PatchSiren

open-feature CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM open-feature CVE published 2026-09-17

CVE-2026-54495

CVE-2026-54495 debrief: OpenFeature Operator vulnerability allows tenant to access cluster-scoped resources. The OpenFeature Operator allows users to expose feature flags to applications. In version 0.9.2 and earlier, a tenant who can create a controller-owned workload can use the openfeature.dev/featureflagsource annotation with NAMESPACE/NAME syntax to reference a FeatureFlagSource or InProcessConfigura [truncated]