Vulnerability GO-2026-5088
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
3 months ago
June 25, 2026 at 06:26 PM UTC
kcp's cache server is accessible without authentication or authorization checks in github.com/kcp-dev/kcp
v0.2.0 - v0.29.2
v0.2.0 - v0.29.2
Summary
kcp's cache server is accessible without authentication or authorization checks in github.com/kcp-dev/kcp
Details
kcp's cache server is accessible without authentication or authorization checks in github.com/kcp-dev/kcp
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
3 hours ago
kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace in github.com/kcp-dev/kcp
v0.2.0 - v0.31.3 GO-2026-6517
v0.2.0 - v0.31.3 GO-2026-6517
Critical
10 days ago
kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace
v0.2.0 - v0.31.3 and v0.32.0 - v0.32.1 GHSA-c8w2-fgvx-vhv4
v0.2.0 - v0.31.3 and v0.32.0 - v0.32.1 GHSA-c8w2-fgvx-vhv4
High Risk
5 months ago
kcp's cache server is accessible without authentication or authorization checks
v0.2.0 - v0.29.2 and v0.30.0 - v0.30.2 GHSA-3j3q-wp9x-585p
v0.2.0 - v0.29.2 and v0.30.0 - v0.30.2 GHSA-3j3q-wp9x-585p
Unknown
11 months ago
kcp is missing update validation allows arbitrary LogicalCluster status patches through initializingworkspaces Virtual Workspace in github.com/kcp-dev/kcp
v0.2.0 - v0.28.2 GO-2025-3985
v0.2.0 - v0.28.2 GO-2025-3985
Low Risk
1 year ago
kcp is missing update validation allows arbitrary LogicalCluster status patches through initializingworkspaces Virtual Workspace
v0.2.0 - v0.28.2 GHSA-q6hv-wcjr-wp8h
v0.2.0 - v0.28.2 GHSA-q6hv-wcjr-wp8h
Impacted packages
Timeline
Published
3 months ago
June 25, 2026 at 06:26 PM UTC
Last Modified
2 months ago
July 16, 2026 at 09:10 PM UTC