<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 20:21:42 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-373542</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-373542</link>
      <description>EUVD-2026-373542</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-373542</guid>
    </item>
    <item>
      <title>fkie_cve-2026-61794</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-61794</link>
      <description>&lt;p&gt;Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, the Tenant update validation in internal/webhook/tenant/validation/forbidden_annotations_regex.go compiles ForbiddenLabels.Regex for both the labels and annotations checks instead of validating ForbiddenAnnotations.Regex. An administrator who can update a Tenant can therefore persist a malformed ForbiddenAnnotations.Regex while leaving the labels expression valid. Namespace creation or update later passes the stored expression through pkg/api/forbidden_list.go, where regexp.MustCompile can panic during forbidden metadata validation and deny namespace operations for the affected tenant. This issue is fixed in version 0.13.7.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, the Tenant update validation in internal/webhook/tenant/validation/forbidden_annotations_regex.go compiles ForbiddenLabels.Regex for both the labels and annotations checks instead of validating ForbiddenAnnotations.Regex. An administrator who can update a Tenant can therefore persist a malformed ForbiddenAnnotations.Regex while leaving the labels expression valid. Namespace creation or update later passes the stored expression through pkg/api/forbidden_list.go, where regexp.MustCompile can panic during forbidden metadata validation and deny namespace operations for the affected tenant. This issue is fixed in version 0.13.7.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-61794</guid>
    </item>
    <item>
      <title>GHSA-gxjc-74v5-3vx3 — Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-gxjc-74v5-3vx3</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/projectcapsule/capsule&lt;/p&gt;
&lt;p&gt;### Summary
A validation bug in `internal/webhook/tenant/validation/forbidden_annotations_regex.go` allows an invalid `ForbiddenAnnotations.Regex` value to bypass Tenant admission on update. The webhook compiles `ForbiddenLabels.Regex` for both labels and annotations, so a malformed annotations regex can be persisted. Once stored, namespace admission later evaluates the bad regex through `pkg/api/forbidden_list.go`, where `regexp.MustCompile` can panic and cause admission failure.&lt;/p&gt;
&lt;p&gt;### Details
In `internal/webhook/tenant/validation/forbidden_annotations_regex.go`, `OnUpdate` validates the new Tenant object, but the loop compiles `tnt.Spec.NamespaceOptions.ForbiddenLabels.Regex` for both `labels` and `annotations`. That means an invalid `ForbiddenAnnotations.Regex` is never validated if `ForbiddenLabels.Regex` is valid.&lt;/p&gt;
&lt;p&gt;Relevant paths:
- `internal/webhook/tenant/validation/forbidden_annotations_regex.go`
- `internal/webhook/namespace/validation/user_metadata.go`
- `pkg/api/forbidden_list.go`&lt;/p&gt;
&lt;p&gt;Namespace admission later calls `api.ValidateForbidden(...)`, and `ForbiddenListSpec.RegexMatch()` uses `regexp.MustCompile(in.Regex)`. If the malformed regex is present in the Tenant spec, any namespace request that reaches this check can panic or fail hard, causing denial of service for namespace operations in the affected tenant.&lt;/p&gt;
&lt;p&gt;### PoC
1. Update a Tenant so that:
   - `spec.namespaceOptions.forbiddenLabels.regex` is valid
   - `spec.namespaceOptions.forbiddenAnnotations.regex` is…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/projectcapsule/capsule&lt;/p&gt;
&lt;p&gt;### Summary
A validation bug in `internal/webhook/tenant/validation/forbidden_annotations_regex.go` allows an invalid `ForbiddenAnnotations.Regex` value to bypass Tenant admission on update. The webhook compiles `ForbiddenLabels.Regex` for both labels and annotations, so a malformed annotations regex can be persisted. Once stored, namespace admission later evaluates the bad regex through `pkg/api/forbidden_list.go`, where `regexp.MustCompile` can panic and cause admission failure.&lt;/p&gt;
&lt;p&gt;### Details
In `internal/webhook/tenant/validation/forbidden_annotations_regex.go`, `OnUpdate` validates the new Tenant object, but the loop compiles `tnt.Spec.NamespaceOptions.ForbiddenLabels.Regex` for both `labels` and `annotations`. That means an invalid `ForbiddenAnnotations.Regex` is never validated if `ForbiddenLabels.Regex` is valid.&lt;/p&gt;
&lt;p&gt;Relevant paths:
- `internal/webhook/tenant/validation/forbidden_annotations_regex.go`
- `internal/webhook/namespace/validation/user_metadata.go`
- `pkg/api/forbidden_list.go`&lt;/p&gt;
&lt;p&gt;Namespace admission later calls `api.ValidateForbidden(...)`, and `ForbiddenListSpec.RegexMatch()` uses `regexp.MustCompile(in.Regex)`. If the malformed regex is present in the Tenant spec, any namespace request that reaches this check can panic or fail hard, causing denial of service for namespace operations in the affected tenant.&lt;/p&gt;
&lt;p&gt;### PoC
1. Update a Tenant so that:
   - `spec.namespaceOptions.forbiddenLabels.regex` is valid
   - `spec.namespaceOptions.forbiddenAnnotations.regex` is…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-gxjc-74v5-3vx3</guid>
    </item>
  </channel>
</rss>
