—
GO-2026-6157
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) in github.com/projectcapsule/capsule
Quick fix
GO-2026-6157 — github.com/projectcapsule/capsule: upgrade to the fixed version with the command below.
go get github.com/projectcapsule/capsule@v0.13.8Details
Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) in github.com/projectcapsule/capsule
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/projectcapsule/capsule
Introduced in:
0.13.0Fixed in: 0.13.8Fix
go get github.com/projectcapsule/capsule@v0.13.8