Web Application Vulnerability in OpenChoreo by OpenChoreo
CVE-2026-73840
5.3MEDIUM
What is CVE-2026-73840?
OpenChoreo, an open-source platform for Kubernetes, contains a notable flaw in its webhook handling. Specifically, the POST /api/v1alpha1/autobuild endpoint allows an attacker to trigger builds based on unauthenticated parameters such as repository URLs and branches, without requiring HMAC-SHA256 verification in the X-Hub-Signature. This vulnerability also facilitates cross-provider triggers using manipulated commit SHA values. These issues have been addressed in the versions 1.0.3, 1.1.3, and 1.2.0-rc.2.
Affected Version(s)
openchoreo < 1.0.3 < 1.0.3
openchoreo >= 1.1.0, < 1.1.3 < 1.1.0, 1.1.3
openchoreo >= 1.2.0-rc.1, < 1.2.0-rc.2 < 1.2.0-rc.1, 1.2.0-rc.2
