Junglewise Threat Intelligence

CVE-2026-40109: Flux notification-controller improper authentication in GCR Receiver

CVE-2026-40109 · Severity: low · CVSS 3.1 · Published 2026-04-10

Vendors: Go.

Executive brief

Flux is a tool used to automate the deployment of applications to Kubernetes clusters. A vulnerability in its notification component allows an attacker with a valid Google account to trigger a synchronization process between the cluster and its source code repositories. While this could lead to unauthorized system activity, the practical impact is low because the process only synchronizes to the state already defined in your secure code repositories.

Technical details

The 'gcr' Receiver type in Flux notification-controller does not validate the 'email' claim of Google OIDC tokens used for Pub/Sub push authentication. This allows any valid Google-issued JWT to authenticate against the Receiver webhook endpoint. An attacker who discovers the webhook URL (which is a SHA256 hash of the token, name, and namespace) can trigger unauthorized Flux reconciliations for resources listed in the Receiver's specification. The impact is mitigated by the idempotent nature of Flux reconciliations and request deduplication. The issue is fixed in version 1.8.3 by allowing optional validation of 'email' and 'audience' claims.

Affected products

  • FluxCD notification-controller < 1.8.3

Timeline

  • 2026-04-09: patched: Version 1.8.3 released
  • 2026-04-10: advisory: GitHub Advisory published

References

Related threats