<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T21:47:45.672989+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-343459</id>
    <title>EUVD-2026-343459</title>
    <updated>2026-10-05T21:47:45.729842+00:00</updated>
    <content>EUVD-2026-343459</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-343459"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-65835</id>
    <title>fkie_cve-2026-65835</title>
    <updated>2026-10-05T21:47:45.729886+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE-2026-22872 fix, TenantResource RawItems and Generators in internal/controllers/resources/collect.go, including handleRawItem and handleGeneratorItem, did not apply the ResourceReference.LoadResources and IsNamespacedGVK cluster-scoped resource rejection guard used by NamespacedItems, allowing a Tenant Owner to create cluster-scoped resources such as ClusterRole or ValidatingWebhookConfiguration through the cluster-admin controller client. This issue is fixed in version 0.13.8.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-65835"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-jr6p-8pjj-mfx6</id>
    <title>GHSA-jr6p-8pjj-mfx6 — Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped reso…</title>
    <updated>2026-10-05T21:47:45.729923+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/projectcapsule/capsule</p>
<p>### Summary
CVE-2026-22872 (GHSA-qjjm-7j9w-pw72) reported that a Tenant Owner could create cluster-scoped resources
(e.g. `ClusterRole`, `ValidatingWebhookConfiguration`) through a `TenantResource`, because the controller
applies them with its cluster-admin ServiceAccount and `SetNamespace` is ineffective for cluster-scoped
kinds. The v0.13.0 fix added a cluster-scope rejection guard, but **only on the NamespacedItems selection
path** (`ResourceReference.LoadResources` -&gt; `IsNamespacedGVK`, error `"cluster-scoped kind ... is not
allowed"`). The **RawItems create path — the exact vector the original advisory named — and the Generators
path were not given this guard.** The vulnerability therefore persists in all releases **v0.13.0 through
v0.13.7** and on trunk HEAD (`8d89d6865d`).</p>
<p>### Details
TenantResource reconcile flow:
- `internal/controllers/resources/namespaced.go` `reconcile()` obtains the apply client via `loadClient()`;
  by default (impersonation off, no `Spec.ServiceAccount`) this is the manager client whose SA is bound to
  cluster-admin (`charts/capsule/templates/rbac.yaml:488-501`, `{fullname}-manager-rolebinding` -&gt;
  roleRef cluster-admin).
- `Collector.Collect()` (`collect.go`) processes `spec.RawItems` via `handleRawItem` and `spec.Generators`
  via `handleGeneratorItem`.</p>
<p>`handleRawItem` (`collect.go:406-425`, trunk HEAD — byte-identical to v0.13.0):
```go
tmplString := tpl.FastTemplate(string(item.Raw), opts.Iterator.FastContext)
obj := &amp;unstructured.Unst…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-jr6p-8pjj-mfx6"/>
  </entry>
</feed>
