github.com/siderolabs/omni
Go6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/siderolabs/omnipage 1 of 1
- CVE-2025-59824MEDIUMCVSS 5.4EG 5.4✓ Fixed in 0.48.02025-09-24
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to version 0.48.0, Omni Wireguard SideroLink has the potential to escape. Omni and each Talos machine establish a peer-to-peer (P2P) SideroLink connection using …
- CVE-2025-59836MEDIUMCVSS 5.3EG 5.3✓ Fixed in 1.1.52025-10-13
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, there is a nil pointer dereference vulnerability in the Omni Resource Service allows unauthenticated users to cause a server panic and denial…
- CVE-2025-61688HIGHCVSS 7.5EG 8.6✓ Fixed in 1.1.52025-10-13
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, Omni might leak sensitive information via an API.
- CVE-2026-45720HIGHCVSS 7.0EG 7.0✓ Fixed in 1.7.32026-06-05
Omni has a TOCTOU race condition that allows multiple concurrent uses of a single-use SAML session token ## Summary `SAML.getSession` (`internal/pkg/auth/interceptor/saml.go`) checks the `Used` flag on a `SAMLAssertion` resource and then…
- CVE-2026-45723LOWCVSS 2.7EG 2.7✓ Fixed in 1.7.32026-06-05
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic ## Summary `managementServer.CreateSchematic` (`internal/backend/grpc/schematics.go`) passes the caller-controlled `TalosVersion` fiel…
- CVE-2026-45726HIGHCVSS 7.6EG 7.6✓ Fixed in 1.7.32026-06-05
Omni: Reader-level users can retrieve imported cluster CA keys via ResourceService ## Summary Omni supports importing standalone Talos clusters. During this process, an ImportedClusterSecrets resource is created, which contains the full…
Check whether github.com/siderolabs/omni is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/siderolabs/omni CVEs against the assets you own.
Start Free Scan →