VYPR

Go modules package

github.com/fluxcd/notification-controller

pkg:golang/github.com/fluxcd/notification-controller

Vulnerabilities (2)

  • CVE-2026-40109LowApr 9, 2026
    affected < 1.8.3fixed 1.8.3

    Flux notification-controller is the event forwarder and notification dispatcher for the GitOps Toolkit controllers. Prior to 1.8.3, the gcr Receiver type in Flux notification-controller does not validate the email claim of Google OIDC tokens used for Pub/Sub push authentication.

  • CVE-2022-39272Oct 21, 2022
    affected >= 0.0.1-alpha-1, < 0.27.0fixed 0.27.0

    Flux is an open and extensible continuous delivery solution for Kubernetes. Versions prior to 0.35.0 are subject to a Denial of Service. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fi