Vulnerabilities
Last updated 31 minutes ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic | Medium Risk 4.9 | 10 days ago | 3 hours ago |
|
|
Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation | Medium Risk 6.8 | 10 days ago | 3 hours ago |
|
|
Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement | High Risk 7.1 | 10 days ago | 3 hours ago |
|
|
Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation in github.com/projectcapsule/capsule | Unknown | 3 hours ago | 3 hours ago |
|
|
Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic in github.com/projectcapsule/capsule | Unknown | 3 hours ago | 3 hours ago |
|
|
Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement in github.com/projectcapsule/capsule | Unknown | 3 hours ago | 3 hours ago |
|
|
capsule-proxy service discloses Namespaces of colliding tenants to owners of different tenants with the same ServiceAccount name | Medium Risk 4.3 | 2 years ago | 18 days ago |
|
|
capsule-proxy service discloses Namespaces of colliding tenants to owners of different tenants with the same ServiceAccount name | Medium Risk 4.3 | 2 years ago | 18 days ago |
|
|
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) | Medium Risk 6.6 | 1 month ago | 1 month ago |
|
|
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests | Medium Risk 6.8 | 1 month ago | 1 month ago |
|
|
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) in github.com/projectcapsule/capsule | Unknown | 1 month ago | 1 month ago |
|
|
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests in github.com/projectcapsule/capsule | Unknown | 1 month ago | 1 month ago |
|
|
Capsule TenantResource RawItems Cluster-Scoped Resource Creation Vulnerability | Medium Risk 6.0 | 4 months ago | 3 months ago |
|
|
Capsule: Incomplete fix of CVE-2026-30963: singular/plural typo leaves namespaces/finalize unprotected | Medium Risk 5.7 | 3 months ago | 3 months ago |
|
|
Capsule TenantResource RawItems Cluster-Scoped Resource Creation Vulnerability in github.com/projectcapsule/capsule | Unknown | 3 months ago | 3 months ago |
|
|
Capsule: Incomplete fix of CVE-2026-30963: singular/plural typo leaves namespaces/finalize unprotected in github.com/projectcapsule/capsule | Unknown | 3 months ago | 3 months ago |
|
|
Capsule Namespace Hijacking via subresource | Low Risk 3.9 | 4 months ago | 3 months ago |
|
|
Capsule Namespace Hijacking via subresource in github.com/projectcapsule/capsule | Unknown | 3 months ago | 3 months ago |
|
|
Capsule tenant owners with "patch namespace" permission can hijack system namespaces label in github.com/projectcapsule/capsule | Unknown | 1 year ago | 6 months ago |
|
|
Capsule tenant owner with "patch namespace" permission can hijack system namespaces in github.com/projectcapsule/capsule | Unknown | 2 years ago | 6 months ago |
|
|
Capsule Proxy Authentication bypass using an empty token in github.com/projectcapsule/capsule-proxy | Unknown | 2 years ago | 6 months ago |
|
|
Capsule tenant owners with "patch namespace" permission can hijack system namespaces label | Critical 9.0 | 1 year ago | 1 year ago |
|
|
Capsule tenant owner with "patch namespace" permission can hijack system namespaces | High Risk 8.4 | 2 years ago | 1 year ago |
|
|
Capsule Proxy Authentication bypass using an empty token | Critical 9.8 | 2 years ago | 2 years ago |
Page 1