Product
critical
advisory
Lighthouse Cross-Namespace Resource Injection Vulnerability
1 TTP 1 CVEA vulnerability in Submariner Lighthouse allows a compromised spoke cluster to inject unauthorized EndpointSlices and ServiceImports into peer cluster namespaces, leading to potential privilege escalation.
Lighthouse
cloud-native
kubernetes
privilege-escalation
submariner
1t
1c
high
advisory
webonyx/graphql-php Unbounded Recursion Vulnerability
2 rules 1 TTPThe webonyx/graphql-php library has an unbounded recursion vulnerability in its parser that can lead to a stack overflow, causing a denial of service by terminating the PHP process with a SIGSEGV.
graphql-php +4
graphql
denial-of-service
recursion
php
2r
1t