GHSA-c5f6-2rm9-2w8g

Suggest an improvement
Source
https://github.com/advisories/GHSA-c5f6-2rm9-2w8g
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-c5f6-2rm9-2w8g/GHSA-c5f6-2rm9-2w8g.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-c5f6-2rm9-2w8g
Aliases
Published
2026-09-02T23:45:14Z
Modified
2026-09-10T15:25:52Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)
Details

Summary

The OpenChoreo autobuild webhook endpoint (POST /api/v1alpha1/autobuild) selected the git provider used to authenticate an incoming webhook from a client-supplied request header rather than from the target component's configuration, and its Bitbucket provider accepted requests without a valid signature. A caller could set the X-Event-Key header to be treated as a Bitbucket webhook, bypassing the HMAC secret that otherwise protects GitHub and GitLab webhooks, and trigger a component build without authenticating.

Impact

An attacker who can reach the autobuild webhook endpoint and knows the repository URL and branch configured for an auto-build component can trigger a build for that component without authenticating — including components configured for GitHub or GitLab, since the provider used or verification is chosen by the caller rather than by the component's configuration. The triggered build runs against a commit SHA supplied by the attacker, and the component lookup is not scoped to a tenant or namespace, so any auto-build component across the cluster matching the given repository and branch is affected. This can result in unauthorized builds — and, where auto-deploy is configured, unauthorized deployment of attacker-influenced code — and can be used to exhaust build resources through repeated unauthenticated triggering.

The exposure applies to any component with spec.autoBuild: true, regardless of which git provider it declares, wherever the autobuild webhook endpoint is network-reachable.

Patches

Fixed in 1.0.3, 1.1.3, and 1.2.0-rc.2. The fix validates Bitbucket webhooks with HMAC-SHA256 against the configured secret using the same verification path as GitHub, requires a configured, non-empty secret for every provider (a missing secret now rejects the request instead of skipping validation), and requires the authenticated provider to match the git provider configured for the matched component. Upgrading is non-disruptive — no component or webhook configuration changes are required beyond the standard upgrade. Upgrade path: 1.1.x → 1.1.3, 1.0.x and earlier → 1.0.3, 1.2 line → 1.2.0-rc.2 or later.

Database specific
{
    "cwe_ids": [
        "CWE-287",
        "CWE-290",
        "CWE-345"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-02T23:45:14Z",
    "nvd_published_at": "2026-08-13T22:17:28Z",
    "severity": "MODERATE"
}
References

Affected packages

Go / github.com/openchoreo/openchoreo

Package

Name
github.com/openchoreo/openchoreo
View open source insights on deps.dev
Purl
pkg:golang/github.com/openchoreo/openchoreo

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.0.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-c5f6-2rm9-2w8g/GHSA-c5f6-2rm9-2w8g.json"

Go / github.com/openchoreo/openchoreo

Package

Name
github.com/openchoreo/openchoreo
View open source insights on deps.dev
Purl
pkg:golang/github.com/openchoreo/openchoreo

Affected ranges

Type
SEMVER
Events
Introduced
1.1.0
Fixed
1.1.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-c5f6-2rm9-2w8g/GHSA-c5f6-2rm9-2w8g.json"

Go / github.com/openchoreo/openchoreo

Package

Name
github.com/openchoreo/openchoreo
View open source insights on deps.dev
Purl
pkg:golang/github.com/openchoreo/openchoreo

Affected ranges

Type
SEMVER
Events
Introduced
1.2.0-rc.1
Fixed
1.2.0-rc.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-c5f6-2rm9-2w8g/GHSA-c5f6-2rm9-2w8g.json"