—
GO-2026-4718
Chall-Manager's invalid NetworkPolicy enables a malicious actor to pivot into another namespace in github.com/ctfer-io/chall-manager/deploy
Quick fix
GO-2026-4718 — github.com/ctfer-io/chall-manager/deploy: upgrade to the fixed version with the command below.
go get github.com/ctfer-io/chall-manager/deploy@v0.6.5Details
Chall-Manager's invalid NetworkPolicy enables a malicious actor to pivot into another namespace in github.com/ctfer-io/chall-manager/deploy
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/ctfer-io/chall-manager/deploy
Introduced in:
0Fixed in: 0.6.5Fix
go get github.com/ctfer-io/chall-manager/deploy@v0.6.5Go/github.com/ctfer-io/chall-manager/sdk
Introduced in:
0Fixed in: 0.6.5Fix
go get github.com/ctfer-io/chall-manager/sdk@v0.6.5References
- https://github.com/ctfer-io/chall-manager/security/advisories/GHSA-mw24-f3xh-j3qv[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-32768[ADVISORY]
- https://github.com/ctfer-io/chall-manager/commit/dc5ef27dfed2befef7f506ab8ca14d062b0d79c5[WEB]
- https://github.com/ctfer-io/chall-manager/releases/tag/v0.6.5[WEB]