CVE-2026-61795
Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, hostnameRegexHandler.OnUpdate in internal/we
CVSS
6.8
Medium
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 18, 2026 · Last modified: Sep 18, 2026 · CWE-697
Not enough EPSS history yet.
Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, hostnameRegexHandler.OnUpdate in internal/webhook/tenant/validation/hostname_regex.go reverses the new and old Tenant parameters and validates the previous AllowedHostnames.Regex instead of the submitted value. A cluster administrator can therefore store a malformed AllowedHostnames.Regex after the webhook accepts the update based on stale valid state. Subsequent Ingress creation or update reaches validate_hostnames.go, which evaluates the malformed pattern, ignores the regular-expression error, and treats every hostname as unmatched, blocking Ingress operations for the affected tenant until an administrator repairs the Tenant configuration. This issue is fixed in version 0.13.7.
- github.comhttps://github.com/projectcapsule/capsule/commit/8d89d6865df6f41c7faa22fc9e807a57b01bfd0e
- github.comhttps://github.com/projectcapsule/capsule/pull/1983
- github.comhttps://github.com/projectcapsule/capsule/releases/tag/v0.13.7
- github.comhttps://github.com/projectcapsule/capsule/security/advisories/GHSA-f94q-w3w8-cj67