and tooling stay the same
Request a Quote

Questions teams ask before switching

Is Nirmata Enterprise for Kyverno a fork?

No. It's an OSS-compatible distribution of Kyverno. Your policies, CRDs and tooling work unchanged. The difference is the release branches we keep patching after upstream moves on.

We're on an older version. Do we have to upgrade first?

Not if your version is within its N4K support window. You can move to the patched N4K build for the version you already run, then plan upgrades on your own change-control cycle. Check your version.

What kinds of CVEs get backported?

Both Kyverno engine vulnerabilities (for example the 2026 apiCall and CEL http SSRF fixes) and CVEs in dependencies and the Go toolchain. Every fix is listed in the release notes.

How is this different from hardened or minimal container images?

Rebuilding an image clears CVEs in base packages. It can't change Kyverno's own code. Engine vulnerabilities on older branches need a code backport, and that is maintainer work.

How is it priced?

Plans start at $14,800 per year and scale with your cluster footprint. Every plan includes backports, 24/7 support and upgrade planning.

Stop choosing between an emergency upgrade and an unpatched Kyverno

Get patched builds for the version you run today, from the team that created Kyverno.