github.com/fluxcd/source-controller
The GitOps Toolkit source management component
Activity
- Latest release
- 1w ago
- Total releases
- 65
- Cadence
- ~20 days
- Last 12 months
- 16
Reach
- Stars
- 282
Details
- First release
- Apr 16, 2020
| Version | Released | |
|---|---|---|
v1.9.5
patch
|
v1.9.5
patch
Dependencies (66)
+ 58 more |
|
v1.9.4
patch
|
v1.9.4
patch
Dependencies (66)
+ 58 more |
|
v1.9.3
patch
|
v1.9.3
patch
Dependencies (66)
+ 58 more |
|
v1.9.2
minor
|
v1.9.2
minor
Dependencies (66)
+ 58 more |
|
v1.9.1
patch
|
v1.9.1
patch
Dependencies (66)
+ 58 more |
|
v1.9.0
minor
|
v1.9.0
minor
Dependencies (66)
+ 58 more |
|
v1.8.5
patch
|
v1.8.5
patch
Dependencies (65)
+ 57 more |
|
v1.8.4
patch
1 CVE
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.8.4
patch
Dependencies (65)
+ 57 more |
|
v1.8.3
patch
1 CVE
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.8.3
patch
Dependencies (65)
+ 57 more |
|
v1.8.2
patch
1 CVE
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.8.2
patch
Dependencies (65)
+ 57 more |
|
v1.8.1
minor
1 CVE
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.8.1
minor
Dependencies (65)
+ 57 more |
|
v1.8.0
minor
1 CVE
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.8.0
minor
Dependencies (65)
+ 57 more |
|
v1.7.4
minor
1 CVE
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.7.4
minor
Dependencies (65)
+ 57 more |
|
v1.7.3
patch
1 CVE
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.7.3
patch
Dependencies (65)
+ 57 more |
|
v1.7.2
patch
1 CVE
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.7.2
patch
Dependencies (65)
+ 57 more |
|
v1.7.1
patch
1 CVE
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.7.1
patch
Dependencies (65)
+ 57 more |
|
v1.7.0
minor
1 CVE
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.7.0
minor
Dependencies (65)
+ 57 more |
|
v1.7.0-rc.3
pre
1 CVE
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.7.0-rc.3
pre
Dependencies (65)
+ 57 more |
|
v1.7.0-rc.2
pre
1 CVE
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.7.0-rc.2
pre
Dependencies (65)
+ 57 more |
|
v1.7.0-rc.1
pre
1 CVE
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.7.0-rc.1
pre
Dependencies (65)
+ 57 more |
|
v1.6.2
patch
1 CVE
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.6.2
patch
Dependencies (66)
+ 58 more |
|
v1.6.1
minor
1 CVE
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.6.1
minor
Dependencies (66)
+ 58 more |
|
v1.2.2
minor
2 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.2.2
minor
Dependencies (57)
+ 49 more |
|
v1.1.0
minor
2 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.1.0
minor
Dependencies (57)
+ 49 more |
|
v1.0.1
major
2 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.0.1
major
Dependencies (56)
+ 48 more |
|
v1.0.0-rc.4
pre
2 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v1.0.0-rc.4
pre
Dependencies (56)
+ 48 more |
|
v0.36.1
minor
2 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.36.1
minor
Dependencies (56)
+ 48 more |
|
v0.35.0
minor
2 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.35.0
minor
Dependencies (56)
+ 48 more |
|
v0.32.0
minor
2 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.32.0
minor
Dependencies (54)
+ 46 more |
|
v0.31.0
minor
2 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.31.0
minor
Dependencies (55)
+ 47 more |
|
v0.30.1
patch
2 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.30.1
patch
Dependencies (56)
+ 48 more |
|
v0.30.0
minor
2 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev |
v0.30.0
minor
Dependencies (56)
+ 48 more |
|
v0.29.0
minor
3 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.30.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.29.0
minor
Dependencies (53)
+ 45 more |
|
v0.28.0
minor
3 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.30.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.28.0
minor
Dependencies (53)
+ 45 more |
|
v0.25.7
patch
3 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.30.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.25.7
patch
Dependencies (48)
+ 40 more |
|
v0.25.6
patch
3 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.30.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.25.6
patch
Dependencies (48)
+ 40 more |
|
v0.25.5
patch
3 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.30.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.25.5
patch
Dependencies (48)
+ 40 more |
|
v0.25.4
patch
3 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.30.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.25.4
patch
Dependencies (48)
+ 40 more |
|
v0.25.2
minor
3 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.30.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.25.2
minor
Dependencies (48)
+ 40 more |
|
v0.24.4
patch
3 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.30.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.24.4
patch
Dependencies (43)
+ 35 more |
|
v0.24.2
minor
3 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.30.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.24.2
minor
Dependencies (43)
+ 35 more |
|
v0.22.5
patch
3 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.30.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.22.5
patch
Dependencies (42)
+ 34 more |
|
v0.22.3
patch
3 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.30.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.22.3
patch
Dependencies (42)
+ 34 more |
|
v0.22.2
minor
3 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.30.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.22.2
minor
Dependencies (42)
+ 34 more |
|
v0.19.2
minor
3 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.30.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.19.2
minor
Dependencies (33)
+ 25 more |
|
v0.17.2
patch
3 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.30.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.17.2
patch
Dependencies (32)
+ 24 more |
|
v0.17.0
minor
3 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.30.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.17.0
minor
Dependencies (32)
+ 24 more |
|
v0.16.1
patch
3 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.30.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.16.1
patch
Dependencies (31)
+ 23 more |
|
v0.16.0
minor
3 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.30.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.16.0
minor
Dependencies (29)
+ 21 more |
|
v0.15.1
minor
3 CVEs
CVE-2026-47680
GO-2026-5472
GHSA-jjrm-hr5f-673x
Jun 25, 2026
Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Source controller: Improper path handling allows traversal in github.com/fluxcd/source-controller Fixed in
1.8.5
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2024-31216
GO-2024-2859
GHSA-v554-xwgw-hc3w
Jun 04, 2024
source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller source-controller leaks Azure Storage SAS token into logs in github.com/fluxcd/source-controller Fixed in
1.2.5
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2022-39272
GHSA-f4p5-x4vc-mh4v
BIT-flux-2022-39272
BIT-kustomize-2022-39272
GO-2022-1071
Oct 19, 2022
Improper use of metav1.Duration allows for Denial of Service
5.0
/ 10
Medium
Network
Low
Low
None
Changed
None
None
Low
Flux controllers within the affected versions range are vulnerable to a denial of service attack. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields The issue has two root causes: a) the Kubernetes type WorkaroundsAdmission controllers can be employed to restrict the values that can be used for fields CreditsThis issue was reported by Alexander Block (@codablock) through the Flux security mailing list (as recommended). For more informationIf you have any questions or comments about this advisory:
References
Fixed in
0.30.0
References
Updated Sep 10, 2026 · Source: OSV.dev |
v0.15.1
minor
Dependencies (30)
+ 22 more |