CVE Browser
Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation
Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement
Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic
Capsule: Incomplete fix of CVE-2026-30963: singular/plural typo leaves namespaces/finalize unprotected
Capsule: Incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalati…
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
Capsule Namespace Hijacking via subresource
Capsule TenantResource RawItems Cluster-Scoped Resource Creation Vulnerability
Capsule tenant owners with "patch namespace" permission can hijack system namespaces label
Capsule tenant owner with "patch namespace" permission can hijack system namespaces
Authentication bypass using an empty token in capsule-proxy
Service accounts can see namespaces of other tenants in capsule-proxy
Showing 1 to 12 CVEs · page 1