Impact
The vulnerability lies in the tenant update validation logic, which compiles the ForbiddenLabels.Regex expression for both labels and annotations instead of validating ForbiddenAnnotations.Regex. An administrator with tenant‑update rights can persist a malformed ForbiddenAnnotations.Regex. When a namespace is later created or updated, the stored expression is fed to the regular expression compiler, causing a panic that prevents namespace operations for the affected tenant, effectively denying service. This is a classic input validation flaw categorized as CWE‑20.
Affected Systems
The flaw impacts Capsule deployments from version 0.13.0 to 0.13.7 inclusive. Any installation that allows administrators to modify Tenant objects is susceptible. The issue was fixed in Capsule 0.13.7, so users on earlier 0.13.x releases must upgrade to avoid denial of service to the tenant's namespaces.
Risk and Exploitability
With a CVSS score of 6.8, the vulnerability is considered moderate severity. The EPSS score is less than 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. An attacker would need the right to update a Tenant object, a privilege typically held by a trusted administrator. Once an attacker injects a malformed ForbiddenAnnotations.Regex, any subsequent namespace creation or update triggers a panic in the admission controller, causing a denial of service for the affected tenant.
OpenCVE Enrichment
Github GHSA