PatchSiren

projectcapsule CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM projectcapsule CVE published 2026-07-30

CVE-2026-65835

The Capsule framework for Kubernetes, versions 0.13.0-0.13.8, contains a vulnerability that allows Tenant Owners to create cluster-scoped resources such as ClusterRole or ValidatingWebhookConfiguration. This is due to an incomplete fix for CVE-2026-22872 in internal/controllers/resources/collect.go. The issue is addressed in version 0.13.8. Kubernetes administrators and users of the Capsule framework, esp [truncated]

MEDIUM projectcapsule CVE published 2026-07-30

CVE-2026-65834

The Capsule framework for Kubernetes, versions prior to 0.13.8, had a vulnerability where CapsuleConfiguration.Spec.NodeMetadata.ForbiddenLabels.Regex and CapsuleConfiguration.Spec.NodeMetadata.ForbiddenAnnotations.Regex were not validated by the configuration admission webhook. This allowed a Cluster Admin to store a malformed regex that could crash the node admission webhook on Node create, update, or p [truncated]