UNKNOWN Go
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation in github.com/openchoreo/openchoreo
GO-2026-6428 · CVE-2026-73842 · GHSA-rh53-xvx2-j327
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation in github.com/openchoreo/openchoreo
References
- ADVISORY https://github.com/openchoreo/openchoreo/security/advisories/GHSA-rh53-xvx2-j327
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-73842
- FIX https://github.com/openchoreo/openchoreo/commit/50fcae3f1753fd0ac3ae655a3fc080a761c49c04
- FIX https://github.com/openchoreo/openchoreo/commit/93e6f10953cfc249af2222ddb6730d4b0a729129
- FIX https://github.com/openchoreo/openchoreo/commit/e3da3c63dcf0895c693cb17ce142ef95e959b62a
- FIX https://github.com/openchoreo/openchoreo/pull/4256
- FIX https://github.com/openchoreo/openchoreo/pull/4258
- FIX https://github.com/openchoreo/openchoreo/pull/4259
- WEB https://github.com/openchoreo/openchoreo/releases/tag/v1.0.3
- WEB https://github.com/openchoreo/openchoreo/releases/tag/v1.1.3
- WEB https://github.com/openchoreo/openchoreo/releases/tag/v1.2.0-rc.2
Ready to move
Start Securing
Free, no credit card | First findings in minutes