All 6 CVE vulnerabilities found in omni, with AI-generated Chinese analysis, references, and POCs.
Vendor: siderolabs
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-45720 | Omni: TOCTOU race condition allows multiple concurrent uses of a single-use SAML session token CWE-294 | 7.0 | High | 2026-09-17 |
| CVE-2026-45723 | Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic CWE-20 | 2.7 | Low | 2026-09-17 |
| CVE-2026-45726 | Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService CWE-200 | 7.6 | High | 2026-09-17 |
| CVE-2025-61688 | Omni leaks information via the API CWE-200 | 8.6 | High | 2025-10-13 |
| CVE-2025-59836 | Omni is Vulnerable to DoS via Empty Create/Update Resource Requests CWE-703 | 5.3 | Medium | 2025-10-13 |
| CVE-2025-59824 | Omni Wireguard SideroLink potential escape CWE-863 | 9.9AI | Critical AI | 2025-09-24 |
All 6 known CVE vulnerabilities affecting omni with full Chinese analysis, references, and POCs where available.