PT-2026-95490 · Capsule · Capsule

CVE-2026-61795

·

Published

2026-09-18

·

Updated

2026-09-28

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Capsule versions 0.13.0 through 0.13.6
Description A parameter order bug in the hostnameRegexHandler.OnUpdate function within internal/webhook/tenant/validation/hostname regex.go causes the webhook to validate the old Tenant object instead of the new one being submitted. This allows a cluster administrator to persist a malformed AllowedHostnames.Regex value to the system because the validation is performed against a stale, valid state.
When subsequent Ingress resources are created or updated, the system evaluates this malformed pattern in validate hostnames.go. Because the regular-expression error is ignored, every hostname is treated as unmatched, resulting in a Denial of Service (DoS) that blocks all Ingress operations for the affected tenant until the configuration is manually repaired.
Recommendations Update Capsule to version 0.13.7. As a temporary mitigation, avoid updating the AllowedHostnames.Regex parameter in the Tenant configuration until the update is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61795
GHSA-F94Q-W3W8-CJ67
GO-2026-6519

Affected Products

Capsule