github.com/fluxcd/notification-controller
The GitOps Toolkit event forwarder and notification dispatcher
Activity
- Latest release
- 1w ago
- Total releases
- 63
- Cadence
- ~22 days
- Last 12 months
- 14
Reach
- Stars
- 181
Details
- First release
- Jul 01, 2020
| Version | Released | |
|---|---|---|
v1.9.4
patch
|
v1.9.4
patch
Dependencies (52)
+ 44 more |
|
v1.9.3
patch
|
v1.9.3
patch
Dependencies (52)
+ 44 more |
|
v1.9.2
minor
|
v1.9.2
minor
Dependencies (52)
+ 44 more |
|
v1.9.1
patch
|
v1.9.1
patch
Dependencies (52)
+ 44 more |
|
v1.9.0
minor
|
v1.9.0
minor
Dependencies (52)
+ 44 more |
|
v1.8.4
patch
|
v1.8.4
patch
Dependencies (50)
+ 42 more |
|
v1.8.3
patch
|
v1.8.3
patch
Dependencies (50)
+ 42 more |
|
v1.8.2
patch
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.8.2
patch
Dependencies (50)
+ 42 more |
|
v1.8.1
minor
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.8.1
minor
Dependencies (50)
+ 42 more |
|
v1.8.0
minor
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.8.0
minor
Dependencies (50)
+ 42 more |
|
v1.7.5
patch
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.7.5
patch
Dependencies (49)
+ 41 more |
|
v1.7.4
minor
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.7.4
minor
Dependencies (49)
+ 41 more |
|
v1.7.3
patch
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.7.3
patch
Dependencies (49)
+ 41 more |
|
v1.7.2
patch
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.7.2
patch
Dependencies (49)
+ 41 more |
|
v1.7.1
patch
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.7.1
patch
Dependencies (49)
+ 41 more |
|
v1.7.0
minor
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.7.0
minor
Dependencies (49)
+ 41 more |
|
v1.6.0
minor
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.6.0
minor
Dependencies (46)
+ 38 more |
|
v1.5.0
minor
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.5.0
minor
Dependencies (42)
+ 34 more |
|
v1.4.0
minor
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.4.0
minor
Dependencies (40)
+ 32 more |
|
v1.3.0
minor
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.3.0
minor
Dependencies (40)
+ 32 more |
|
v1.2.4
patch
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.2.4
patch
Dependencies (39)
+ 31 more |
|
v1.2.2
patch
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.2.2
patch
Dependencies (39)
+ 31 more |
|
v1.2.1
patch
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.2.1
patch
Dependencies (39)
+ 31 more |
|
v1.2.0
minor
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.2.0
minor
Dependencies (39)
+ 31 more |
|
v1.1.0
major
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.1.0
major
Dependencies (37)
+ 29 more |
|
v1.0.0-rc.4
pre
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.0.0-rc.4
pre
Dependencies (33)
+ 25 more |
|
v1.0.0-rc.1
pre
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.0.0-rc.1
pre
Dependencies (32)
+ 24 more |
|
v0.32.0
minor
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.32.0
minor
Dependencies (32)
+ 24 more |
|
v0.31.0
minor
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.31.0
minor
Dependencies (31)
+ 23 more |
|
v0.30.2
patch
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.30.2
patch
Dependencies (31)
+ 23 more |
|
v0.30.1
patch
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.30.1
patch
Dependencies (31)
+ 23 more |
|
v0.30.0
minor
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.30.0
minor
Dependencies (31)
+ 23 more |
|
v0.29.1
patch
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.29.1
patch
Dependencies (30)
+ 22 more |
|
v0.29.0
minor
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.29.0
minor
Dependencies (30)
+ 22 more |
|
v0.28.0
minor
1 CVE
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev |
v0.28.0
minor
Dependencies (29)
+ 21 more |
|
v0.25.2
patch
2 CVEs
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.27.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.25.2
patch
Dependencies (28)
+ 20 more |
|
v0.25.1
minor
2 CVEs
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.27.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.25.1
minor
Dependencies (28)
+ 20 more |
|
v0.24.1
minor
2 CVEs
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.27.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.24.1
minor
Dependencies (28)
+ 20 more |
|
v0.23.4
patch
2 CVEs
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.27.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.23.4
patch
Dependencies (27)
+ 19 more |
|
v0.23.3
patch
2 CVEs
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.27.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.23.3
patch
Dependencies (27)
+ 19 more |
|
v0.23.2
patch
2 CVEs
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.27.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.23.2
patch
Dependencies (27)
+ 19 more |
|
v0.23.1
minor
2 CVEs
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.27.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.23.1
minor
Dependencies (27)
+ 19 more |
|
v0.22.3
patch
2 CVEs
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.27.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.22.3
patch
Dependencies (27)
+ 19 more |
|
v0.22.2
minor
2 CVEs
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.27.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.22.2
minor
Dependencies (27)
+ 19 more |
|
v0.17.0
minor
2 CVEs
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.27.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.17.0
minor
Dependencies (25)
+ 17 more |
|
v0.16.0
minor
2 CVEs
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.27.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.16.0
minor
Dependencies (25)
+ 17 more |
|
v0.15.1
minor
2 CVEs
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.27.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.15.1
minor
Dependencies (24)
+ 16 more |
|
v0.14.0
minor
2 CVEs
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.27.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.14.0
minor
Dependencies (24)
+ 16 more |
|
v0.13.0
minor
2 CVEs
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.27.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.13.0
minor
Dependencies (22)
+ 14 more |
|
v0.11.0
minor
2 CVEs
CVE-2026-40109
GO-2026-5419
GHSA-h9cx-xjg6-5v2w
Jun 25, 2026
Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering in github.com/fluxcd/notification-controller Fixed in
1.8.3
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.27.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.11.0
minor
Dependencies (19)
+ 11 more |