Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

GHSA-gxjc-74v5-3vx3

MediumCVSS 4.9 / 10
Published Sep 18, 2026·Last modified Sep 18, 2026
Affected Components(1)
Go logogithub.com/projectcapsule/capsule
0.13.0 – 0.13.7
Description

Summary

A validation bug in internal/webhook/tenant/validation/forbidden_annotations_regex.go allows an invalid ForbiddenAnnotations.Regex value to bypass Tenant admission on update. The webhook compiles ForbiddenLabels.Regex for both labels and annotations, so a malformed annotations regex can be persisted. Once stored, namespace admission later evaluates the bad regex through pkg/api/forbidden_list.go, where regexp.MustCompile can panic and cause admission failure.

Details

In internal/webhook/tenant/validation/forbidden_annotations_regex.go, OnUpdate validates the new Tenant object, but the loop compiles tnt.Spec.NamespaceOptions.ForbiddenLabels.Regex for both labels and annotations. That means an invalid ForbiddenAnnotations.Regex is never validated if ForbiddenLabels.Regex is valid.

Relevant paths:

  • internal/webhook/tenant/validation/forbidden_annotations_regex.go
  • internal/webhook/namespace/validation/user_metadata.go
  • pkg/api/forbidden_list.go

Namespace admission later calls api.ValidateForbidden(...), and ForbiddenListSpec.RegexMatch() uses regexp.MustCompile(in.Regex). If the malformed regex is present in the Tenant spec, any namespace request that reaches this check can panic or fail hard, causing denial of service for namespace operations in the affected tenant.

PoC

  1. Update a Tenant so that:
    • spec.namespaceOptions.forbiddenLabels.regex is valid
    • spec.namespaceOptions.forbiddenAnnotations.regex is malformed, for example: [invalid-regex(
  2. The Tenant update is accepted because the webhook compiles the labels regex for both fields.
  3. Create or update a Namespace that triggers forbidden metadata validation.
  4. The namespace admission path reaches regexp.MustCompile(...) and panics.
package main

import (
	"fmt"
	"regexp"
)

type ForbiddenListSpec struct {
	Regex string
}

type NamespaceOptions struct {
	ForbiddenLabels      ForbiddenListSpec
	ForbiddenAnnotations ForbiddenListSpec
}

type Tenant struct {
	NamespaceOptions *NamespaceOptions
}

func validateTenantUpdate(tnt *Tenant) error {
	if tnt.NamespaceOptions == nil {
		return nil
	}

	annotationsToCheck := map[string]string{
		"labels":      tnt.NamespaceOptions.ForbiddenLabels.Regex,
		"annotations": tnt.NamespaceOptions.ForbiddenAnnotations.Regex,
	}

	for scope, annotation := range annotationsToCheck {
		if _, err := regexp.Compile(tnt.NamespaceOptions.ForbiddenLabels.Regex); err != nil {
			return fmt.Errorf("deny update: unable to compile %s regex for forbidden %s", annotation, scope)
		}
	}

	return nil
}

func validateForbidden(metadata map[string]string, forbidden ForbiddenListSpec) error {
	for key := range metadata {
		if forbidden.Regex != "" {
			if regexp.MustCompile(forbidden.Regex).MatchString(key) {
				return fmt.Errorf("forbidden key matched: %s", key)
			}
		}
	}

	return nil
}

func main() {
	oldTenant := &Tenant{
		NamespaceOptions: &NamespaceOptions{
			ForbiddenLabels:      ForbiddenListSpec{Regex: `^[a-z0-9-]+$`},
			ForbiddenAnnotations: ForbiddenListSpec{Regex: `^[a-z0-9-]+$`},
		},
	}

	newTenant := &Tenant{
		NamespaceOptions: &NamespaceOptions{
			ForbiddenLabels:      ForbiddenListSpec{Regex: `^[a-z0-9-]+$`},
			ForbiddenAnnotations: ForbiddenListSpec{Regex: `[invalid-regex(`},
		},
	}

	fmt.Println("=== Update step ===")
	if err := validateTenantUpdate(newTenant); err != nil {
		fmt.Printf("unexpected deny: %v\n", err)
	} else {
		fmt.Println("allowed: malformed ForbiddenAnnotations.Regex bypassed validation")
	}

	fmt.Println()
	fmt.Println("=== Namespace step ===")
	_ = oldTenant

	defer func() {
		if r := recover(); r != nil {
			fmt.Printf("panic reproduced from ValidateForbidden: %v\n", r)
		}
	}()

	_ = validateForbidden(map[string]string{"example": "value"}, ForbiddenListSpec{Regex: `[invalid-regex(`})
	fmt.Println("no panic, unexpected")
}

Expected output:

=== Update step ===
allowed: malformed ForbiddenAnnotations.Regex bypassed validation

=== Namespace step ===
panic reproduced from ValidateForbidden: regexp: Compile(`[invalid-regex(`): error parsing regexp: missing closing ]: `[invalid-regex(`

Impact

An attacker who can update the Tenant configuration can persist a malformed ForbiddenAnnotations.Regex and cause namespace admission failures for the affected tenant. This can result in a tenant-scoped denial of service.

Upload your SBOM

Upload your own SBOM in CycloneDX 1.6 or higher (JSON) directly here to check your vulnerabilities.

Risk Scores
Base Score
4.9

The vulnerability can be exploited over the network without needing physical access. It is easy for an attacker to exploit this vulnerability. An attacker needs high-level or administrative privileges. No user interaction is needed for the attacker to exploit this vulnerability. The impact is confined to the system where the vulnerability exists. There is a high impact on the availability of the system.

Threat Intelligence
4.5

Exploitation attempts have been detected. Elevated vigilance and prompt remediation are advised.

EPSS
0.59%

The exploit probability is very low. The vulnerability is unlikely to be exploited in the next 30 days.

Exploit
Not available

We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.

Browse More

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard