CRITICALGo →
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs
OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs
Affected packages
- github.com/openchoreo/openchoreo
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/openchoreo/openchoreo/security/advisories/GHSA-qh9r-j7rp-4x2m
- https://nvd.nist.gov/vuln/detail/CVE-2026-73843
- https://github.com/openchoreo/openchoreo/pull/4122
- https://github.com/openchoreo/openchoreo/commit/047d80ddc63b4b4b9dd67044d5cffcdbd77685ce
- https://github.com/openchoreo/openchoreo/commit/0aa0ffe1623bd8eb4235cb2a5854336695953c3a
- https://github.com/openchoreo/openchoreo/commit/b42eeb0f5dce95195a9781d7c5a1fe9e38f5da8f
- https://github.com/openchoreo/openchoreo
- https://github.com/openchoreo/openchoreo/releases/tag/v1.0.2
- https://github.com/openchoreo/openchoreo/releases/tag/v1.1.2
- https://github.com/openchoreo/openchoreo/releases/tag/v1.2.0
Structured record: https://osv.dev/vulnerability/GHSA-qh9r-j7rp-4x2m
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta