CVE-2026-40109Disclosure

LOWCVSS 3.1 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Flux notification-controller is the event forwarder and notification dispatcher for the GitOps Toolkit controllers. Prior to 1.8.3, the gcr Receiver type in Flux notification-controller does not validate the email claim of Google OIDC tokens used for Pub/Sub push authentication. This allows any valid Google-issued token, to authenticate against the Receiver webhook endpoint, triggering unauthorized Flux reconciliations. Exploitation requires the attacker to know the Receiver's webhook URL. The webhook path is generated as /hook/sha256sum(token+name+namespace), where the token is a random string stored in a Kubernetes Secret. There is no API or endpoint that enumerates webhook URLs. An attacker cannot discover the path without either having access to the cluster and permissions to read the Receiver's .status.webhookPath in the target namespace, or obtaining the URL through other means (e.g. leaked secrets or access to Pub/Sub config). Upon successful authentication, the controller triggers a reconciliation for all resources listed in the Receiver's .spec.resources. However, the practical impact is limited: Flux reconciliation is idempotent, so if the desired state in the configured sources (Git, OCI, Helm) has not changed, the reconciliation results in a no-op with no effect on cluster state. Additionally, Flux controllers deduplicate reconciliation requests, sending many requests in a short period results in only a single reconciliation being processed. This vulnerability is fixed in 1.8.3.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287CWE-345

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-04-10); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-10: 2Mentions · 2026-04-11: 1Mentions · 2026-04-28: 1Technical Details · 2026-04-11: 1Technical Details · 2026-04-28: 104-1004-1104-28
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-102
Disclosure1General1
2026-04-111
Disclosure1
2026-04-281
Disclosure1
Full discourse4 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-40109: CVE-2026-40109: Improper Authentication in Flux notification-controller GCR Receiver The Flux notification-controller prior to version 1.8.3 suffers from improper authentication in its Google Container Registry (GCR) Receiver webhook l... https://cvereports.com/reports/CVE-2026-40109

    Post summary

    The snippet announces CVE‑2026‑40109, noting improper authentication in Flux notification‑controller GCR Receiver before version 1.8.3, with no evidence of exploitation, PoC, or remediation.

    0000028
    36 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔵 Flux notification-controller, Authentication Bypass, #CVE-2026-40109 (Low) https://dailycve.com/flux-notification-controller-authentication-bypass-cve-2026-40109-low/

    Post summary

    The post announces a low‑severity authentication bypass flaw (CVE‑2026‑40109) in Flux notification‑controller, providing basic vulnerability details but no evidence of exploitation or mitigation steps.

    0000047
    181 followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-40109 Flux notification-controller is the event forwarder and notification dispatcher for the GitOps Toolkit controllers. Prior to 1.8.3, the gcr Receiver type in Flux noti… https://www.cve.org/CVERecord?id=CVE-2026-40109 ----- Traducción: CVE-2026-40109 Flu… http://infoflow.cloud`

    Post summary

    The message merely references CVE‐2026‑40109 with a link, offering no useful technical or threat information.

    0000031
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40109 Flux notification-controller is the event forwarder and notification dispatcher for the GitOps Toolkit controllers. Prior to 1.8.3, the gcr Receiver type in Flux noti… https://www.cve.org/CVERecord?id=CVE-2026-40109

    Post summary

    The statement provides a concise disclosure of CVE‑2026‑40109 without any evidence of exploitation, PoC, or mitigation details.

    00000212
    57.0K followersView on X

Explore more