The Lab · 2026-03-26 05:27:08 · GitHub Issues
A critical security flaw in Tekton Pipelines' git resolver allows authenticated users to read any file from the underlying pod's filesystem, including sensitive ServiceAccount tokens. The vulnerability, tracked as CVE-2026-33211, stems from improper path validation in the `getFileContent()` function, enabling path trav...
The Lab · 2026-04-10 10:39:39 · GitHub Issues
A critical vulnerability in Kyverno's TLS 1.3 implementation can cause connections to deadlock and consume resources uncontrollably, creating a direct path to denial-of-service attacks. The flaw, tracked as CVE-2026-32283, is triggered when one side of a TLS connection sends multiple key update messages within a single...
The Lab · 2026-04-11 19:22:32 · GitHub Issues
A critical vulnerability in Kyverno's TLS 1.3 implementation can cause connections to deadlock and trigger uncontrolled resource consumption, creating a direct path to denial-of-service (DoS) attacks. The flaw, tracked as CVE-2026-32283, is triggered when one side of a TLS connection sends multiple key update messages ...
The Lab · 2026-04-15 10:22:54 · GitHub Issues
Kubescape is integrating a new GitOps-native mechanism for accepting security risks directly into its vulnerability scanning pipeline. The core development adds a `SecurityExceptionAdapter` that uses a dynamic Kubernetes client to read custom resource definitions (CRDs) for `SecurityException` and `ClusterSecurityExcep...