OVERVIEW CVE-2026-40109 affects Flux notification-controller versions prior to 1.8.3. The vulnerability exists in the gcr Receiver type, which fails to validate the email claim of Google OIDC tokens used for Pub/Sub push authentication. This validation gap allows any valid Google-issued token to authenticate against the Receiver webhook endpoint, potentially triggering unauthorized Flux reconciliations. The issue is specific to GitOps Toolkit deployments using the gcr notification receiver configuration. SEVERITY This is a low-severity vulnerability with a CVSS v3.1 score of 3.1. The attack requires network access and high complexity, including prior knowledge of the webhook URL (which is intentionally difficult to enumerate). While the vulnerability permits integrity violations through unauthorized reconciliation triggering, the practical impact is significantly constrained. Flux reconciliation is idempotent, meaning unauthorized requests cause no cluster state changes if the desired state has not been modified in configured sources. Additionally, the controller deduplicates rapid requests, preventing denial-of-service through request flooding. EXPLOITATION STATUS There is no evidence of active exploitation. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog and has no public exploit code available. The EPSS score of 0.000120000 indicates minimal probability of exploitation in the wild. Community attention remains low given the restrictive attack requirements and limited practical impact. Organizations should prioritize patching to version 1.8.3 or later through standard update procedures, though the urgency is lower than for vulnerabilities with higher exploitability potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Fluxcd | Notification-Controller | < 1.8.3CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.