<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 00:12:21 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-368836</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-368836</link>
      <description>EUVD-2026-368836</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-368836</guid>
    </item>
    <item>
      <title>fkie_cve-2026-55636</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-55636</link>
      <description>&lt;p&gt;Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.6, charts/capsule/templates/configuration.yaml configures the validating webhook with namespace/finalize instead of the Kubernetes resource name namespaces/finalize. A user with namespaces/finalize RBAC can send a PUT request to /api/v1/namespaces/{namespace}/finalize, and the singular rule never matches the plural resource, so the validating webhook is not invoked and the user can change the namespace tenant label. matchPolicy: Equivalent does not compensate because it handles API group and version equivalence rather than resource-name errors. This vulnerability is fixed in 0.13.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.6, charts/capsule/templates/configuration.yaml configures the validating webhook with namespace/finalize instead of the Kubernetes resource name namespaces/finalize. A user with namespaces/finalize RBAC can send a PUT request to /api/v1/namespaces/{namespace}/finalize, and the singular rule never matches the plural resource, so the validating webhook is not invoked and the user can change the namespace tenant label. matchPolicy: Equivalent does not compensate because it handles API group and version equivalence rather than resource-name errors. This vulnerability is fixed in 0.13.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-55636</guid>
    </item>
    <item>
      <title>GHSA-gwxr-7h77-7777 — Capsule: Incomplete fix of CVE-2026-30963: singular/plural typo leaves namespaces/finalize unprotected</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gwxr-7h77-7777</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/projectcapsule/capsule&lt;/p&gt;
&lt;p&gt;### Summary
Capsule v0.13.2 webhook rules contain `namespace/finalize` (singular) instead of `namespaces/finalize` (plural). K8s requires plural. The finalize defense from CVE-2026-30963 fix is absent.&lt;/p&gt;
&lt;p&gt;### Details
PUT to `/api/v1/namespaces/&amp;lt;ns&amp;gt;/finalize` has resource=namespaces (plural). The singular rule never matches. `matchPolicy: Equivalent` does not compensate.&lt;/p&gt;
&lt;p&gt;### PoC
Confirmed on kind + Capsule v0.13.2. alice (non-admin with namespaces/finalize RBAC): `kubectl label --as=alice` = DENIED (control). `kubectl replace --raw /finalize --as=alice` = 200 OK (bypass). Tenant label changed.&lt;/p&gt;
&lt;p&gt;### Impact
Namespace tenant-label hijack. Same threat model as CVE-2026-30963. One-char fix: `namespace/finalize` -&amp;gt; `namespaces/finalize`.
The CVE-2026-30963 fix in Capsule v0.13.2 added subresource entries to the namespace validating webhook, but `charts/capsule/templates/configuration.yaml` line 105 contains a singular/plural typo: `namespace/finalize` instead of `namespaces/finalize`. Kubernetes webhook rules require the plural resource name. The finalize subresource defense is entirely absent.&lt;/p&gt;
&lt;p&gt;### Details
In Kubernetes admission webhooks, `rules.resources` matches against the plural resource name. A PUT to `/api/v1/namespaces/&amp;lt;ns&amp;gt;/finalize` has `resource=namespaces` (plural). The rule `namespace/finalize` (singular) never matches any real API request.&lt;/p&gt;
&lt;p&gt;The `matchPolicy: Equivalent` setting does NOT compensate (it handles API group/version variations, not resource name typos).&lt;/p&gt;
&lt;p&gt;###…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/projectcapsule/capsule&lt;/p&gt;
&lt;p&gt;### Summary
Capsule v0.13.2 webhook rules contain `namespace/finalize` (singular) instead of `namespaces/finalize` (plural). K8s requires plural. The finalize defense from CVE-2026-30963 fix is absent.&lt;/p&gt;
&lt;p&gt;### Details
PUT to `/api/v1/namespaces/&amp;lt;ns&amp;gt;/finalize` has resource=namespaces (plural). The singular rule never matches. `matchPolicy: Equivalent` does not compensate.&lt;/p&gt;
&lt;p&gt;### PoC
Confirmed on kind + Capsule v0.13.2. alice (non-admin with namespaces/finalize RBAC): `kubectl label --as=alice` = DENIED (control). `kubectl replace --raw /finalize --as=alice` = 200 OK (bypass). Tenant label changed.&lt;/p&gt;
&lt;p&gt;### Impact
Namespace tenant-label hijack. Same threat model as CVE-2026-30963. One-char fix: `namespace/finalize` -&amp;gt; `namespaces/finalize`.
The CVE-2026-30963 fix in Capsule v0.13.2 added subresource entries to the namespace validating webhook, but `charts/capsule/templates/configuration.yaml` line 105 contains a singular/plural typo: `namespace/finalize` instead of `namespaces/finalize`. Kubernetes webhook rules require the plural resource name. The finalize subresource defense is entirely absent.&lt;/p&gt;
&lt;p&gt;### Details
In Kubernetes admission webhooks, `rules.resources` matches against the plural resource name. A PUT to `/api/v1/namespaces/&amp;lt;ns&amp;gt;/finalize` has `resource=namespaces` (plural). The rule `namespace/finalize` (singular) never matches any real API request.&lt;/p&gt;
&lt;p&gt;The `matchPolicy: Equivalent` setting does NOT compensate (it handles API group/version variations, not resource name typos).&lt;/p&gt;
&lt;p&gt;###…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gwxr-7h77-7777</guid>
    </item>
  </channel>
</rss>
