CVE-2026-30963: CWE-20: Improper Input Validation in projectcapsule capsule
Capsule is a multi-tenancy and policy-based framework for Kubernetes. To defend against namespace hijacking achieved through update/patch operations on namespaces, Capsule uses a webhook to validate update requests targeting namespaces. However, in Kubernetes, the namespace/finalize and namespace/status subresource APIs can also modify various fields of a namespace, including the metadata field. Prior to version 0.13.0, the webhook does not define interception rules for these subresources. As a result, if a tenant administrator has permission to modify namespace/status or namespace/finalize, they can successfully perform namespace hijacking. Version 0.13.0 fixes the issue. Another mitigation is to add two subresources (namespaces and snamespaces/status with namespace/finalize within it) to the resources list in the ValidatingWebhookConfiguration rules.
AI Analysis
Technical Summary
Capsule is a multi-tenancy and policy-based framework for Kubernetes that protects namespaces from hijacking by validating update requests via a webhook. Before version 0.13.0, the webhook did not cover the namespace/finalize and namespace/status subresource APIs, which can modify namespace metadata fields. This omission allows tenant administrators with permissions to these subresources to bypass protections and hijack namespaces. The issue is fixed in version 0.13.0 by adding these subresources to the ValidatingWebhookConfiguration rules, preventing unauthorized modifications through these APIs.
Potential Impact
An attacker with tenant administrator privileges who can modify the namespace/status or namespace/finalize subresources can hijack namespaces by altering metadata fields. This could lead to unauthorized control or manipulation of Kubernetes namespaces within the Capsule framework. The impact is limited to tenants with those specific permissions and is rated low severity (CVSS 3.9) due to the required privileges and complexity.
Mitigation Recommendations
Upgrade Capsule to version 0.13.0 or later, which includes the fix by adding interception rules for the namespace/finalize and namespace/status subresources in the webhook configuration. Alternatively, manually add these subresources (namespaces and namespaces/status with namespace/finalize) to the ValidatingWebhookConfiguration rules to ensure they are validated. No other vendor advisory or patch information is provided, so check the vendor advisory for any updates.
CVE-2026-30963: CWE-20: Improper Input Validation in projectcapsule capsule
Description
Capsule is a multi-tenancy and policy-based framework for Kubernetes. To defend against namespace hijacking achieved through update/patch operations on namespaces, Capsule uses a webhook to validate update requests targeting namespaces. However, in Kubernetes, the namespace/finalize and namespace/status subresource APIs can also modify various fields of a namespace, including the metadata field. Prior to version 0.13.0, the webhook does not define interception rules for these subresources. As a result, if a tenant administrator has permission to modify namespace/status or namespace/finalize, they can successfully perform namespace hijacking. Version 0.13.0 fixes the issue. Another mitigation is to add two subresources (namespaces and snamespaces/status with namespace/finalize within it) to the resources list in the ValidatingWebhookConfiguration rules.
CVSS v3.1
Score 3.9low
Affected software
pkg:github/projectcapsule/capsuleRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Capsule is a multi-tenancy and policy-based framework for Kubernetes that protects namespaces from hijacking by validating update requests via a webhook. Before version 0.13.0, the webhook did not cover the namespace/finalize and namespace/status subresource APIs, which can modify namespace metadata fields. This omission allows tenant administrators with permissions to these subresources to bypass protections and hijack namespaces. The issue is fixed in version 0.13.0 by adding these subresources to the ValidatingWebhookConfiguration rules, preventing unauthorized modifications through these APIs.
Potential Impact
An attacker with tenant administrator privileges who can modify the namespace/status or namespace/finalize subresources can hijack namespaces by altering metadata fields. This could lead to unauthorized control or manipulation of Kubernetes namespaces within the Capsule framework. The impact is limited to tenants with those specific permissions and is rated low severity (CVSS 3.9) due to the required privileges and complexity.
Mitigation Recommendations
Upgrade Capsule to version 0.13.0 or later, which includes the fix by adding interception rules for the namespace/finalize and namespace/status subresources in the webhook configuration. Alternatively, manually add these subresources (namespaces and namespaces/status with namespace/finalize) to the ValidatingWebhookConfiguration rules to ensure they are validated. No other vendor advisory or patch information is provided, so check the vendor advisory for any updates.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-03-07T17:53:48.814Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a1de301e29bf47b503a4ebf
Added to database: 06/01/2026, 19:52:33 UTC
Last enriched: 06/08/2026, 20:48:13 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 79
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.