Summary
Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests
CapsuleConfiguration.Spec.NodeMetadata.ForbiddenLabels.Regex and ForbiddenAnnotations.Regex are never validated by any admission webhook. A Cluster Admin can persist a malformed regex to etcd without being blocked. Once stored, every Node CREATE, UPDATE, or PATCH request triggers regexp.MustCompile() in pkg/api/forbidden_list.go:36, which panics and crashes the node admission webhook, causing a cluster-wide Denial of Service for all Node operations.
Root cause
internal/webhook/tenant/validation/ contains dedicated regex validators for every Tenant regex field (hostname, storageclass, ingressclass, containerregistry, etc.). internal/webhook/cfg/ contains no regex validator at all, only owners.go, serviceaccount.go, and warnings.go.
The downstream consumer internal/webhook/node/user_metadata.go calls:
// line 131
matched = forbiddenLabels.RegexMatch(label)
// line 150
matched = forbiddenAnnotations.RegexMatch(annotation)
Which routes to pkg/api/forbidden_list.go:36:
func (in ForbiddenListSpec) RegexMatch(value string) (ok bool) {
if len(in.Regex) > 0 {
ok = regexp.MustCompile(in.Regex).MatchString(value) // ← panics on invalid regex
}
return ok
}
Unlike regexp.Compile, regexp.MustCompile panics instead of returning an error. Since no webhook validates the CapsuleConfiguration regex fields before storage, a malformed value reaches MustCompile on every Node admission request.
Comparison with existing CVEs
GHSA-f94q-w3w8-cj67 and GHSA-gxjc-74v5-3vx3 affect individual Tenant fields, their validators existed but checked the wrong field. This issue is different: no validator exists at all for CapsuleConfiguration regex fields, and the blast radius is cluster-wide (all Nodes), not scoped to one tenant.
PoC
package main
import (
"fmt"
"regexp"
)
type ForbiddenListSpec struct{ Regex string }
// Exact copy of pkg/api/forbidden_list.go:34-38
func (in ForbiddenListSpec) RegexMatch(value string) bool {
if len(in.Regex) > 0 {
return regexp.MustCompile(in.Regex).MatchString(value)
}
return false
}
func main() {
// 1. cfg webhook has no validator → invalid regex stored in etcd
// (no webhook in internal/webhook/cfg/ checks regex fields)
// 2. Stored malformed regex loaded from CapsuleConfiguration
forbidden := ForbiddenListSpec{Regex: `[invalid-regex(`}
// 3. node/user_metadata.go:131 called on every Node admission request
defer func() {
if r := recover(); r != nil {
fmt.Printf("PANIC: %v\n", r)
// Output: PANIC: regexp: Compile(`[invalid-regex(`): error parsing regexp: missing closing ]
}
}()
forbidden.RegexMatch("kubernetes.io/hostname")
}
Expected output:
PANIC: regexp: Compile(`[invalid-regex(`): error parsing regexp: missing closing ]: `[invalid-regex(`
Impact
A Cluster Admin (or compromised admin account) can update CapsuleConfiguration
with a malformed NodeMetadata regex (e.g., [invalid-regex(). The update is
accepted without validation and persisted to etcd. Once stored, every subsequent
Node admission request triggers regexp.MustCompile() with the invalid pattern,
causing the Capsule node webhook to panic.
Affected operations (cluster-wide):
- Node labeling, annotations, and taints (
kubectl label/annotate/taint node) - Cluster autoscaler operations (cannot register or remove nodes)
- Cloud provider node lifecycle management (metadata sync, status updates)
- Node maintenance workflows (cordon, drain, uncordon)
Severity:
This is a cluster-wide Denial of Service affecting all Node infrastructure
operations. Unlike tenant-scoped CVEs (GHSA-f94q-w3w8-cj67, GHSA-gxjc-74v5-3vx3)
that impact only Ingress or Namespace operations within a single tenant, this
vulnerability blocks the entire cluster's ability to manage nodes.
The cluster cannot scale, perform maintenance, or process any node metadata
changes until a Cluster Admin manually corrects the CapsuleConfiguration, requiring
direct kubectl access with valid YAML.
The application does not adequately validate input before processing it, allowing unexpected values to reach sensitive code paths. Typical impact: varies by context: data corruption, logic bypass, or denial of service.
CVE-2026-65834 has a CVSS score of 6.8 (Medium). The vector is network-reachable, high privileges required, and no user interaction. A CVSS score reflects the worst-case severity of the vulnerability, not your specific exposure. Whether this affects your application depends on whether the vulnerable code is present and reachable in your environment. A fixed version is available (0.13.8); upgrading removes the vulnerable code path.
Affected versions
Security releases
Kodem intelligence
Severity tells you how bad this could be in the worst case. It does not tell you whether you are exposed. Exploitability and impact are functions of runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A vulnerable package can sit in your dependency tree and never run.
Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter. Kodem's runtime-powered SCA identifies whether this CVE is reachable in your applications.
Already deployed Kodem?
See it in your environmentNew to Kodem? Get a demo →Remediation advice
Add a node_metadata_regex.go handler to internal/webhook/cfg/ following the same pattern as forbidden_annotations_regex.go:
package cfg
import (
"context"
"regexp"
"sigs.k8s.io/controller-runtime/pkg/client"
"sigs.k8s.io/controller-runtime/pkg/webhook/admission"
capsulev1beta2 "github.com/projectcapsule/capsule/api/v1beta2"
ad "github.com/projectcapsule/capsule/pkg/runtime/admission"
"github.com/projectcapsule/capsule/pkg/runtime/events"
"github.com/projectcapsule/capsule/pkg/runtime/handlers"
)
type nodeMetadataRegexHandler struct{}
func NodeMetadataRegexHandler() handlers.TypedHandler[*capsulev1beta2.CapsuleConfiguration] {
return &nodeMetadataRegexHandler{}
}
func (h *nodeMetadataRegexHandler) OnCreate(
_ client.Client,
_ client.Reader,
cfg *capsulev1beta2.CapsuleConfiguration,
_ admission.Decoder,
_ events.EventRecorder,
) handlers.Func {
return func(_ context.Context, req admission.Request) *admission.Response {
return h.validate(cfg, req)
}
}
func (h *nodeMetadataRegexHandler) OnDelete(
client.Client,
client.Reader,
*capsulev1beta2.CapsuleConfiguration,
admission.Decoder,
events.EventRecorder,
) handlers.Func {
return func(context.Context, admission.Request) *admission.Response {
return nil
}
}
func (h *nodeMetadataRegexHandler) OnUpdate(
_ client.Client,
_ client.Reader,
cfg *capsulev1beta2.CapsuleConfiguration,
_ *capsulev1beta2.CapsuleConfiguration,
_ admission.Decoder,
_ events.EventRecorder,
) handlers.Func {
return func(_ context.Context, req admission.Request) *admission.Response {
return h.validate(cfg, req)
}
}
func (h *nodeMetadataRegexHandler) validate(cfg *capsulev1beta2.CapsuleConfiguration, req admission.Request) *admission.Response {
if cfg.Spec.NodeMetadata == nil {
return nil
}
expressions := map[string]string{
"labels": cfg.Spec.NodeMetadata.ForbiddenLabels.Regex,
"annotations": cfg.Spec.NodeMetadata.ForbiddenAnnotations.Regex,
}
for scope, expression := range expressions {
if expression == "" {
continue
}
if _, err := regexp.Compile(expression); err != nil {
return ad.Denyf(
"unable to compile regex %q for forbidden %s: %v",
expression,
scope,
err,
)
}
}
return nil
}
Step 2: Register the handler in cmd/controller/main.go:
route.ConfigValidation(
cfgvalidation.Handler(cfg,
cfgvalidation.WarningHandler(),
cfgvalidation.ServiceAccountHandler(),
cfgvalidation.OwnerHandler(),
cfgvalidation.NodeMetadataRegexHandler(), // ← ADD THIS LINE
),
),
Frequently Asked Questions
- What is CVE-2026-65834? CVE-2026-65834 is a medium-severity improper input validation vulnerability in github.com/projectcapsule/capsule (go), affecting versions <= 0.13.7. It is fixed in 0.13.8. The application does not adequately validate input before processing it, allowing unexpected values to reach sensitive code paths.
- How severe is CVE-2026-65834? CVE-2026-65834 has a CVSS score of 6.8 (Medium). This score reflects the worst-case severity of the vulnerability, not your specific exposure. Whether it represents real risk in your environment depends on whether the vulnerable code is present and reachable.
- Which versions of github.com/projectcapsule/capsule are affected by CVE-2026-65834? github.com/projectcapsule/capsule (go) versions <= 0.13.7 is affected.
- Is there a fix for CVE-2026-65834? Yes. CVE-2026-65834 is fixed in 0.13.8. Upgrade to this version or later.
- Is CVE-2026-65834 exploitable, and should I be worried? Whether CVE-2026-65834 is exploitable in your environment depends on whether the vulnerable code is present and reachable. A CVSS score is a worst-case rating; it does not account for your specific deployment, configuration, or usage patterns. Kodem, an Intelligent Application Security platform, uses runtime intelligence to show which vulnerabilities actually execute in production, so you can focus on the ones that represent real risk. Get a demo
- What actually determines whether CVE-2026-65834 is exploitable, and how bad it is? Exploitability and impact are not fixed properties of a CVE. They depend on runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A high CVSS score on a dependency that never runs is not the same as real risk. Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter.
- How do I fix CVE-2026-65834? Upgrade
github.com/projectcapsule/capsuleto 0.13.8 or later.