<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 14:03:11 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-343459</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-343459</link>
      <description>EUVD-2026-343459</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-343459</guid>
    </item>
    <item>
      <title>fkie_cve-2026-65835</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-65835</link>
      <description>&lt;p&gt;Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE-2026-22872 fix, TenantResource RawItems and Generators in internal/controllers/resources/collect.go, including handleRawItem and handleGeneratorItem, did not apply the ResourceReference.LoadResources and IsNamespacedGVK cluster-scoped resource rejection guard used by NamespacedItems, allowing a Tenant Owner to create cluster-scoped resources such as ClusterRole or ValidatingWebhookConfiguration through the cluster-admin controller client. This issue is fixed in version 0.13.8.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE-2026-22872 fix, TenantResource RawItems and Generators in internal/controllers/resources/collect.go, including handleRawItem and handleGeneratorItem, did not apply the ResourceReference.LoadResources and IsNamespacedGVK cluster-scoped resource rejection guard used by NamespacedItems, allowing a Tenant Owner to create cluster-scoped resources such as ClusterRole or ValidatingWebhookConfiguration through the cluster-admin controller client. This issue is fixed in version 0.13.8.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-65835</guid>
    </item>
    <item>
      <title>GHSA-jr6p-8pjj-mfx6 — Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped reso…</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-jr6p-8pjj-mfx6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/projectcapsule/capsule&lt;/p&gt;
&lt;p&gt;### Summary
CVE-2026-22872 (GHSA-qjjm-7j9w-pw72) reported that a Tenant Owner could create cluster-scoped resources
(e.g. `ClusterRole`, `ValidatingWebhookConfiguration`) through a `TenantResource`, because the controller
applies them with its cluster-admin ServiceAccount and `SetNamespace` is ineffective for cluster-scoped
kinds. The v0.13.0 fix added a cluster-scope rejection guard, but **only on the NamespacedItems selection
path** (`ResourceReference.LoadResources` -&amp;gt; `IsNamespacedGVK`, error `&amp;#34;cluster-scoped kind ... is not
allowed&amp;#34;`). The **RawItems create path — the exact vector the original advisory named — and the Generators
path were not given this guard.** The vulnerability therefore persists in all releases **v0.13.0 through
v0.13.7** and on trunk HEAD (`8d89d6865d`).&lt;/p&gt;
&lt;p&gt;### Details
TenantResource reconcile flow:
- `internal/controllers/resources/namespaced.go` `reconcile()` obtains the apply client via `loadClient()`;
  by default (impersonation off, no `Spec.ServiceAccount`) this is the manager client whose SA is bound to
  cluster-admin (`charts/capsule/templates/rbac.yaml:488-501`, `{fullname}-manager-rolebinding` -&amp;gt;
  roleRef cluster-admin).
- `Collector.Collect()` (`collect.go`) processes `spec.RawItems` via `handleRawItem` and `spec.Generators`
  via `handleGeneratorItem`.&lt;/p&gt;
&lt;p&gt;`handleRawItem` (`collect.go:406-425`, trunk HEAD — byte-identical to v0.13.0):
```go
tmplString := tpl.FastTemplate(string(item.Raw), opts.Iterator.FastContext)
obj := &amp;amp;unstructured.Unst…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/projectcapsule/capsule&lt;/p&gt;
&lt;p&gt;### Summary
CVE-2026-22872 (GHSA-qjjm-7j9w-pw72) reported that a Tenant Owner could create cluster-scoped resources
(e.g. `ClusterRole`, `ValidatingWebhookConfiguration`) through a `TenantResource`, because the controller
applies them with its cluster-admin ServiceAccount and `SetNamespace` is ineffective for cluster-scoped
kinds. The v0.13.0 fix added a cluster-scope rejection guard, but **only on the NamespacedItems selection
path** (`ResourceReference.LoadResources` -&amp;gt; `IsNamespacedGVK`, error `&amp;#34;cluster-scoped kind ... is not
allowed&amp;#34;`). The **RawItems create path — the exact vector the original advisory named — and the Generators
path were not given this guard.** The vulnerability therefore persists in all releases **v0.13.0 through
v0.13.7** and on trunk HEAD (`8d89d6865d`).&lt;/p&gt;
&lt;p&gt;### Details
TenantResource reconcile flow:
- `internal/controllers/resources/namespaced.go` `reconcile()` obtains the apply client via `loadClient()`;
  by default (impersonation off, no `Spec.ServiceAccount`) this is the manager client whose SA is bound to
  cluster-admin (`charts/capsule/templates/rbac.yaml:488-501`, `{fullname}-manager-rolebinding` -&amp;gt;
  roleRef cluster-admin).
- `Collector.Collect()` (`collect.go`) processes `spec.RawItems` via `handleRawItem` and `spec.Generators`
  via `handleGeneratorItem`.&lt;/p&gt;
&lt;p&gt;`handleRawItem` (`collect.go:406-425`, trunk HEAD — byte-identical to v0.13.0):
```go
tmplString := tpl.FastTemplate(string(item.Raw), opts.Iterator.FastContext)
obj := &amp;amp;unstructured.Unst…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-jr6p-8pjj-mfx6</guid>
    </item>
  </channel>
</rss>
