THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-gxjc-74v5-3vx3 (medium) — Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic

[GHSA] GHSA-gxjc-74v5-3vx3 (medium) — Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic

medgithub_advisoriesPublished 2026-09-18

GHSA-gxjc-74v5-3vx3 Severity: medium CVE: CVE-2026-61794

Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic

### Summary A validation bug in `internal/webhook/tenant/validation/forbidden_annotations_regex.go` allows an invalid `ForbiddenAnnotations.Regex` value to bypass Tenant admission on update. The webhook compiles `ForbiddenLabels

Indicators of compromise

Original source: https://github.com/advisories/GHSA-gxjc-74v5-3vx3