When Multitenancy Goes Wrong: A Deep Dive Into Kcp’s First CVE - Marvin Beckers, ClickHouse
About this talk
This talk, presented by Marvin Beckers from ClickHouse, focuses on multitenancy challenges within kcp, a CNCF Sandbox project designed to manage Kubernetes-style APIs. The speaker delves into CVE-2025-29922, which escalates from a medium to a high severity vulnerability due to flaws in resource isolation. Beckers explains how the virtual workspaces feature was compromised, allowing service providers to manipulate resources beyond their permissions. Through this session, the audience gains insight into the discovery process of this vulnerability and the subsequent protective measures implemented to safeguard kcp users and their data.
More from this event
See all 436 talks →
Best of KubeCon + CloudNativeCon Amsterdam 2026
2:17
The Quiet Work of Forever: Sustaining Open Source Communities - O. Hope Amaechi-Okorie, JSON Schema
26:24
Evolving KServe: The Unified Model Inference Platform for Both Predictive and... F. Spolti & J. Lee
32:40
Preventing S3 Cost Storms: Applying Cortex’s Efficiency Lessons to I/O-Heav... A. Fishman-Lichterman
5:32