- Sources: critical advisory, GHSA-2mw5-23gm-pccq, GHSA-52gf-6rpq-fgmx, GHSA-c5f6-2rm9-2w8g, GHSA-v7qx-mqhq-grvh
- Summary: The severe entry is CVE-2026-73842, scored 9.0 under
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H: OpenChoreo's control-plane cluster-gateway internal listener authenticates no caller and permits mutating methods, so anyone reaching it can read Secrets outside kube-system in any tenant namespace, create, modify or delete workloads, and exec into pods across every connected data plane. The advisory states the critical rating holds where the internal port is reachable by untrusted workloads with no restrictive NetworkPolicy and that it is scored conservatively as High otherwise, because the network isolation of the internal listener is not fixed in source. The dates come from API fields rather than from any claim in the advisory text: the repository advisories carry published_at of 2026-07-27 and 2026-08-04 with NVD publication on 2026-08-13, while github_reviewed_at on all of them is 2026-09-02, so what happened on 2026-09-02 is database ingestion rather than disclosure, and fixes land in 1.0.3, 1.0.4, 1.1.3, 1.1.4, 1.1.6, 1.2.0, 1.2.1, 1.2.3 and 1.2.0-rc.2 depending on the advisory. - Why it matters: A cluster-takeover path stayed invisible to Go dependency scanning for four to five weeks after the project disclosed it, so a team relying on the advisory database rather than on the project's own feed had no signal in that window.
- Follow-up: Track whether the ingestion lag on this batch is explained, and whether GHSA-2xp9-vwfh-vxw4, unresolvable on the 2026-09-02 page and returning HTTP 404 again today, ever appears.
send feedback on this story