go

github.com/projectcapsule/capsule

View on go registry
18 Total advisories
18 Vulnerabilities
0 Malware

Dependency scanning

Check whether github.com/projectcapsule/capsule is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 6.8
Go

CVE-2026-61795

Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation

HIGH 7.1
Go

CVE-2026-61672

Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement

MEDIUM 4.9
Go

CVE-2026-61794

Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic

MEDIUM 4.3
Go

CVE-2023-46254

capsule-proxy service discloses Namespaces of colliding tenants to owners of different tenants with the same ServiceAccount name

MEDIUM 6.6
Go

CVE-2026-65835

Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)

MEDIUM 6.8
Go

CVE-2026-65834

Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests

UNKNOWN
Go

CVE-2026-65835

Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) in github.com/projectcapsule/capsule

UNKNOWN
Go

CVE-2026-65834

Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests in github.com/projectcapsule/capsule

UNKNOWN
Go

CVE-2026-22872

Capsule TenantResource RawItems Cluster-Scoped Resource Creation Vulnerability

MEDIUM 5.7
Go

CVE-2026-55636

Capsule: Incomplete fix of CVE-2026-30963: singular/plural typo leaves namespaces/finalize unprotected

UNKNOWN
Go

CVE-2026-22872

Capsule TenantResource RawItems Cluster-Scoped Resource Creation Vulnerability in github.com/projectcapsule/capsule

UNKNOWN
Go

CVE-2026-55636

Capsule: Incomplete fix of CVE-2026-30963: singular/plural typo leaves namespaces/finalize unprotected in github.com/projectcapsule/capsule

LOW 3.9
Go

CVE-2026-30963

Capsule Namespace Hijacking via subresource

UNKNOWN
Go

CVE-2026-30963

Capsule Namespace Hijacking via subresource in github.com/projectcapsule/capsule

UNKNOWN
Go

CVE-2025-55205

Capsule tenant owners with "patch namespace" permission can hijack system namespaces label in github.com/projectcapsule/capsule

UNKNOWN
Go

CVE-2024-39690

Capsule tenant owner with "patch namespace" permission can hijack system namespaces in github.com/projectcapsule/capsule

CRITICAL 9.0
Go

CVE-2025-55205

Capsule tenant owners with "patch namespace" permission can hijack system namespaces label

HIGH 8.4
Go

CVE-2024-39690

Capsule tenant owner with "patch namespace" permission can hijack system namespaces

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes