- EPSS -
- Veröffentlicht 17.09.2026 19:40:57
- Zuletzt bearbeitet 24.09.2026 21:25:27
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.0 until 1.7.3, SAML.getSession in internal/pkg/auth/interceptor/saml.go checks SAMLAssertion.Used and marks it used in separate state operations. Conc...
CVE-2026-45723
- EPSS -
- Veröffentlicht 17.09.2026 19:39:28
- Zuletzt bearbeitet 23.09.2026 18:12:04
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.CreateSchematic in internal/backend/grpc/schematics.go passes the caller-controlled TalosVersion field to imageFactoryClient.OverlaysVe...
CVE-2026-45726
- EPSS -
- Veröffentlicht 17.09.2026 19:37:50
- Zuletzt bearbeitet 24.09.2026 21:25:27
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a standalone Talos cluster creates an ImportedClusterSecrets resource containing the cluster's complete CA secrets bundle. The access ...
CVE-2025-61688
- EPSS 0.29%
- Veröffentlicht 13.10.2025 20:46:54
- Zuletzt bearbeitet 08.10.2026 12:10:00
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, Omni might leak sensitive information via an API.
CVE-2025-59836
- EPSS 0.54%
- Veröffentlicht 13.10.2025 20:43:40
- Zuletzt bearbeitet 08.10.2026 12:10:00
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.1.5 and 1.0.2, there is a nil pointer dereference vulnerability in the Omni Resource Service allows unauthenticated users to cause a server panic and denial of service...
CVE-2025-59824
- EPSS 0.18%
- Veröffentlicht 24.09.2025 20:15:33
- Zuletzt bearbeitet 22.12.2025 14:09:39
Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to version 0.48.0, Omni Wireguard SideroLink has the potential to escape. Omni and each Talos machine establish a peer-to-peer (P2P) SideroLink connection using WireGuard t...