- Sources: GHSA-rh53-xvx2-j327, CVE-2026-73842
- Summary: The OpenChoreo advisory describes an internal cluster-gateway listener that performs no caller authentication and grants tunneled Kubernetes access to every connected data plane, including Secret reads. The client library's read-only restriction is not enforced server side. Fixed in 1.0.3, 1.1.3, and 1.2.0.
- Why it matters: Anyone running OpenChoreo needs 1.0.3, 1.1.3, or 1.2.0, because the internal listener grants tunneled Kubernetes access with no caller check.
- Follow-up: Whether the listener gains authentication rather than only network-level restriction, and any reported exploitation.
send feedback on this story