• Sources: GHSA-rh53-xvx2-j327, CVE-2026-73842
  • Summary: The OpenChoreo advisory describes an internal cluster-gateway listener that performs no caller authentication and grants tunneled Kubernetes access to every connected data plane, including Secret reads. The client library's read-only restriction is not enforced server side. Fixed in 1.0.3, 1.1.3, and 1.2.0.
  • Why it matters: Anyone running OpenChoreo needs 1.0.3, 1.1.3, or 1.2.0, because the internal listener grants tunneled Kubernetes access with no caller check.
  • Follow-up: Whether the listener gains authentication rather than only network-level restriction, and any reported exploitation.

send feedback on this story