THREAT OPS › Threat News › [GHSA] GHSA-gjw4-3v3v-rqxg (high) — Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement
[GHSA] GHSA-gjw4-3v3v-rqxg (high) — Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement
GHSA-gjw4-3v3v-rqxg Severity: high CVE: CVE-2026-61672
Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement
## Summary
Capsule lets a cluster administrator forbid specific metadata keys that tenant owners must not place on their own resources: `Tenant.spec.namespaceOptions.forbiddenLabels` / `forbiddenAnnotations` (namespaces), `Tenant.spec.
Indicators of compromise
- 34262c5536604762090144b6f8aed3ef2780c18csha1
- CVE-2026-61672cve
- kubernetes.iodomain
- pod-security.kubernetes.iodomain
- app.kubernetes.iodomain
Original source: https://github.com/advisories/GHSA-gjw4-3v3v-rqxg