THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-f94q-w3w8-cj67 (medium) — Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation

[GHSA] GHSA-f94q-w3w8-cj67 (medium) — Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation

highgithub_advisoriesPublished 2026-09-18

GHSA-f94q-w3w8-cj67 Severity: medium CVE: CVE-2026-61795

Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation

### Summary

A parameter order bug in `internal/webhook/tenant/validation/hostname_regex.go` causes the `hostnameRegexHandler.OnUpdate` webhook to validate the **old** Tenant object's `AllowedHostn

Indicators of compromise

Original source: https://github.com/advisories/GHSA-f94q-w3w8-cj67