Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

capsule — Vulnerabilities & Security Advisories 11

All 11 CVE vulnerabilities found in capsule, with AI-generated Chinese analysis, references, and POCs.

Vendor: clastix

CVE ID Title CVSS Severity Published
CVE-2026-61795 Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation CWE-697 6.8 Medium 2026-09-18
CVE-2026-61672 Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement CWE-697 7.1 High 2026-09-18
CVE-2026-61794 Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic CWE-20 6.8 Medium 2026-09-18
CVE-2026-55636 Capsule: Incomplete fix of CVE-2026-30963: singular/plural typo leaves namespaces/finalize unprotected CWE-863 5.7 Medium 2026-09-15
CVE-2026-65835 Capsule: Incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) CWE-269 6.6 Medium 2026-07-30
CVE-2026-65834 Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests CWE-20 6.8 Medium 2026-07-30
CVE-2026-30963 Capsule Namespace Hijacking via subresource CWE-20 3.9 Low 2026-06-01
CVE-2026-22872 Capsule TenantResource RawItems Cluster-Scoped Resource Creation Vulnerability CWE-20 - - 2026-06-01
CVE-2025-55205 Capsule tenant owners with "patch namespace" permission can hijack system namespaces label CWE-863 9.1 Critical 2025-08-18
CVE-2024-39690 Capsule tenant owner with "patch namespace" permission can hijack system namespaces CWE-863 8.5 High 2024-08-20
CVE-2022-46167 Capsule vulnerable to privilege escalation by ServiceAccount deployed in a Tenant Namespace CWE-863 8.8 High 2022-12-02

All 11 known CVE vulnerabilities affecting capsule with full Chinese analysis, references, and POCs where available.