CVE-2026-61672
7.1 HIGHpublic exploit availablePublished 2026-09-18 · Updated 2026-09-24
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, ForbiddenListSpec.ExactMatch in pkg/api/forbidden_list.go sorts denied metadata keys case-insensitively and then uses sort.SearchStrings, which assumes byte-order sorting. When an administrator's forbidden list mixes capitalized and lowercase keys or otherwise has different case-insensitive and byte ordering, the binary search can return false for a key that is present. An authenticated tenant owner can then pass the missed key through api.ValidateForbidden and bypass configured namespace, Service, or delegated node metadata restrictions, potentially influencing cluster policies, network exposure, or scheduling outside the tenant boundary. Uniformly lowercase lists whose two orderings coincide are not affected. This issue is fixed in version 0.13.7.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:N
Weaknesses
CWE-697, CWE-863
Public exploit & PoC references
- https://github.com/projectcapsule/capsule/commit/755cef54bf4a1bc56d6692130132bc70755bef46
- https://github.com/projectcapsule/capsule/pull/1982
- https://github.com/projectcapsule/capsule/releases/tag/v0.13.7
- https://github.com/projectcapsule/capsule/security/advisories/GHSA-gjw4-3v3v-rqxg
- https://github.com/projectcapsule/capsule/security/advisories/GHSA-gjw4-3v3v-rqxg
All references
- https://github.com/projectcapsule/capsule/commit/755cef54bf4a1bc56d6692130132bc70755bef46
- https://github.com/projectcapsule/capsule/pull/1982
- https://github.com/projectcapsule/capsule/releases/tag/v0.13.7
- https://github.com/projectcapsule/capsule/security/advisories/GHSA-gjw4-3v3v-rqxg
- https://github.com/projectcapsule/capsule/security/advisories/GHSA-gjw4-3v3v-rqxg
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- UNSCOREDCVE-2026-100371PoC
- UNSCOREDCVE-2026-100392PoC
- MEDIUMCVE-2026-100529PoC
- HIGHCVE-2026-100530PoC
- HIGHCVE-2026-100535PoC
- MEDIUMCVE-2026-100538PoC
- LOWCVE-2026-100539PoC
- MEDIUMCVE-2026-100540PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.