THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-gjw4-3v3v-rqxg (high) — Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement

[GHSA] GHSA-gjw4-3v3v-rqxg (high) — Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement

highgithub_advisoriesPublished 2026-09-18

GHSA-gjw4-3v3v-rqxg Severity: high CVE: CVE-2026-61672

Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement

## Summary

Capsule lets a cluster administrator forbid specific metadata keys that tenant owners must not place on their own resources: `Tenant.spec.namespaceOptions.forbiddenLabels` / `forbiddenAnnotations` (namespaces), `Tenant.spec.

Indicators of compromise

Original source: https://github.com/advisories/GHSA-gjw4-3v3v-rqxg