CVE-2026-65835
- EPSS 0.19%
- Veröffentlicht 30.07.2026 19:53:52
- Zuletzt bearbeitet 31.07.2026 20:16:53
Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE-2026-22872 fix, TenantResource RawItems and Generators in internal/controllers/resources/collect.go, including handleRawItem and ...
CVE-2026-65834
- EPSS 0.27%
- Veröffentlicht 30.07.2026 19:48:55
- Zuletzt bearbeitet 31.07.2026 12:16:53
Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.8, CapsuleConfiguration.Spec.NodeMetadata.ForbiddenLabels.Regex and CapsuleConfiguration.Spec.NodeMetadata.ForbiddenAnnotations.Regex were not validated by the config...
CVE-2026-30963
- EPSS 0.2%
- Veröffentlicht 01.06.2026 18:00:43
- Zuletzt bearbeitet 22.07.2026 07:10:00
Capsule is a multi-tenancy and policy-based framework for Kubernetes. To defend against namespace hijacking achieved through update/patch operations on namespaces, Capsule uses a webhook to validate update requests targeting namespaces. However, in K...
CVE-2026-22872
- EPSS 0.43%
- Veröffentlicht 01.06.2026 17:42:38
- Zuletzt bearbeitet 22.07.2026 07:10:00
Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin privileges. Although the TenantResource RawItems processing logic forcibly sets the namespace, this is ineffective for cluster-scoped...
- EPSS 0.45%
- Veröffentlicht 18.08.2025 16:28:51
- Zuletzt bearbeitet 15.04.2026 00:35:42
Capsule is a multi-tenancy and policy-based framework for Kubernetes. A namespace label injection vulnerability in Capsule v0.10.3 and earlier allows authenticated tenant users to inject arbitrary labels into system namespaces (kube-system, default, ...
CVE-2024-39690
- EPSS 0.54%
- Veröffentlicht 20.08.2024 15:15:21
- Zuletzt bearbeitet 14.08.2025 14:15:30
Capsule is a multi-tenancy and policy-based framework for Kubernetes. In Capsule v0.7.0 and earlier, the tenant-owner can patch any arbitrary namespace that has not been taken over by a tenant (i.e., namespaces without the ownerReference field), ther...