{"id":"CVE-2026-54495","summary":"Cross-namespace FeatureFlagSource and InProcessConfiguration resolution exposes spec contents on multi-tenant clusters","details":"The OpenFeature Operator allows users to expose feature flags to applications. In version 0.9.2 and earlier, a tenant who can create a controller-owned workload can use the openfeature.dev/featureflagsource annotation with NAMESPACE/NAME syntax to reference a FeatureFlagSource or InProcessConfiguration in another namespace. On multi-tenant clusters that use namespaces as trust boundaries, the cluster-scoped operator reads that resource and materializes spec.envVars literal values, spec.httpSyncBearerToken, sync URIs, and supporting ConfigMaps into the tenant's workload. Single-tenant clusters are not impacted, secretKeyRef and configMapKeyRef values remain namespace-local, and creating a FeatureFlagSource is not required.","aliases":["GHSA-398h-7f66-3h4p","GO-2026-5998"],"modified":"2026-09-19T03:47:13.199352699Z","published":"2026-09-17T19:44:13.222Z","related":["openSUSE-SU-2026:21483-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-668"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54495.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54495.json"},{"type":"ADVISORY","url":"https://github.com/open-feature/open-feature-operator/security/advisories/GHSA-398h-7f66-3h4p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54495"},{"type":"REPORT","url":"https://github.com/open-feature/open-feature-operator/issues/847"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/open-feature/open-feature-operator","events":[{"introduced":"0"},{"last_affected":"90d373fd1661c998ae22f95fb32367dcbfd2d86c"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"last_affected":"0.9.2"}]}}],"versions":["v0.9.2","api/v0.2.49","v0.9.1","api/v0.2.48","v0.9.0","api/v0.2.47","apis/v0.2.46","v0.8.9","v0.8.8","v0.8.7","v0.8.6","v0.8.5","v0.8.4","apis/v0.2.45","api/v0.2.45","v0.8.3","v0.8.2","v0.8.1","v0.8.0","v0.7.2","v0.7.1","apis/v0.2.44","v0.7.0","v0.6.1","apis/v0.2.43","v0.6.0","v0.5.7","apis/v0.2.42","v0.5.6","apis/v0.2.41","v0.5.5","apis/v0.2.40","v0.5.4","apis/v0.2.39","v0.5.3","v0.5.2","v0.5.1","v0.5.0","apis/v0.2.38","apis/v0.2.37","v0.2.36","v0.2.35","v0.2.34","v0.2.33","v0.2.32","v0.2.31","v0.2.30","v0.2.29","v0.2.28","v0.2.27","v0.2.26","v0.2.25","v0.2.24","v0.2.23","v0.2.22","v0.2.21","v0.2.20","v0.2.19","v0.2.18","v0.2.17","v0.2.16","v0.2.15","v0.2.14","v0.2.13","v0.2.12","v0.2.11","v0.2.10","v0.2.9","v0.2.8","v0.2.7","v0.2.6","v0.2.5","v0.2.4","v0.2.3","v0.2.2","v0.2.1","v0.2.0","v0.1.1","v0.1.0","v0.0.9","v0.0.8","v0.0.7","v0.0.6","v0.0.5","v0.0.4","v0.0.3","v0.0.2","v0.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54495.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}