Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40109

17
FAUCET Score

OVERVIEW CVE-2026-40109 affects Flux notification-controller versions prior to 1.8.3. The vulnerability exists in the gcr Receiver type, which fails to validate the email claim of Google OIDC tokens used for Pub/Sub push authentication. This validation gap allows any valid Google-issued token to authenticate against the Receiver webhook endpoint, potentially triggering unauthorized Flux reconciliations. The issue is specific to GitOps Toolkit deployments using the gcr notification receiver configuration. SEVERITY This is a low-severity vulnerability with a CVSS v3.1 score of 3.1. The attack requires network access and high complexity, including prior knowledge of the webhook URL (which is intentionally difficult to enumerate). While the vulnerability permits integrity violations through unauthorized reconciliation triggering, the practical impact is significantly constrained. Flux reconciliation is idempotent, meaning unauthorized requests cause no cluster state changes if the desired state has not been modified in configured sources. Additionally, the controller deduplicates rapid requests, preventing denial-of-service through request flooding. EXPLOITATION STATUS There is no evidence of active exploitation. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog and has no public exploit code available. The EPSS score of 0.000120000 indicates minimal probability of exploitation in the wild. Community attention remains low given the restrictive attack requirements and limited practical impact. Organizations should prioritize patching to version 1.8.3 or later through standard update procedures, though the urgency is lower than for vulnerabilities with higher exploitability potential.

Impacted Technologies

VendorProductVersion(s)CPE
FluxcdNotification-Controller
< 1.8.3CNA affected

CVSS Data

CVSS version used by this source: 3.1

3.1LOW

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
1.6
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.13%
Probability of exploitation in next 30 days
EPSS Percentile
2.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0013 is in the 0th percentile among its peer group of 1,638 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

gopatch availablevia ghsa
Product: github.com/fluxcd/notification-controllerFixed in: 1.8.3

Vendor Advisories (1)

goGHSA-h9cx-xjg6-5v2wlow

Flux notification-controller GCR Receiver missing email validation allows unauthorized reconciliation triggering

Apr 10, 2026

References

github.com / fluxcd/notification-controller/pull/1279
github.com / fluxcd/notification-controller/releases/tag/v1.8.3
github.com / fluxcd/notification-controller/security/advisories/GHSA-h9cx-xjg6-5v2w