github.com/fluxcd/flux2
Open and extensible continuous delivery solution for Kubernetes. Powered by GitOps Toolkit.
Activity
- Latest release
- 3y ago
- Total releases
- 20
- Cadence
- ~17 days
- Last 12 months
- 0
Reach
- Stars
- 8.4k
Details
- First release
- Apr 28, 2022
| Version | Released | |
|---|---|---|
v0.41.2
patch
|
v0.41.2
patch
Dependencies (51)
+ 43 more |
|
v0.41.1
patch
|
v0.41.1
patch
Dependencies (51)
+ 43 more |
|
v0.41.0
minor
|
v0.41.0
minor
Dependencies (51)
+ 43 more |
|
v0.40.2
patch
|
v0.40.2
patch
Dependencies (50)
+ 42 more |
|
v0.40.1
patch
|
v0.40.1
patch
Dependencies (50)
+ 42 more |
|
v0.40.0
minor
|
v0.40.0
minor
Dependencies (50)
+ 42 more |
|
v0.39.0
minor
|
v0.39.0
minor
Dependencies (50)
+ 42 more |
|
v0.38.3
patch
|
v0.38.3
patch
Dependencies (50)
+ 42 more |
|
v0.38.2
patch
|
v0.38.2
patch
Dependencies (50)
+ 42 more |
|
v0.38.1
patch
|
v0.38.1
patch
Dependencies (50)
+ 42 more |
|
v0.38.0
minor
|
v0.38.0
minor
Dependencies (50)
+ 42 more |
|
v0.37.0
minor
|
v0.37.0
minor
Dependencies (50)
+ 42 more |
|
v0.36.0
minor
|
v0.36.0
minor
Dependencies (49)
+ 41 more |
|
v0.35.0
minor
|
v0.35.0
minor
Dependencies (47)
+ 39 more |
|
v0.34.0
minor
1 CVE
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.35.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.34.0
minor
Dependencies (47)
+ 39 more |
|
v0.33.0
minor
1 CVE
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.35.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.33.0
minor
Dependencies (47)
+ 39 more |
|
v0.32.0
minor
1 CVE
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.35.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.32.0
minor
Dependencies (46)
+ 38 more |
|
v0.31.5
patch
3 CVEs
CVE-2022-36035
GO-2022-0960
BIT-flux-2022-36035
GHSA-xwf3-6rgv-939r
Aug 21, 2024
Flux CLI Workload Injection in github.com/fluxcd/flux2 Flux CLI Workload Injection in github.com/fluxcd/flux2 Fixed in
0.32.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.35.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-36049
GHSA-p2g7-xwvr-rrw3
BIT-flux-2022-36049
BIT-helm-2022-36049
Sep 16, 2022
Helm Controller denial of service
7.7
/ 10
High
Network
Low
Low
None
Changed
None
None
High
Helm controller is tightly integrated with the Helm SDK. A vulnerability found in the Helm SDK allows for specific data inputs to cause high memory consumption, which in some platforms could cause the controller to panic and stop processing reconciliations. ImpactIn a shared cluster multi-tenancy environment, a tenant could create a HelmRelease that makes the controller panic, denying all other tenants from their Helm releases being reconciled. CreditsThe initial crash bug was reported by oss-fuzz. The Flux Security team produced the first exploit and worked together with the Helm Security team to ensure that both projects were patched timely. For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.32.0
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.31.5
patch
Dependencies (44)
+ 36 more |
|
v0.31.3
initial
3 CVEs
CVE-2022-36035
GO-2022-0960
BIT-flux-2022-36035
GHSA-xwf3-6rgv-939r
Aug 21, 2024
Flux CLI Workload Injection in github.com/fluxcd/flux2 Flux CLI Workload Injection in github.com/fluxcd/flux2 Fixed in
0.32.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.35.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-36049
GHSA-p2g7-xwvr-rrw3
BIT-flux-2022-36049
BIT-helm-2022-36049
Sep 16, 2022
Helm Controller denial of service
7.7
/ 10
High
Network
Low
Low
None
Changed
None
None
High
Helm controller is tightly integrated with the Helm SDK. A vulnerability found in the Helm SDK allows for specific data inputs to cause high memory consumption, which in some platforms could cause the controller to panic and stop processing reconciliations. ImpactIn a shared cluster multi-tenancy environment, a tenant could create a HelmRelease that makes the controller panic, denying all other tenants from their Helm releases being reconciled. CreditsThe initial crash bug was reported by oss-fuzz. The Flux Security team produced the first exploit and worked together with the Helm Security team to ensure that both projects were patched timely. For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.32.0
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.31.3
initial
Dependencies (44)
+ 36 more |
|
v0.31.4
patch
3 CVEs
CVE-2022-36035
GO-2022-0960
BIT-flux-2022-36035
GHSA-xwf3-6rgv-939r
Aug 21, 2024
Flux CLI Workload Injection in github.com/fluxcd/flux2 Flux CLI Workload Injection in github.com/fluxcd/flux2 Fixed in
0.32.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.35.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-36049
GHSA-p2g7-xwvr-rrw3
BIT-flux-2022-36049
BIT-helm-2022-36049
Sep 16, 2022
Helm Controller denial of service
7.7
/ 10
High
Network
Low
Low
None
Changed
None
None
High
Helm controller is tightly integrated with the Helm SDK. A vulnerability found in the Helm SDK allows for specific data inputs to cause high memory consumption, which in some platforms could cause the controller to panic and stop processing reconciliations. ImpactIn a shared cluster multi-tenancy environment, a tenant could create a HelmRelease that makes the controller panic, denying all other tenants from their Helm releases being reconciled. CreditsThe initial crash bug was reported by oss-fuzz. The Flux Security team produced the first exploit and worked together with the Helm Security team to ensure that both projects were patched timely. For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.32.0
References
Updated Feb 04, 2026 · Source: OSV.dev |
v0.31.4
patch
Dependencies (44)
+ 36 more |