GHSA-fp5j-4fj2-4jvq
HIGHCVE-2026-53999A configuration-validation issue in the Radius Kubernetes controller can cause it to issue a DELETE for the container resource referenced by a tampered radapp.io/status annotation on a Deployment. It follows the "Confused Deputy" pattern. Real-world impact is bounded and depends heavily on install topology: in a multi-tenant install (one controller reconciling Deployments across resource groups ow
- Affected
- >=0, <0.58.0, < 0.58.0
- Fixed in
- 0.58.0
- Weakness
- CWE-20
- Published
- 2026-06-12
- Source
- osv