PT-2026-95490 · Capsule · Capsule
CVE-2026-61795
·
Published
2026-09-18
·
Updated
2026-09-28
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Capsule versions 0.13.0 through 0.13.6
Description
A parameter order bug in the
hostnameRegexHandler.OnUpdate function within internal/webhook/tenant/validation/hostname regex.go causes the webhook to validate the old Tenant object instead of the new one being submitted. This allows a cluster administrator to persist a malformed AllowedHostnames.Regex value to the system because the validation is performed against a stale, valid state.When subsequent Ingress resources are created or updated, the system evaluates this malformed pattern in
validate hostnames.go. Because the regular-expression error is ignored, every hostname is treated as unmatched, resulting in a Denial of Service (DoS) that blocks all Ingress operations for the affected tenant until the configuration is manually repaired.Recommendations
Update Capsule to version 0.13.7.
As a temporary mitigation, avoid updating the
AllowedHostnames.Regex parameter in the Tenant configuration until the update is applied.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Capsule