Web Application Vulnerability in OpenChoreo by OpenChoreo
CVE-2026-73840

5.3MEDIUM

Key Information:

Vendor

Openchoreo

Vendor
CVE Published:
13 August 2026

What is CVE-2026-73840?

OpenChoreo, an open-source platform for Kubernetes, contains a notable flaw in its webhook handling. Specifically, the POST /api/v1alpha1/autobuild endpoint allows an attacker to trigger builds based on unauthenticated parameters such as repository URLs and branches, without requiring HMAC-SHA256 verification in the X-Hub-Signature. This vulnerability also facilitates cross-provider triggers using manipulated commit SHA values. These issues have been addressed in the versions 1.0.3, 1.1.3, and 1.2.0-rc.2.

Affected Version(s)

openchoreo < 1.0.3 < 1.0.3

openchoreo >= 1.1.0, < 1.1.3 < 1.1.0, 1.1.3

openchoreo >= 1.2.0-rc.1, < 1.2.0-rc.2 < 1.2.0-rc.1, 1.2.0-rc.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.