Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-73840— OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)

Quick assessment

Affected
openchoreo openchoreo
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OpenChoreo是openchoreo组织开源的一个面向 Kubernetes 的开发者平台。 OpenChoreo 1.0.3之前版本、1.1.3之前版本和1.2.0-rc.2之前版本存在安全漏洞,该漏洞源于internal/openchoreo-api/api/handlers/webhook_handler.go文件中的POST /api/v1alpha1/autobuild端点根据调用者控制的X-Event-Key选择Webhook提供程序,并接受没有HMAC-SHA256签名的Bitbuck

CVSS 5.3 · Medium EPSS 0.35% · P26

Affected Version Matrix 3

VendorProduct Version RangeStatus
openchoreo openchoreo < 1.0.3 affected
>= 1.1.0, < 1.1.3 affected
>= 1.2.0-rc.1, < 1.2.0-rc.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-73840

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)
Source: CVE Program / CVE List V5
Vulnerability Description
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST /api/v1alpha1/autobuild endpoint in internal/openchoreo-api/api/handlers/webhook_handler.go selected a webhook provider from caller-controlled X-Event-Key, accepted Bitbucket requests without HMAC-SHA256 in X-Hub-Signature or a configured bitbucket-secret, and allowed unauthenticated build triggers for components matched by repository URL and branch, including cross-provider triggers using attacker-supplied commit SHAs. This issue is fixed in versions 1.0.3, 1.1.3, and 1.2.0-rc.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
认证机制不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
OpenChoreo 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
OpenChoreo是openchoreo组织开源的一个面向 Kubernetes 的开发者平台。 OpenChoreo 1.0.3之前版本、1.1.3之前版本和1.2.0-rc.2之前版本存在安全漏洞,该漏洞源于internal/openchoreo-api/api/handlers/webhook_handler.go文件中的POST /api/v1alpha1/autobuild端点根据调用者控制的X-Event-Key选择Webhook提供程序,并接受没有HMAC-SHA256签名的Bitbuck
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
openchoreo openchoreo < 1.0.3 -

II. Public POCs for CVE-2026-73840

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-73840

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-73840 (3)

Vendor Advisories for CVE-2026-73840 (1)

Vendor Pages for CVE-2026-73840 (2)

Same Patch Batch · openchoreo · 2026-08-13 · 6 CVEs total

CVE-2026-73843 9.6 CRITICAL OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway
CVE-2026-73842 9.0 CRITICAL OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not re
CVE-2026-73667 8.8 HIGH OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates ena
CVE-2026-73841 8.8 HIGH OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo opencho
CVE-2026-73666 8.2 HIGH OpenChoreo: Unauthenticated Backstage developer-portal API exposes OpenChoreo catalog data

IV. Related Vulnerabilities

V. Comments for CVE-2026-73840

No comments yet


Leave a comment