
Ryan Merck@rmerck
Stock kube patching will miss this entirely. kcp's front-proxy let authenticated tenants inject X-Remote-Group and stamp system:masters across workspaces. CVE-2026-61682 is a full isolation break hiding behind request-header auth. https://github.com/kcp-dev/kcp/security/advisories/GHSA-c8w2-fgvx-vhv4
0001035
46 followersView on X
