THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-c5f6-2rm9-2w8g (medium) — OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)

[GHSA] GHSA-c5f6-2rm9-2w8g (medium) — OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)

medgithub_advisoriesPublished 2026-09-02

GHSA-c5f6-2rm9-2w8g Severity: medium CVE: CVE-2026-73840

OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)

## Summary The OpenChoreo autobuild webhook endpoint (`POST /api/v1alpha1/autobuild`) selected the git provider used to authenticate an incoming webhook from a client-supplied request header rather than from the target component's confi

Indicators of compromise

Original source: https://github.com/advisories/GHSA-c5f6-2rm9-2w8g