Vulnerability GO-2026-6517

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
3 hours ago
September 28, 2026 at 04:43 PM UTC
kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace in github.com/kcp-dev/kcp
v0.2.0 - v0.31.3
v0.2.0 - v0.31.3

Summary

kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace in github.com/kcp-dev/kcp

Details

kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace in github.com/kcp-dev/kcp

Impacted packages

Timeline

Published
3 hours ago
September 28, 2026 at 04:43 PM UTC
Last Modified
2 hours ago
September 28, 2026 at 05:00 PM UTC