Browse all 6 CVE security advisories affecting openchoreo. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-73843 | OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs — openchoreo CWE-306 | 9.6 | Critical | 2026-08-13 |
| CVE-2026-73842 | OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation — openchoreo CWE-269 | 9.0 | Critical | 2026-08-13 |
| CVE-2026-73841 | OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints — openchoreo CWE-639 | 8.8 | High | 2026-08-13 |
| CVE-2026-73840 | OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass) — openchoreo CWE-287 | 5.3 | Medium | 2026-08-13 |
| CVE-2026-73667 | OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods — openchoreo CWE-78 | 8.8 | High | 2026-08-13 |
This page lists every published CVE security advisory associated with openchoreo. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.