Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
projectcapsule capsule — Capsule Namespace Hijacking via subresource
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L H N U N L N 2.7 .0020 10.6 —
AFFECTED
Product Versions Fixed
capsule < 0.13.0 – —
TIMELINE
Mar 7 Reserved by GitHub_M
Jun 1 EXPLOIT PUBLISHED — CVE-2026-30963 (projectcapsule capsule). Public exploit reference added.
Jun 1 Published (CNA: GitHub_M)
Description
Capsule is a multi-tenancy and policy-based framework for Kubernetes. To defend against namespace hijacking achieved through update/patch operations on namespaces, Capsule uses a webhook to validate update requests targeting namespaces. However, in Kubernetes, the namespace/finalize and namespace/status subresource APIs can also modify various fields of a namespace, including the metadata field. Prior to version 0.13.0, the webhook does not define interception rules for these subresources. As a result, if a tenant administrator has permission to modify namespace/status or namespace/finalize, they can successfully perform namespace hijacking. Version 0.13.0 fixes the issue. Another mitigation is to add two subresources (namespaces and snamespaces/status with namespace/finalize within it) to the resources list in the ValidatingWebhookConfiguration rules.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| March 7, 2026 | Reserved | Reserved by GitHub_M |
| June 1, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-30963 (projectcapsule capsule). Public exploit reference added. |
| June 1, 2026 | Published | Published (CNA: GitHub_M) |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| projectcapsule | capsule | — | < 0.13.0 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-30963 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.