Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.2%top 90%

CVE-2026-30963: CWE-20: Improper Input Validation in projectcapsule capsule

0
Low
VulnerabilityCVE-2026-30963cvecve-2026-30963cwe-20
Published: 06/01/2026 (06/01/2026, 18:00:43 UTC)
Source: CVE Database V5
Vendor/Project: projectcapsule
Product: capsule

Description

Capsule is a multi-tenancy and policy-based framework for Kubernetes. To defend against namespace hijacking achieved through update/patch operations on namespaces, Capsule uses a webhook to validate update requests targeting namespaces. However, in Kubernetes, the namespace/finalize and namespace/status subresource APIs can also modify various fields of a namespace, including the metadata field. Prior to version 0.13.0, the webhook does not define interception rules for these subresources. As a result, if a tenant administrator has permission to modify namespace/status or namespace/finalize, they can successfully perform namespace hijacking. Version 0.13.0 fixes the issue. Another mitigation is to add two subresources (namespaces and snamespaces/status with namespace/finalize within it) to the resources list in the ValidatingWebhookConfiguration rules.

CVSS v3.1

Score 3.9low

Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L

Affected software

GitHub Actionsmore threats →ai
projectcapsule/capsule
pkg:github/projectcapsule/capsule
Affected versions
<0.13.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 06/08/2026, 20:48:13 UTC

Technical Analysis

Capsule is a multi-tenancy and policy-based framework for Kubernetes that protects namespaces from hijacking by validating update requests via a webhook. Before version 0.13.0, the webhook did not cover the namespace/finalize and namespace/status subresource APIs, which can modify namespace metadata fields. This omission allows tenant administrators with permissions to these subresources to bypass protections and hijack namespaces. The issue is fixed in version 0.13.0 by adding these subresources to the ValidatingWebhookConfiguration rules, preventing unauthorized modifications through these APIs.

Potential Impact

An attacker with tenant administrator privileges who can modify the namespace/status or namespace/finalize subresources can hijack namespaces by altering metadata fields. This could lead to unauthorized control or manipulation of Kubernetes namespaces within the Capsule framework. The impact is limited to tenants with those specific permissions and is rated low severity (CVSS 3.9) due to the required privileges and complexity.

Mitigation Recommendations

Upgrade Capsule to version 0.13.0 or later, which includes the fix by adding interception rules for the namespace/finalize and namespace/status subresources in the webhook configuration. Alternatively, manually add these subresources (namespaces and namespaces/status with namespace/finalize) to the ValidatingWebhookConfiguration rules to ensure they are validated. No other vendor advisory or patch information is provided, so check the vendor advisory for any updates.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-03-07T17:53:48.814Z
Cvss Version
3.1
State
PUBLISHED
Remediation Level
null

Threat ID: 6a1de301e29bf47b503a4ebf

Added to database: 06/01/2026, 19:52:33 UTC

Last enriched: 06/08/2026, 20:48:13 UTC

Last updated: 07/31/2026, 19:22:58 UTC

Views: 79

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses