github.com/fluxcd/kustomize-controller
The GitOps Toolkit Kustomize reconciler
Activity
- Latest release
- 2w ago
- Total releases
- 67
- Cadence
- ~26 days
- Last 12 months
- 15
Reach
- Stars
- 285
Details
- First release
- Apr 20, 2020
| Version | Released | |
|---|---|---|
v1.9.5
patch
|
v1.9.5
patch
Dependencies (41)
+ 33 more |
|
v1.9.4
patch
|
v1.9.4
patch
Dependencies (40)
+ 32 more |
|
v1.9.3
patch
|
v1.9.3
patch
Dependencies (40)
+ 32 more |
|
v1.9.2
minor
|
v1.9.2
minor
Dependencies (40)
+ 32 more |
|
v1.9.1
patch
|
v1.9.1
patch
Dependencies (40)
+ 32 more |
|
v1.9.0
minor
|
v1.9.0
minor
Dependencies (40)
+ 32 more |
|
v1.8.5
patch
|
v1.8.5
patch
Dependencies (40)
+ 32 more |
|
v1.8.4
patch
|
v1.8.4
patch
Dependencies (40)
+ 32 more |
|
v1.8.3
patch
|
v1.8.3
patch
Dependencies (40)
+ 32 more |
|
v1.8.2
patch
|
v1.8.2
patch
Dependencies (40)
+ 32 more |
|
v1.8.1
minor
|
v1.8.1
minor
Dependencies (40)
+ 32 more |
|
v1.8.0
minor
|
v1.8.0
minor
Dependencies (40)
+ 32 more |
|
v1.7.3
patch
|
v1.7.3
patch
Dependencies (40)
+ 32 more |
|
v1.7.2
patch
|
v1.7.2
patch
Dependencies (40)
+ 32 more |
|
v1.7.1
patch
|
v1.7.1
patch
Dependencies (40)
+ 32 more |
|
v1.7.0
minor
|
v1.7.0
minor
Dependencies (40)
+ 32 more |
|
v1.7.0-rc.1
pre
|
v1.7.0-rc.1
pre
Dependencies (40)
+ 32 more |
|
v1.6.1
minor
|
v1.6.1
minor
Dependencies (39)
+ 31 more |
|
v1.6.0
minor
|
v1.6.0
minor
Dependencies (39)
+ 31 more |
|
v1.5.1
patch
|
v1.5.1
patch
Dependencies (34)
+ 26 more |
|
v1.5.0
minor
|
v1.5.0
minor
Dependencies (34)
+ 26 more |
|
v1.4.0
minor
|
v1.4.0
minor
Dependencies (34)
+ 26 more |
|
v1.2.2
patch
|
v1.2.2
patch
Dependencies (34)
+ 26 more |
|
v1.2.0
minor
|
v1.2.0
minor
Dependencies (34)
+ 26 more |
|
v1.1.0
minor
|
v1.1.0
minor
Dependencies (46)
+ 38 more |
|
v1.0.1
major
|
v1.0.1
major
Dependencies (46)
+ 38 more |
|
v1.0.0-rc.4
pre
|
v1.0.0-rc.4
pre
Dependencies (46)
+ 38 more |
|
v0.35.0
minor
|
v0.35.0
minor
Dependencies (44)
+ 36 more |
|
v0.32.0
minor
|
v0.32.0
minor
Dependencies (44)
+ 36 more |
|
v0.31.0
minor
|
v0.31.0
minor
Dependencies (44)
+ 36 more |
|
v0.30.0
minor
|
v0.30.0
minor
Dependencies (46)
+ 38 more |
|
v0.29.0
minor
|
v0.29.0
minor
Dependencies (44)
+ 36 more |
|
v0.28.0
minor
1 CVE
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.29.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.28.0
minor
Dependencies (44)
+ 36 more |
|
v0.26.2
minor
1 CVE
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.29.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.26.2
minor
Dependencies (43)
+ 35 more |
|
v0.24.4
patch
1 CVE
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.29.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.24.4
patch
Dependencies (33)
+ 25 more |
|
v0.24.2
patch
1 CVE
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.29.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.24.2
patch
Dependencies (33)
+ 25 more |
|
v0.24.1
minor
1 CVE
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.29.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.24.1
minor
Dependencies (33)
+ 25 more |
|
v0.22.3
patch
4 CVEs
CVE-2022-24878
GO-2022-0448
BIT-flux-2022-24878
BIT-kustomize-2022-24878
GHSA-7pwf-jg34-hxwp
Aug 21, 2024
Improper path handling in Kustomization files allows for denial of service in github.com/fluxcd/flux2 Improper path handling in Kustomization files allows for denial of service in github.com/fluxcd/flux2 Fixed in
0.24.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24877
GO-2022-0447
BIT-flux-2022-24877
BIT-kustomize-2022-24877
GHSA-j77r-2fxf-5jrw
Aug 21, 2024
Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2 Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2 Fixed in
0.24.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.29.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-24817
GHSA-vvmq-fwmg-2gjc
BIT-flux-2022-24817
BIT-kustomize-2022-24817
May 16, 2022
Improper kubeconfig validation allows arbitrary code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Flux2 can reconcile the state of a remote cluster when provided with a kubeconfig with the correct access rights. In multi-tenancy deployments this can also lead to privilege escalation if the controller's service account has elevated permissions. ImpactWithin the affected versions range, one of the permissions set below would be required for the vulnerability to be exploited:
PatchesThis vulnerability was fixed in kustomize-controller v0.23.0 and helm-controller v0.19.0, both included in flux2 v0.29.0. Starting from the fixed versions, both controllers disable the use of command execution from Workarounds
CreditsThe Flux engineering team found and patched this vulnerability. For more informationIf you have any questions or comments about this advisory please open an issue in the flux2 repository. Fixed in
0.23.0
References Updated Dec 02, 2025 · Source: OSV.dev |
v0.22.3
patch
Dependencies (34)
+ 26 more |
|
v0.22.2
minor
4 CVEs
CVE-2022-24878
GO-2022-0448
BIT-flux-2022-24878
BIT-kustomize-2022-24878
GHSA-7pwf-jg34-hxwp
Aug 21, 2024
Improper path handling in Kustomization files allows for denial of service in github.com/fluxcd/flux2 Improper path handling in Kustomization files allows for denial of service in github.com/fluxcd/flux2 Fixed in
0.24.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24877
GO-2022-0447
BIT-flux-2022-24877
BIT-kustomize-2022-24877
GHSA-j77r-2fxf-5jrw
Aug 21, 2024
Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2 Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2 Fixed in
0.24.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.29.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-24817
GHSA-vvmq-fwmg-2gjc
BIT-flux-2022-24817
BIT-kustomize-2022-24817
May 16, 2022
Improper kubeconfig validation allows arbitrary code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Flux2 can reconcile the state of a remote cluster when provided with a kubeconfig with the correct access rights. In multi-tenancy deployments this can also lead to privilege escalation if the controller's service account has elevated permissions. ImpactWithin the affected versions range, one of the permissions set below would be required for the vulnerability to be exploited:
PatchesThis vulnerability was fixed in kustomize-controller v0.23.0 and helm-controller v0.19.0, both included in flux2 v0.29.0. Starting from the fixed versions, both controllers disable the use of command execution from Workarounds
CreditsThe Flux engineering team found and patched this vulnerability. For more informationIf you have any questions or comments about this advisory please open an issue in the flux2 repository. Fixed in
0.23.0
References Updated Dec 02, 2025 · Source: OSV.dev |
v0.22.2
minor
Dependencies (34)
+ 26 more |
|
v0.17.0
minor
4 CVEs
CVE-2022-24878
GO-2022-0448
BIT-flux-2022-24878
BIT-kustomize-2022-24878
GHSA-7pwf-jg34-hxwp
Aug 21, 2024
Improper path handling in Kustomization files allows for denial of service in github.com/fluxcd/flux2 Improper path handling in Kustomization files allows for denial of service in github.com/fluxcd/flux2 Fixed in
0.24.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24877
GO-2022-0447
BIT-flux-2022-24877
BIT-kustomize-2022-24877
GHSA-j77r-2fxf-5jrw
Aug 21, 2024
Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2 Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2 Fixed in
0.24.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.29.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-24817
GHSA-vvmq-fwmg-2gjc
BIT-flux-2022-24817
BIT-kustomize-2022-24817
May 16, 2022
Improper kubeconfig validation allows arbitrary code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Flux2 can reconcile the state of a remote cluster when provided with a kubeconfig with the correct access rights. In multi-tenancy deployments this can also lead to privilege escalation if the controller's service account has elevated permissions. ImpactWithin the affected versions range, one of the permissions set below would be required for the vulnerability to be exploited:
PatchesThis vulnerability was fixed in kustomize-controller v0.23.0 and helm-controller v0.19.0, both included in flux2 v0.29.0. Starting from the fixed versions, both controllers disable the use of command execution from Workarounds
CreditsThe Flux engineering team found and patched this vulnerability. For more informationIf you have any questions or comments about this advisory please open an issue in the flux2 repository. Fixed in
0.23.0
References Updated Dec 02, 2025 · Source: OSV.dev |
v0.17.0
minor
Dependencies (27)
+ 19 more |
|
v0.16.0
minor
4 CVEs
CVE-2022-24878
GO-2022-0448
BIT-flux-2022-24878
BIT-kustomize-2022-24878
GHSA-7pwf-jg34-hxwp
Aug 21, 2024
Improper path handling in Kustomization files allows for denial of service in github.com/fluxcd/flux2 Improper path handling in Kustomization files allows for denial of service in github.com/fluxcd/flux2 Fixed in
0.24.0
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2022-24877
GO-2022-0447
BIT-flux-2022-24877
BIT-kustomize-2022-24877
GHSA-j77r-2fxf-5jrw
Aug 21, 2024
Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2 Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2 Fixed in
0.24.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.29.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-24817
GHSA-vvmq-fwmg-2gjc
BIT-flux-2022-24817
BIT-kustomize-2022-24817
May 16, 2022
Improper kubeconfig validation allows arbitrary code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Flux2 can reconcile the state of a remote cluster when provided with a kubeconfig with the correct access rights. In multi-tenancy deployments this can also lead to privilege escalation if the controller's service account has elevated permissions. ImpactWithin the affected versions range, one of the permissions set below would be required for the vulnerability to be exploited:
PatchesThis vulnerability was fixed in kustomize-controller v0.23.0 and helm-controller v0.19.0, both included in flux2 v0.29.0. Starting from the fixed versions, both controllers disable the use of command execution from Workarounds
CreditsThe Flux engineering team found and patched this vulnerability. For more informationIf you have any questions or comments about this advisory please open an issue in the flux2 repository. Fixed in
0.23.0
References Updated Dec 02, 2025 · Source: OSV.dev |
v0.16.0
minor
Dependencies (29)
+ 21 more |
|
v0.15.3
patch
3 CVEs
CVE-2022-24877
GO-2022-0447
BIT-flux-2022-24877
BIT-kustomize-2022-24877
GHSA-j77r-2fxf-5jrw
Aug 21, 2024
Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2 Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2 Fixed in
0.24.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.29.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-24817
GHSA-vvmq-fwmg-2gjc
BIT-flux-2022-24817
BIT-kustomize-2022-24817
May 16, 2022
Improper kubeconfig validation allows arbitrary code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Flux2 can reconcile the state of a remote cluster when provided with a kubeconfig with the correct access rights. In multi-tenancy deployments this can also lead to privilege escalation if the controller's service account has elevated permissions. ImpactWithin the affected versions range, one of the permissions set below would be required for the vulnerability to be exploited:
PatchesThis vulnerability was fixed in kustomize-controller v0.23.0 and helm-controller v0.19.0, both included in flux2 v0.29.0. Starting from the fixed versions, both controllers disable the use of command execution from Workarounds
CreditsThe Flux engineering team found and patched this vulnerability. For more informationIf you have any questions or comments about this advisory please open an issue in the flux2 repository. Fixed in
0.23.0
References Updated Dec 02, 2025 · Source: OSV.dev |
v0.15.3
patch
Dependencies (29)
+ 21 more |
|
v0.15.1
minor
3 CVEs
CVE-2022-24877
GO-2022-0447
BIT-flux-2022-24877
BIT-kustomize-2022-24877
GHSA-j77r-2fxf-5jrw
Aug 21, 2024
Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2 Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2 Fixed in
0.24.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.29.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-24817
GHSA-vvmq-fwmg-2gjc
BIT-flux-2022-24817
BIT-kustomize-2022-24817
May 16, 2022
Improper kubeconfig validation allows arbitrary code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Flux2 can reconcile the state of a remote cluster when provided with a kubeconfig with the correct access rights. In multi-tenancy deployments this can also lead to privilege escalation if the controller's service account has elevated permissions. ImpactWithin the affected versions range, one of the permissions set below would be required for the vulnerability to be exploited:
PatchesThis vulnerability was fixed in kustomize-controller v0.23.0 and helm-controller v0.19.0, both included in flux2 v0.29.0. Starting from the fixed versions, both controllers disable the use of command execution from Workarounds
CreditsThe Flux engineering team found and patched this vulnerability. For more informationIf you have any questions or comments about this advisory please open an issue in the flux2 repository. Fixed in
0.23.0
References Updated Dec 02, 2025 · Source: OSV.dev |
v0.15.1
minor
Dependencies (29)
+ 21 more |
|
v0.13.3
patch
4 CVEs
CVE-2022-24877
GO-2022-0447
BIT-flux-2022-24877
BIT-kustomize-2022-24877
GHSA-j77r-2fxf-5jrw
Aug 21, 2024
Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2 Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2 Fixed in
0.24.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-41254
GO-2022-0260
BIT-kustomize-2021-41254
GHSA-35rf-v2jv-gfg7
Aug 21, 2024
Privilege escalation to cluster admin on multi-tenant environments in github.com/fluxcd/kustomize-controller Privilege escalation to cluster admin on multi-tenant environments in github.com/fluxcd/kustomize-controller Fixed in
0.15.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.29.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-24817
GHSA-vvmq-fwmg-2gjc
BIT-flux-2022-24817
BIT-kustomize-2022-24817
May 16, 2022
Improper kubeconfig validation allows arbitrary code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Flux2 can reconcile the state of a remote cluster when provided with a kubeconfig with the correct access rights. In multi-tenancy deployments this can also lead to privilege escalation if the controller's service account has elevated permissions. ImpactWithin the affected versions range, one of the permissions set below would be required for the vulnerability to be exploited:
PatchesThis vulnerability was fixed in kustomize-controller v0.23.0 and helm-controller v0.19.0, both included in flux2 v0.29.0. Starting from the fixed versions, both controllers disable the use of command execution from Workarounds
CreditsThe Flux engineering team found and patched this vulnerability. For more informationIf you have any questions or comments about this advisory please open an issue in the flux2 repository. Fixed in
0.23.0
References Updated Dec 02, 2025 · Source: OSV.dev |
v0.13.3
patch
Dependencies (29)
+ 21 more |
|
v0.13.0
minor
4 CVEs
CVE-2022-24877
GO-2022-0447
BIT-flux-2022-24877
BIT-kustomize-2022-24877
GHSA-j77r-2fxf-5jrw
Aug 21, 2024
Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2 Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2 Fixed in
0.24.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-41254
GO-2022-0260
BIT-kustomize-2021-41254
GHSA-35rf-v2jv-gfg7
Aug 21, 2024
Privilege escalation to cluster admin on multi-tenant environments in github.com/fluxcd/kustomize-controller Privilege escalation to cluster admin on multi-tenant environments in github.com/fluxcd/kustomize-controller Fixed in
0.15.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.29.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-24817
GHSA-vvmq-fwmg-2gjc
BIT-flux-2022-24817
BIT-kustomize-2022-24817
May 16, 2022
Improper kubeconfig validation allows arbitrary code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Flux2 can reconcile the state of a remote cluster when provided with a kubeconfig with the correct access rights. In multi-tenancy deployments this can also lead to privilege escalation if the controller's service account has elevated permissions. ImpactWithin the affected versions range, one of the permissions set below would be required for the vulnerability to be exploited:
PatchesThis vulnerability was fixed in kustomize-controller v0.23.0 and helm-controller v0.19.0, both included in flux2 v0.29.0. Starting from the fixed versions, both controllers disable the use of command execution from Workarounds
CreditsThe Flux engineering team found and patched this vulnerability. For more informationIf you have any questions or comments about this advisory please open an issue in the flux2 repository. Fixed in
0.23.0
References Updated Dec 02, 2025 · Source: OSV.dev |
v0.13.0
minor
Dependencies (29)
+ 21 more |
|
v0.12.1
minor
4 CVEs
CVE-2022-24877
GO-2022-0447
BIT-flux-2022-24877
BIT-kustomize-2022-24877
GHSA-j77r-2fxf-5jrw
Aug 21, 2024
Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2 Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2 Fixed in
0.24.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-41254
GO-2022-0260
BIT-kustomize-2021-41254
GHSA-35rf-v2jv-gfg7
Aug 21, 2024
Privilege escalation to cluster admin on multi-tenant environments in github.com/fluxcd/kustomize-controller Privilege escalation to cluster admin on multi-tenant environments in github.com/fluxcd/kustomize-controller Fixed in
0.15.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.29.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-24817
GHSA-vvmq-fwmg-2gjc
BIT-flux-2022-24817
BIT-kustomize-2022-24817
May 16, 2022
Improper kubeconfig validation allows arbitrary code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Flux2 can reconcile the state of a remote cluster when provided with a kubeconfig with the correct access rights. In multi-tenancy deployments this can also lead to privilege escalation if the controller's service account has elevated permissions. ImpactWithin the affected versions range, one of the permissions set below would be required for the vulnerability to be exploited:
PatchesThis vulnerability was fixed in kustomize-controller v0.23.0 and helm-controller v0.19.0, both included in flux2 v0.29.0. Starting from the fixed versions, both controllers disable the use of command execution from Workarounds
CreditsThe Flux engineering team found and patched this vulnerability. For more informationIf you have any questions or comments about this advisory please open an issue in the flux2 repository. Fixed in
0.23.0
References Updated Dec 02, 2025 · Source: OSV.dev |
v0.12.1
minor
Dependencies (29)
+ 21 more |
|
v0.11.1
patch
4 CVEs
CVE-2022-24877
GO-2022-0447
BIT-flux-2022-24877
BIT-kustomize-2022-24877
GHSA-j77r-2fxf-5jrw
Aug 21, 2024
Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2 Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2 Fixed in
0.24.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-41254
GO-2022-0260
BIT-kustomize-2021-41254
GHSA-35rf-v2jv-gfg7
Aug 21, 2024
Privilege escalation to cluster admin on multi-tenant environments in github.com/fluxcd/kustomize-controller Privilege escalation to cluster admin on multi-tenant environments in github.com/fluxcd/kustomize-controller Fixed in
0.15.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.29.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-24817
GHSA-vvmq-fwmg-2gjc
BIT-flux-2022-24817
BIT-kustomize-2022-24817
May 16, 2022
Improper kubeconfig validation allows arbitrary code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Flux2 can reconcile the state of a remote cluster when provided with a kubeconfig with the correct access rights. In multi-tenancy deployments this can also lead to privilege escalation if the controller's service account has elevated permissions. ImpactWithin the affected versions range, one of the permissions set below would be required for the vulnerability to be exploited:
PatchesThis vulnerability was fixed in kustomize-controller v0.23.0 and helm-controller v0.19.0, both included in flux2 v0.29.0. Starting from the fixed versions, both controllers disable the use of command execution from Workarounds
CreditsThe Flux engineering team found and patched this vulnerability. For more informationIf you have any questions or comments about this advisory please open an issue in the flux2 repository. Fixed in
0.23.0
References Updated Dec 02, 2025 · Source: OSV.dev |
v0.11.1
patch
Dependencies (29)
+ 21 more |
|
v0.11.0
minor
4 CVEs
CVE-2022-24877
GO-2022-0447
BIT-flux-2022-24877
BIT-kustomize-2022-24877
GHSA-j77r-2fxf-5jrw
Aug 21, 2024
Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2 Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2 Fixed in
0.24.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-41254
GO-2022-0260
BIT-kustomize-2021-41254
GHSA-35rf-v2jv-gfg7
Aug 21, 2024
Privilege escalation to cluster admin on multi-tenant environments in github.com/fluxcd/kustomize-controller Privilege escalation to cluster admin on multi-tenant environments in github.com/fluxcd/kustomize-controller Fixed in
0.15.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.29.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-24817
GHSA-vvmq-fwmg-2gjc
BIT-flux-2022-24817
BIT-kustomize-2022-24817
May 16, 2022
Improper kubeconfig validation allows arbitrary code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Flux2 can reconcile the state of a remote cluster when provided with a kubeconfig with the correct access rights. In multi-tenancy deployments this can also lead to privilege escalation if the controller's service account has elevated permissions. ImpactWithin the affected versions range, one of the permissions set below would be required for the vulnerability to be exploited:
PatchesThis vulnerability was fixed in kustomize-controller v0.23.0 and helm-controller v0.19.0, both included in flux2 v0.29.0. Starting from the fixed versions, both controllers disable the use of command execution from Workarounds
CreditsThe Flux engineering team found and patched this vulnerability. For more informationIf you have any questions or comments about this advisory please open an issue in the flux2 repository. Fixed in
0.23.0
References Updated Dec 02, 2025 · Source: OSV.dev |
v0.11.0
minor
Dependencies (29)
+ 21 more |
|
v0.9.1
minor
4 CVEs
CVE-2022-24877
GO-2022-0447
BIT-flux-2022-24877
BIT-kustomize-2022-24877
GHSA-j77r-2fxf-5jrw
Aug 21, 2024
Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2 Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2 Fixed in
0.24.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-41254
GO-2022-0260
BIT-kustomize-2021-41254
GHSA-35rf-v2jv-gfg7
Aug 21, 2024
Privilege escalation to cluster admin on multi-tenant environments in github.com/fluxcd/kustomize-controller Privilege escalation to cluster admin on multi-tenant environments in github.com/fluxcd/kustomize-controller Fixed in
0.15.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.29.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-24817
GHSA-vvmq-fwmg-2gjc
BIT-flux-2022-24817
BIT-kustomize-2022-24817
May 16, 2022
Improper kubeconfig validation allows arbitrary code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Flux2 can reconcile the state of a remote cluster when provided with a kubeconfig with the correct access rights. In multi-tenancy deployments this can also lead to privilege escalation if the controller's service account has elevated permissions. ImpactWithin the affected versions range, one of the permissions set below would be required for the vulnerability to be exploited:
PatchesThis vulnerability was fixed in kustomize-controller v0.23.0 and helm-controller v0.19.0, both included in flux2 v0.29.0. Starting from the fixed versions, both controllers disable the use of command execution from Workarounds
CreditsThe Flux engineering team found and patched this vulnerability. For more informationIf you have any questions or comments about this advisory please open an issue in the flux2 repository. Fixed in
0.23.0
References Updated Dec 02, 2025 · Source: OSV.dev |
v0.9.1
minor
Dependencies (26)
+ 18 more |
|
v0.7.1
minor
4 CVEs
CVE-2022-24877
GO-2022-0447
BIT-flux-2022-24877
BIT-kustomize-2022-24877
GHSA-j77r-2fxf-5jrw
Aug 21, 2024
Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2 Improper path handling in kustomization files allows path traversal in github.com/fluxcd/flux2 Fixed in
0.24.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2021-41254
GO-2022-0260
BIT-kustomize-2021-41254
GHSA-35rf-v2jv-gfg7
Aug 21, 2024
Privilege escalation to cluster admin on multi-tenant environments in github.com/fluxcd/kustomize-controller Privilege escalation to cluster admin on multi-tenant environments in github.com/fluxcd/kustomize-controller Fixed in
0.15.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.29.0
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2022-24817
GHSA-vvmq-fwmg-2gjc
BIT-flux-2022-24817
BIT-kustomize-2022-24817
May 16, 2022
Improper kubeconfig validation allows arbitrary code execution
9.9
/ 10
Critical
Network
Low
Low
None
Changed
High
High
High
Flux2 can reconcile the state of a remote cluster when provided with a kubeconfig with the correct access rights. In multi-tenancy deployments this can also lead to privilege escalation if the controller's service account has elevated permissions. ImpactWithin the affected versions range, one of the permissions set below would be required for the vulnerability to be exploited:
PatchesThis vulnerability was fixed in kustomize-controller v0.23.0 and helm-controller v0.19.0, both included in flux2 v0.29.0. Starting from the fixed versions, both controllers disable the use of command execution from Workarounds
CreditsThe Flux engineering team found and patched this vulnerability. For more informationIf you have any questions or comments about this advisory please open an issue in the flux2 repository. Fixed in
0.23.0
References Updated Dec 02, 2025 · Source: OSV.dev |
v0.7.1
minor
Dependencies (24)
+ 16 more |