github.com/projectcapsule/capsule
Go11 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/projectcapsule/capsulepage 1 of 1
- CVE-2023-46254MEDIUMCVSS 4.3EG 4.3fixed in 0.4.52023-11-06
capsule-proxy is a reverse proxy for Capsule kubernetes multi-tenancy framework. A bug in the RoleBinding reflector used by `capsule-proxy` gives ServiceAccount tenant owners the right to list Namespaces of other tenants backed by the same…
- CVE-2024-39690HIGHCVSS 8.4EG 8.4fixed in 0.7.12024-08-20
Capsule is a multi-tenancy and policy-based framework for Kubernetes. In Capsule v0.7.0 and earlier, the tenant-owner can patch any arbitrary namespace that has not been taken over by a tenant (i.e., namespaces without the ownerReference f…
- CVE-2025-55205CRITICALCVSS 9.0EG 9.0fixed in 0.10.42025-08-18
Capsule is a multi-tenancy and policy-based framework for Kubernetes. A namespace label injection vulnerability in Capsule v0.10.3 and earlier allows authenticated tenant users to inject arbitrary labels into system namespaces (kube-system…
- CVE-2026-22872CRITICALCVSS 9.1EG 9.1fixed in 0.13.02026-05-28
Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin privileges. Although the TenantResource RawItems processing logic forcibly sets the namespace, this is ineffective for clu…
- CVE-2026-30963LOWCVSS 2.7EG 2.7fixed in 0.13.02026-05-28
Capsule is a multi-tenancy and policy-based framework for Kubernetes. To defend against namespace hijacking achieved through update/patch operations on namespaces, Capsule uses a webhook to validate update requests targeting namespaces. Ho…
- CVE-2026-55636MEDIUMCVSS 5.7EG 5.7fixed in 0.13.62026-06-17
Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.6, charts/capsule/templates/configuration.yaml configures the validating webhook with namespace/finalize instead of the Kubernetes resource name n…
- CVE-2026-61672HIGHCVSS 7.1EG 7.1fixed in 0.13.72026-09-18
Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, ForbiddenListSpec.ExactMatch in pkg/api/forbidden_list.go sorts denied metadata keys case-insensitively and then uses sort.SearchStrings, which assumes …
- CVE-2026-61794MEDIUMCVSS 6.8EG 6.8fixed in 0.13.72026-09-18
Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, the Tenant update validation in internal/webhook/tenant/validation/forbidden_annotations_regex.go compiles ForbiddenLabels.Regex for both the l…
- CVE-2026-61795MEDIUMCVSS 6.8EG 6.8fixed in 0.13.72026-09-18
Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, hostnameRegexHandler.OnUpdate in internal/webhook/tenant/validation/hostname_regex.go reverses the new and old Tenant parameters and validates …
- CVE-2026-65834MEDIUMCVSS 6.8EG 6.8fixed in 0.13.82026-07-30
Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.8, CapsuleConfiguration.Spec.NodeMetadata.ForbiddenLabels.Regex and CapsuleConfiguration.Spec.NodeMetadata.ForbiddenAnnotations.Regex were not validated by…
- CVE-2026-65835MEDIUMCVSS 6.6EG 6.6fixed in 0.13.82026-07-30
Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE-2026-22872 fix, TenantResource RawItems and Generators in internal/controllers/resources/collect.go, including handleR…
Check whether github.com/projectcapsule/capsule is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/projectcapsule/capsule CVEs against the assets you own.
Book a Demo →