boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-30963LOW
projectcapsule capsule — Capsule Namespace Hijacking via subresource
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   H   N  U  N  L  N    2.7   .0020   10.6     —
AFFECTED
  Product  Versions    Fixed
  capsule  < 0.13.0 –  —
TIMELINE
  Mar 7   Reserved by GitHub_M
  Jun 1   EXPLOIT PUBLISHED — CVE-2026-30963 (projectcapsule capsule). Public exploit reference added.
  Jun 1   Published (CNA: GitHub_M)
CWE-20 · CNA: GitHub_M · CVSS v3.1 · 2 references · NVD status: Analyzed

Description

Capsule is a multi-tenancy and policy-based framework for Kubernetes. To defend against namespace hijacking achieved through update/patch operations on namespaces, Capsule uses a webhook to validate update requests targeting namespaces. However, in Kubernetes, the namespace/finalize and namespace/status subresource APIs can also modify various fields of a namespace, including the metadata field. Prior to version 0.13.0, the webhook does not define interception rules for these subresources. As a result, if a tenant administrator has permission to modify namespace/status or namespace/finalize, they can successfully perform namespace hijacking. Version 0.13.0 fixes the issue. Another mitigation is to add two subresources (namespaces and snamespaces/status with namespace/finalize within it) to the resources list in the ValidatingWebhookConfiguration rules.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
March 7, 2026ReservedReserved by GitHub_M
June 1, 2026EXPLOIT PUBLISHEDEXPLOIT PUBLISHED — CVE-2026-30963 (projectcapsule capsule). Public exploit reference added.
June 1, 2026PublishedPublished (CNA: GitHub_M)

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
projectcapsulecapsule< 0.13.0

Weaknesses

CWE-20

References (2)

Related

Authoritative record: CVE-2026-30963 at cve.org

Vendors: projectcapsule

Weaknesses: CWE-20

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-30963 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.