CVE ID :CVE-2026-73843 Published : Aug. 13, 2026, 10:17 p.m. | 1 hour, 55 minutes ago Description :OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-facing…
CVE-2026-73842 – OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
CVE ID :CVE-2026-73842 Published : Aug. 13, 2026, 10:17 p.m. | 1 hour, 55 minutes ago Description :OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go exposed…
CVE-2026-73841 – OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints
CVE ID :CVE-2026-73841 Published : Aug. 13, 2026, 10:17 p.m. | 1 hour, 55 minutes ago Description :OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go and internal/openchoreo-api/api/handlers/wirelogs.go authorize…
CVE-2026-73667 – OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods
CVE ID :CVE-2026-73667 Published : Aug. 13, 2026, 10:17 p.m. | 1 hour, 55 minutes ago Description :OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow…
CVE-2026-73666 – OpenChoreo: Unauthenticated Backstage developer-portal API exposes OpenChoreo catalog data, scaffolder logs, and allows unauthenticated catalog write/delete
CVE ID :CVE-2026-73666 Published : Aug. 13, 2026, 10:17 p.m. | 1 hour, 55 minutes ago Description :OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend…
CVE-2026-71193 – OpenStack Designate Cross-Tenant Zone Overlap Vulnerability
CVE ID :CVE-2026-71193 Published : Aug. 12, 2026, 11:17 p.m. | 54 minutes ago Description :In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to…
CVE-2026-49481 – UpSnap vulnerable to Remote Code Execution via IP Field Template Injection in wake_cmd/shutdown_cmd
CVE ID :CVE-2026-49481 Published : Aug. 12, 2026, 11:17 p.m. | 54 minutes ago Description :UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability…
CVE-2026-73519 – WolfStack < 25.9.2 Hard-coded Secret Authentication Bypass via X-WolfStack-Secret
CVE ID :CVE-2026-73519 Published : Aug. 12, 2026, 10:17 p.m. | 1 hour, 55 minutes ago Description :WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant…
CVE-2026-73501 – kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default
CVE ID :CVE-2026-73501 Published : Aug. 12, 2026, 10:17 p.m. | 1 hour, 55 minutes ago Description :kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently replaces…
CVE-2026-73500 – etcd: `tlsListener.acceptLoop` spawns unbounded handshake goroutines with no deadline
CVE ID :CVE-2026-73500 Published : Aug. 12, 2026, 10:17 p.m. | 1 hour, 55 minutes ago Description :etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33,…