UNKNOWN Go
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs in github.com/openchoreo/openchoreo
GO-2026-6362 · CVE-2026-73843 · GHSA-qh9r-j7rp-4x2m
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs in github.com/openchoreo/openchoreo
References
- ADVISORY https://github.com/openchoreo/openchoreo/security/advisories/GHSA-qh9r-j7rp-4x2m
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-73843
- FIX https://github.com/openchoreo/openchoreo/commit/047d80ddc63b4b4b9dd67044d5cffcdbd77685ce
- FIX https://github.com/openchoreo/openchoreo/commit/0aa0ffe1623bd8eb4235cb2a5854336695953c3a
- FIX https://github.com/openchoreo/openchoreo/commit/b42eeb0f5dce95195a9781d7c5a1fe9e38f5da8f
- FIX https://github.com/openchoreo/openchoreo/pull/4122
- WEB https://github.com/openchoreo/openchoreo/releases/tag/v1.0.2
- WEB https://github.com/openchoreo/openchoreo/releases/tag/v1.1.2
- WEB https://github.com/openchoreo/openchoreo/releases/tag/v1.2.0
Ready to move
Start Securing
Free, no credit card | First findings in minutes