THREAT OPS › Threat News › [GHSA] GHSA-68cj-mvg9-rgm2 (medium) — Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
[GHSA] GHSA-68cj-mvg9-rgm2 (medium) — Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
GHSA-68cj-mvg9-rgm2 Severity: medium CVE: CVE-2026-65834
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
### Summary
`CapsuleConfiguration.Spec.NodeMetadata.ForbiddenLabels.Regex` and `ForbiddenAnnotations.Regex` are never validated by any admission webhook. A Cluster Admin can persist a malformed regex t
Indicators of compromise
- CVE-2026-65834cve
- kubernetes.iodomain
- sigs.k8s.iodomain
Original source: https://github.com/advisories/GHSA-68cj-mvg9-rgm2