GO · JULY 2026 · EARLY WARNING

Capsule Package Vulnerability: Regex Panic on Node Admission Requests

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-68CJ-MVG9-RGM2Severity: HIGH

An early warning has been issued regarding a potential vulnerability in the Capsule package that allows a malformed regex to be stored, leading to a panic and cluster-wide denial of service on Node admission requests.

What happened

The Capsule package, specifically versions from 0 to 0.13.7, appears to have a vulnerability where the CapsuleConfiguration NodeMetadata regex fields lack webhook validation. This reportedly allows a malformed regex to be stored in etcd, which can cause a panic and result in a cluster-wide denial of service when Node admission requests are processed.

To assess your exposure, review and validate the regex fields in your CapsuleConfiguration before storage to prevent potential panics. This issue is under investigation, and further details should be obtained from the primary sources for accurate information.

For more information, consult the GitHub advisory [GHSA-68cj-mvg9-rgm2](https://github.com/projectcapsule/capsule/security/advisories/GHSA-68cj-mvg9-rgm2). It is recommended to stay updated with the latest developments and apply any necessary mitigations as advised by the Capsule project team.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If capsule is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats