Security: projectcapsule/capsule
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)GHSA-jr6p-8pjj-mfx6 published
Jul 8, 2026 by oliverbaehlerModerate -
CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requestsGHSA-68cj-mvg9-rgm2 published
Jul 8, 2026 by oliverbaehlerModerate -
Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panicGHSA-gxjc-74v5-3vx3 published
Jun 24, 2026 by oliverbaehlerModerate -
hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validationGHSA-f94q-w3w8-cj67 published
Jun 24, 2026 by oliverbaehlerModerate -
Incomplete fix of CVE-2026-30963: singular/plural typo leaves namespaces/finalize unprotectedGHSA-gwxr-7h77-7777 published
Jun 17, 2026 by oliverbaehlerModerate -
Capsule Namespace Hijacking via subresourceGHSA-2ww6-hf35-mfjm published
May 28, 2026 by oliverbaehlerLow -
TenantResource RawItems Cluster-Scoped Resource Creation VulnerabilityGHSA-qjjm-7j9w-pw72 published
May 28, 2026 by oliverbaehlerHigh -
A tenant owner with "patch namespace" permission can hijack system namespaces label" (similar to CVE-2024-39690)GHSA-fcpm-6mxq-m5vv published
Aug 18, 2025 by oliverbaehlerCritical -
A tenant owner with "patch namespace" permission can hijack system namespacesGHSA-mq69-4j5w-3qwp published
Aug 20, 2024 by oliverbaehlerHigh