Capsule Package Vulnerability: Regex Panic on Node Admission Requests
An early warning has been issued regarding a potential vulnerability in the Capsule package that allows a malformed regex to be stored, leading to a panic and cluster-wide denial of service on Node admission requests.
What happened
The Capsule package, specifically versions from 0 to 0.13.7, appears to have a vulnerability where the CapsuleConfiguration NodeMetadata regex fields lack webhook validation. This reportedly allows a malformed regex to be stored in etcd, which can cause a panic and result in a cluster-wide denial of service when Node admission requests are processed.
To assess your exposure, review and validate the regex fields in your CapsuleConfiguration before storage to prevent potential panics. This issue is under investigation, and further details should be obtained from the primary sources for accurate information.
For more information, consult the GitHub advisory [GHSA-68cj-mvg9-rgm2](https://github.com/projectcapsule/capsule/security/advisories/GHSA-68cj-mvg9-rgm2). It is recommended to stay updated with the latest developments and apply any necessary mitigations as advised by the Capsule project team.
How 0Day mitigates this
capsule is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.