18 Total advisories
18 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/projectcapsule/capsule is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 6.8
CVE-2026-61795
Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation
HIGH 7.1
CVE-2026-61672
Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement
MEDIUM 4.9
CVE-2026-61794
Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic
MEDIUM 4.3
CVE-2023-46254
capsule-proxy service discloses Namespaces of colliding tenants to owners of different tenants with the same ServiceAccount name
MEDIUM 6.6
CVE-2026-65835
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)
MEDIUM 6.8
CVE-2026-65834
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
UNKNOWN
CVE-2026-65835
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) in github.com/projectcapsule/capsule
UNKNOWN
CVE-2026-65834
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests in github.com/projectcapsule/capsule
UNKNOWN
CVE-2026-22872
Capsule TenantResource RawItems Cluster-Scoped Resource Creation Vulnerability
MEDIUM 5.7
CVE-2026-55636
Capsule: Incomplete fix of CVE-2026-30963: singular/plural typo leaves namespaces/finalize unprotected
UNKNOWN
CVE-2026-22872
Capsule TenantResource RawItems Cluster-Scoped Resource Creation Vulnerability in github.com/projectcapsule/capsule
UNKNOWN
CVE-2026-55636
Capsule: Incomplete fix of CVE-2026-30963: singular/plural typo leaves namespaces/finalize unprotected in github.com/projectcapsule/capsule
LOW 3.9
CVE-2026-30963
Capsule Namespace Hijacking via subresource
UNKNOWN
CVE-2026-30963
Capsule Namespace Hijacking via subresource in github.com/projectcapsule/capsule
UNKNOWN
CVE-2025-55205
Capsule tenant owners with "patch namespace" permission can hijack system namespaces label in github.com/projectcapsule/capsule
UNKNOWN
CVE-2024-39690
Capsule tenant owner with "patch namespace" permission can hijack system namespaces in github.com/projectcapsule/capsule
CRITICAL 9.0
CVE-2025-55205
Capsule tenant owners with "patch namespace" permission can hijack system namespaces label
HIGH 8.4
CVE-2024-39690
Capsule tenant owner with "patch namespace" permission can hijack system namespaces
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes