Capsule has an incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation) in github.com/projectcapsule/capsule
{
"review_status": "UNREVIEWED",
"url": "https://pkg.go.dev/vuln/GO-2026-6157"
}