THREAT OPS › Threat News › [GHSA] GHSA-c5f6-2rm9-2w8g (medium) — OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)
[GHSA] GHSA-c5f6-2rm9-2w8g (medium) — OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)
GHSA-c5f6-2rm9-2w8g Severity: medium CVE: CVE-2026-73840
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)
## Summary The OpenChoreo autobuild webhook endpoint (`POST /api/v1alpha1/autobuild`) selected the git provider used to authenticate an incoming webhook from a client-supplied request header rather than from the target component's confi
Indicators of compromise
- CVE-2026-73840cve
Original source: https://github.com/advisories/GHSA-c5f6-2rm9-2w8g