Multiple security vulnerabilities have been identified in github., affecting version 0.13.8 and potentially impacting system integrity and confidentiality. The overall risk is moderate to high due to the potential for privilege escalation and data exposure.
CVE-2026-65834 (CVSS 7.5 — High): A vulnerability in CapsuleConfiguration NodeMetadata regex fields allows an attacker to trigger a MustCompile panic on all Node admission requests, potentially leading to denial of service or data corruption.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in github., affecting version 0.13.8 and potentially impacting system integrity and confidentiality. The overall risk is moderate to high due to the potential for privilege escalation and data exposure.
CVE-2026-65834 (CVSS 7.5 — High): A vulnerability in CapsuleConfiguration NodeMetadata regex fields allows an attacker to trigger a MustCompile panic on all Node admission requests, potentially leading to denial of service or data corruption.[emaillocker id="1283"]
CVE-2026-65835: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation), enabling an attacker to escalate privileges and access sensitive data. These vulnerabilities collectively present a significant risk to administrators who have not applied the latest patches. Administrators should review their exposure and apply updates as soon as possible.
CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) |. These vulnerabilities collectively present a significant risk to administrators who have not applied the latest patches.
These vulnerabilities collectively present a significant risk to administrators who have not applied the latest patches.
We recommend you to update github.com/projectcapsule/capsule to version 0.13.8.
The following reports contain further technical details:
[/emaillocker]