Vulnerabilities & PatchesEmerging1 src
CVE-2026-73842 - OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
CVE ID : CVE-2026-73842
Published : Aug. 13, 2026, 10:17 p. m.
• 48 minutes ago
Description : OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1. 0. 3, 1. 1. 3, and 1. 2. 0-rc. 2, internal/cluster-gateway/server.
go exposed /api/proxy/, /api/exec/, and /api/wirelogs/ on an internal listener without requiring a client certificate or token, allowing any network-reachable caller to read tenant Kubernetes Secrets, mutate workloads, and execute commands across connected data planes. This issue is fixed in versions 1. 0. 3, 1. 1. 3, and 1. 2. 0-rc. 2.
Severity: 9.0
• CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...