Onyxia is a data science environment for kubernetes. In versions 4.6.0 through 4.8.0, Onyxia-API leaked the credentials of private helm repositories in the public (unauthenticated) /public/catalogs endpoint.vOnly instances using private helm repositories (i.e setting username & password in the catalogs configuration) are affected. This is fixed in version 4.9.0.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/58xxx/CVE-2025-58366.json",
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-522"
]
}{
"versions": [
{
"introduced": "4.6.0"
},
{
"last_affected": "4.8.0"
}
]
}[
{
"signature_type": "Line",
"source": "https://github.com/inseefrlab/onyxia-api/commit/38fe3acca6c0200cd3db935334e02b1b6af67e9e",
"signature_version": "v1",
"target": {
"file": "onyxia-api/src/main/java/fr/insee/onyxia/api/configuration/CatalogWrapper.java"
},
"id": "CVE-2025-58366-acc2f36c",
"deprecated": false,
"digest": {
"line_hashes": [
"238080932978260150636074596967990981493",
"214212985932319106320472696507199961827",
"32561169961295695454912076373701741457",
"139413866440363358078004620851079328471",
"251261211353442491565180977005261035115",
"54446219779737093380004512783766296181"
],
"threshold": 0.9
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-58366.json"
"2026-04-12T18:28:21Z"