THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-rh53-xvx2-j327 (critical) — OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation

[GHSA] GHSA-rh53-xvx2-j327 (critical) — OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation

medgithub_advisoriesPublished 2026-09-04

GHSA-rh53-xvx2-j327 Severity: critical CVE: CVE-2026-73842

OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation

### Summary

The OpenChoreo control-plane cluster-gateway exposes internal management APIs (`/api/proxy/`, `/api/exec/`, `/api/wirelogs/`) that tunnel requests through to conne

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-rh53-xvx2-j327