Skip to content

Menu
  • Home
Menu

CVE-2026-73843 – OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs

Posted on August 14, 2026

CVE ID :CVE-2026-73843 Published : Aug. 13, 2026, 10:17 p.m. | 1 hour, 55 minutes ago Description :OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing…

CVE-2026-73842 – OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation

Posted on August 14, 2026

CVE ID :CVE-2026-73842 Published : Aug. 13, 2026, 10:17 p.m. | 1 hour, 55 minutes ago Description :OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed…

CVE-2026-73841 – OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints

Posted on August 14, 2026

CVE ID :CVE-2026-73841 Published : Aug. 13, 2026, 10:17 p.m. | 1 hour, 55 minutes ago Description :OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize…

CVE-2026-73667 – OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods

Posted on August 14, 2026

CVE ID :CVE-2026-73667 Published : Aug. 13, 2026, 10:17 p.m. | 1 hour, 55 minutes ago Description :OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow…

CVE-2026-73666 – OpenChoreo: Unauthenticated Backstage developer-portal API exposes OpenChoreo catalog data, scaffolder logs, and allows unauthenticated catalog write/delete

Posted on August 14, 2026

CVE ID :CVE-2026-73666 Published : Aug. 13, 2026, 10:17 p.m. | 1 hour, 55 minutes ago Description :OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend…

CVE-2026-71193 – OpenStack Designate Cross-Tenant Zone Overlap Vulnerability

Posted on August 13, 2026

CVE ID :CVE-2026-71193 Published : Aug. 12, 2026, 11:17 p.m. | 54 minutes ago Description :In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to…

CVE-2026-49481 – UpSnap vulnerable to Remote Code Execution via IP Field Template Injection in wake_cmd/shutdown_cmd

Posted on August 13, 2026

CVE ID :CVE-2026-49481 Published : Aug. 12, 2026, 11:17 p.m. | 54 minutes ago Description :UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability…

CVE-2026-73519 – WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret

Posted on August 13, 2026

CVE ID :CVE-2026-73519 Published : Aug. 12, 2026, 10:17 p.m. | 1 hour, 55 minutes ago Description :WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant…

CVE-2026-73501 – kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default

Posted on August 13, 2026

CVE ID :CVE-2026-73501 Published : Aug. 12, 2026, 10:17 p.m. | 1 hour, 55 minutes ago Description :kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces…

CVE-2026-73500 – etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline

Posted on August 13, 2026

CVE ID :CVE-2026-73500 Published : Aug. 12, 2026, 10:17 p.m. | 1 hour, 55 minutes ago Description :etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33,…

Posts pagination

1 2 … 128 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme